Vendors hit by a cyberattack saw nearly five of their third-party suppliers also compromised per incident in 2022, double the 2.5 entities per vendor in 2021, according to a new study by Black Kite, a cyber risk intelligence company.
"Catastrophic" Damage
In its Third-Party Breach Report, the Boston-based firm called the breach impact and damage “catastrophic,” in its analysis of 63 third-party breaches and nearly 300 publicly disclosed victims. The study’s results should put organizations on “heightened risk in 2023,” Black Kite said.
Managed security service providers (MSSPs) should heed the study’s findings by assessing and shoring up their cyber defenses. This was never more evident than in the SolarWinds attack of 2020 and the Kaseya assault of 2021 that expanded the attack surface to managed service providers (MSPs).
More Findings From the Report
The report’s key findings include:
Commenting on the survey results, Jeffrey Wheatman, Black Kite cyber risk evangelist, said:
“Global business ecosystems continue to get more complex, with every organization increasingly impacted by the cybersecurity posture of their partners, and their partners' partners, and so on. The reality is your attack surface is much bigger than the stuff you can control. But the good news is, you can assess and monitor your extended ecosystem to spot vulnerabilities, take action and avoid catastrophe.”