top of page
Insights banner.jpg

INSIGHTS

Search

Trust.....but Verify!

  • Owen Flynn
  • 23 hours ago
  • 3 min read

Trust…..but Verify

 

As more and more workloads are moved to the cloud and delivered through third-party service providers, it is important to understand that vendor risk (and specifically the security aspects of this risk) continues to increase and represent a growing cause for concern. Recent reports have highlighted a worrying trend of both an increasing number of data and security breaches as well as an increase in the scale of these breaches. Some items of note on the volume, time to identify, and causative factors of these breaches include:

 

·      Reported data breaches in 2019 are up 54% compared to 2018 (Data Breach Quickview report, Risk Based Security)

·      The average time to identify a security breach in 2019 was 206 days (Cost of a data breach report, IBM)

·      61% of companies have over 500 accounts with non-expiring passwords, 53% had over 1,000 sensitive files open to every employee, and only 5% of companies’ folders were properly protected on average (Varonis Global Data Risk Report, Varonis)

 

While the statistics above are sobering a frequently overlooked dimension is how your third-party service providers are positioned around cyber security and the steps they are taking to ensure access to your systems and important data is secured (even from within their own organisation). With 97% of financial services professionals expressing major concern over third-party cyber risk and nearly 80% saying they had already terminated or would decline a business relationship because of a vendor's cybersecurity performance (Third-Party Cyber Risk for Financial Services, BitSight & CeFPro) it is important to ensure your business has a similar outlook when selecting which vendors to partner with and how to construct that partnership.

 

In todays connected and cloud enabled world it is certainly a positive step to ensure vendor and service provider accreditations and certifications are in place to mitigate risk, however it is important to remember that this is only part of the action required and an organisation’s accountabilities in this area require further effort and ongoing vigilance.

 

I can recall one instance when working with an organisation consuming PaaS, SaaS, and private cloud services from a single service provider, we were not fully convinced of the effectiveness of their security position and operational practices despite their ISO27001 accreditation. On closer inspection we discovered the majority of this service provider’s administrative accounts (and some generic system accounts) were set to not require password resets, had passwords that had not been changed in literally years, and also included active accounts for a handful of staff members who were no longer working for them. Our expectation was that we would not have found such a large volume of these issues around privileged access management if the service provider was closely aligned with their ISO27001 certification (specifically Annex A.9). Naturally we raised these findings with the service provider and the issues were quickly addressed. In light of the statistics above it is alarming to ponder how our security position was compromised due to a lack of process, procedure, and discipline on our service providers behalf and how long it would have remained so if not for our proactive approach in seeking indicators on the effectiveness of their existing controls.

 

In these and similar cases our recommendation is to ‘Trust but Verify’. Trust that your service provider is acting in your best interests but take the steps to verify that your trust is not misplaced. One clear step is to construct your cloud or other service consumption contract in such a way that you are permitted regular auditing which is tailored to measuring the effectiveness of controls (and not just the mere presence of controls). Recognising we all work in busy and demanding environments; it is equally important to go ahead and frequently complete these audits to generate an authoritative position on the effectiveness of your service provider’s controls, and in turn map your own organisation’s exposure and risk profile.

 

Please contact me directly on 0409285045 or owenflynn@zenitil.com.au If you would like to speak further on how to construct and position your cloud and service provider engagements for effective outcomes and a reduced risk profile for your organisation.

 
 
 

Recent Posts

See All

Comments


bottom of page