Prevalent's 2024 Third-Party Risk Management Study | Prevalent (2024)

PHOENIX, May 8, 2024 — Prevalent Inc. published its 2024 Third-Party Risk Management Study today, finding that 61% of companies experienced a third-party data breach or cybersecurity incident last year. Breaches rose 20 points—or 49%—year over year, increasing threefold since 2021.

“What stands out in our report isn’t only the number of breaches, which is the highest we’ve tracked, but also the scale,” said Prevalent CEO Kevin Hickey. “Breaches in 2023 impacted huge supply chains—from Okta and LastPass to Change Healthcare and PJ&A—exposing sensitive records of millions of people worldwide. There has never been a more urgent time to take third-party security more seriously.”

Conducted this February and March, the survey’s respondents include heads of information security, data privacy, risk management, procurement, and other IT executives at companies spanning dozens of industries and whose supply chains collectively represent half a million vendors.

Prevalent’s study identified multiple areas of concern that could explain the unprecedented breadth and depth of third-party breaches:

“Although most organizations report having TPRM programs in place, half still rely on spreadsheets and use a patchwork of tools to assess their vendors,” said Prevalent COO Brad Hibbert, adding that 60% of respondents are not using a dedicated TPRM platform.

According to the report, the consequence of companies’ reliance on multiple tools is a lack of coordination, leaving their supply chains unguarded. Only a third of respondents indicated their third-party security programs were highly coordinated.

While the survey respondents’ average number of third parties was 3,200, respondents reported assessing or monitoring only 33% of those vendors. “There is a lot of risk hiding among those unassessed relationships,” said Mr. Hibbert.

More than 62% of respondents reported understaffing was the biggest obstacle to better safeguarding their organizations from third-party breaches. The average respondent said they need double their current staff dedicated to third-party security.

“Later stages of third-party lifecycles lack adequate risk assessment and monitoring, and overall remediation is woefully lacking,” per Prevalent’s report. While nearly 90% of companies track risks from the sourcing and selection phases, fewer than 80% track service-level agreements (SLAs) and offboarding risks later in the relationship lifecycle.

“What surprised us was the disparity between the share of organizations tracking risks and the share remediating them,” explained Mr. Hibbert. “A shockingly low 46% of companies report remediating risk as a result of risk assessments—the stage where risks must be mitigated.”

​​Prevalent found that AI use remains low in the sector, with only 5% of companies actively leveraging AI in their TPRM programs. However, interest remains high, with 61% saying they are actively investigating its uses.

Prevalent advises creating cross-functional teams and establishing clear ownership of TPRM programs as well as automating TPRM processes around a single platform to unify teams, data, and risk lifecycles.

Read the blog post and download the full e-book and infographic for additional statistics, context, and recommendations on benchmarking existing TPRM practices.

Prevalent's 2024 Third-Party Risk Management Study | Prevalent (2024)
Top Articles
How much money should you have saved by age 40? | Ally
Initialize new disks
The Tribes and Castes of the Central Provinces of India, Volume 3
Ffxiv Act Plugin
Skylar Vox Bra Size
Kevin Cox Picks
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Don Wallence Auto Sales Vehicles
Gw2 Legendary Amulet
Midway Antique Mall Consignor Access
Dark Souls 2 Soft Cap
Vichatter Gifs
Yesteryear Autos Slang
Pwc Transparency Report
Housework 2 Jab
A rough Sunday for some of the NFL's best teams in 2023 led to the three biggest upsets: Analysis - NFL
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Idaho Harvest Statistics
Carolina Aguilar Facebook
Spoilers: Impact 1000 Taping Results For 9/14/2023 - PWMania - Wrestling News
97226 Zip Code
X-Chromosom: Aufbau und Funktion
Craigslist Clinton Ar
12 Top-Rated Things to Do in Muskegon, MI
Hannaford To-Go: Grocery Curbside Pickup
Academy Sports Meridian Ms
Unable to receive sms verification codes
Speedstepper
Nottingham Forest News Now
Lacey Costco Gas Price
Taylored Services Hardeeville Sc
Evil Dead Rise - Everything You Need To Know
James Ingram | Biography, Songs, Hits, & Cause of Death
What does wym mean?
Pokemmo Level Caps
The Venus Flytrap: A Complete Care Guide
Sedano's Supermarkets Expands to Orlando - Sedano's Supermarkets
Cheap Motorcycles Craigslist
Ewwwww Gif
Petsmart Northridge Photos
How To Paint Dinos In Ark
Wisconsin Women's Volleyball Team Leaked Pictures
Busch Gardens Wait Times
South Bend Tribune Online
Weather Underground Corvallis
Reese Witherspoon Wiki
Scarlet Maiden F95Zone
Simnet Jwu
Canada Life Insurance Comparison Ivari Vs Sun Life
Nfl Espn Expert Picks 2023
Service Changes and Self-Service Options
Yoshidakins
Latest Posts
Article information

Author: Terence Hammes MD

Last Updated:

Views: 5888

Rating: 4.9 / 5 (69 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Terence Hammes MD

Birthday: 1992-04-11

Address: Suite 408 9446 Mercy Mews, West Roxie, CT 04904

Phone: +50312511349175

Job: Product Consulting Liaison

Hobby: Jogging, Motor sports, Nordic skating, Jigsaw puzzles, Bird watching, Nordic skating, Sculpting

Introduction: My name is Terence Hammes MD, I am a inexpensive, energetic, jolly, faithful, cheerful, proud, rich person who loves writing and wants to share my knowledge and understanding with you.