Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

It's Time to Take Third-Party Risk Seriously

By Mark Sangster
September 01, 2019

A recent study of 600 IT and security decision-makers revealed that though 60% of organizations have formal third-party risk policies, 44% of them have experienced a significant breach caused by a vendor. This is disturbing in itself, revealing a major discrepancy between the third-party policies organizations espouse and those policies' effectiveness. But what's more, only half of firms discontinued their relationship with the guilty vendor, and 69% did not change the risk policies that had just failed them.

The Ponemon Institute found that on average, companies share confidential and sensitive information with approximately 583 third parties. That figure seems staggering, but this one is more so: only 34% of companies keep a comprehensive inventory of their third parties. As companies increasingly outsource aspects of their business to third parties, their risk profile becomes increasingly complex.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
New York's Latest Cybersecurity Commitment Image

On Aug. 9, 2023, Gov. Kathy Hochul introduced New York's inaugural comprehensive cybersecurity strategy. In sum, the plan aims to update government networks, bolster county-level digital defenses, and regulate critical infrastructure.

The Bankruptcy Hotline Image

Recent cases of importance to your practice.

The DOJ's Corporate Enforcement Policy: One Year Later Image

The DOJ's Criminal Division issued three declinations since the issuance of the revised CEP a year ago. Review of these cases gives insight into DOJ's implementation of the new policy in practice.

How AI Has Affected PR Image

When we consider how the use of AI affects legal PR and communications, we have to look at it as an industrywide global phenomenon. A recent online conference provided an overview of the latest AI trends in public relations, and specifically, the impact of AI on communications. Here are some of the key points and takeaways from several of the speakers, who provided current best practices, tips, concerns and case studies.

CLE Shouldn't Be the Only Mandatory Training for Attorneys Image

Each stage of an attorney's career offers opportunities for a curriculum that addresses both the individual's and the firm's need to drive success.