Editor's note:AJ Yawn is a partner at Armanino LLP, a consulting and accounting firm headquartered in San Ramon, California.Armanino LLP. The views expressed in this article are solely those of the author.

A company's network defense is only as strong as its weakest link, which for most organizations often lies with third-party vendors.

For CFOs, treating such cybersecurity risks as solely an IT responsibility can come at a high cost.

According to a report jointly released by IBM and the Ponemon Institute,the average global cost of a data breach between March 2022 and March 2023reached $4.45 million, a 15% increase from three years earlier and a record high.

Among various types of breaches, those involving third parties are the most common. Research shows that 40% of breaches are discovered by benign third parties, 33% are identified by internal teams and tools, and another 27% are disclosed by attackers during ransomware incidents.

More alarmingly,a 2023 study by SecurityScorecard and the Cyentia Institute found that 98% of organizations worldwidehave at least one third-party vendor in their integration relationships that has experienced a data breach in the past two years.

Escalating Risks

Today, organizations that overlook cyber vulnerabilities do so at their own peril. Beyond potential business disruptions and financial losses, such companies also face the possibility of reputational damage and litigation. This is also an area of growing concern for the federal government.

In May 2021, U.S. President Joe Biden signedExecutive Order 14028, aimed at modernizing and strengthening the federal government's cybersecurity standards. Following the order, the Cloud Security Alliancepublished a blog postpredicting that the order would prompt many organizations to re-examine their vendor risk management processes.

"Enhancing the security of the software supply chain is a key component of the executive order, and organizations must now verify that the vendors they work with are secure and reliable," the post stated. "This will likely lead to increased scrutiny of vendor risk assessments, potential security vulnerabilities in the supply chain, and existing remediation policies."

Vendor-related issues also feature prominently in the cybersecurity rulesfinalized by the U.S. Securities and Exchange Commission (SEC) last year. These rules require disclosure to the SEC within four days of determining a "material" cybersecurity incident, among other provisions. The incident disclosure rule does not exempt companies from disclosing third-party cybersecurity incidents that could have a material impact on them.

The SEC stated in the final rules: "Whether an incident is material does not depend on where the relevant electronic systems are located or who owns them. In other words, we believe that a reasonable investor would not consider a significant breach of a registrant's data immaterial simply because the data is stored on third-party systems, especially as companies increasingly rely on third-party cloud services and data may be outside their direct control."

The SEC acknowledged that companies may have limited visibility into third-party systems and stated that any disclosures related to such systems should be based on available information.

Meanwhile, third-party issues can also have ripple effects on cyber insurance. CFOs need a deep understanding of their organization's and its third-party vendors' data management and cybersecurity practices to navigate the increasingly complex cyber insurance market. Cyber insurance is a necessary expense, and costs continue to rise. Companies need to demonstrate to insurers that their data management and access control practices meet rigorous standards. After obtaining initial coverage, maintaining these high standards is crucial to avoiding premium spikes.

Risk Mitigation Steps

For these reasons, today's companies must conduct a comprehensive assessment of third-party vendors' data management and cybersecurity practices. This process should not be left solely to IT and cybersecurity leaders; CFOs also play a critical role.

Finance leaders and their audit teams need to go beyond superficial certification questions and dig deeper. For example: Are the vendor's current defenses robust enough? What level of risk are we willing to accept? Do their data security standards meet or exceed ours? If the relationship ends, how will our data be handled? Will the vendor use our data to train AI systems? Which individuals within the vendor's organization have access to our data?

As part of the process for reviewing potential cybersecurity risks from vendors, companies should take the following steps:

  1. Review the vendor's incident response process before onboarding.In addition to standard due diligence, review their past breach incidents and causes, and ask what improvements they have made to enhance data security if a security event has occurred. Also, inquire about their response protocols to understand how they plan to notify you and what steps they will take in the event of an incident.
  2. Properly inventory the data that third parties will access or generate.Classify data based on sensitivity and regulatory requirements, and clearly define the scope of third-party data access and usage permissions.
  3. Ensure consistent identity and access management, as well as appropriate organizational and security measures, are implemented throughout the relationship.Implement strict access controls and limit data access based on the principle of least privilege. Clearly define procedures for data return or destruction upon termination of the relationship. Collaborate with third parties to regularly review and update data security policies and procedures.

We live in an era where data breaches are no longer a matter of "if" but "when," and by the time a breach occurs, it is too late to analyze a vendor's data security measures. By ensuring diligent management of third-party vendor risks, CFOs will simultaneously strengthen their company's cyber defenses and financial integrity.