Report: 51% of orgs have experienced a data breach caused by a third party, with 74% saying it was the result of giving third parties too much privileged access
VentureBeat : Tweets: @searchsecurity and @mikeellsworth Tweets: @searchsecurity : A new report from @securelink and the Ponemon Institute highlights the risks of outsourcing key business processes without paying due care and attention to your service provider's #cybersecurity. @alexscroxton https://twitter.com/... Mike Ellsworth / @mikeellsworth : 51% of organizations experienced a third-party data breach While many businesses continue to outsource critical business processes to 3rd-parties, half are not assessing the security and privacy practices of all 3rd-parties before granting them access. https://venturebeat.com/... https://twitter.com/...
Context & Ripple Effects
Securelink and the Ponemon Institute quantify what the related coverage keeps showing anecdotally: the attack surface has moved outside the firewall. When a firm as security-conscious as Deloitte confirmed a breach touching all company email and admin accounts, the question stopped being whether perimeter defense fails but which external actor holds the keys.
The report lands on a specific failure mode — over-granted privileged access — and pairs it with a governance gap: half of organizations grant third parties access without assessing their security practices first. That echoes the insider-threat finding that departing employees forward content to personal accounts, another case where access outlives its justification.
First-order effects
- Organizations that outsourced critical processes now face the direct cost of remediation for breaches they did not cause but enabled through excessive privileged access granted to vendors.
Second-order effects
- Vendors selling into these organizations will face security assessments as a hard procurement gate, since the report shows the buyer-side vetting step is the control most often skipped — the same accountability pressure visible when health care providers reported higher patient mortality after cyberattacks driven by third-party vendor security gaps.
Third-order effects
- If the pattern holds, privileged-access management and continuous third-party monitoring shift from best practice to contractual and regulatory baseline, because regulators already treat unmonitored access as negligence — the same posture behind federal findings that agencies cannot detect data access attempts.
The trend: Enterprise cybersecurity is reorganizing around supply-chain and privilege governance rather than perimeter defense, as breaches increasingly arrive through authorized third-party access.