-

New Whistic/RiskRecon Report Finds 60% of Companies Are Spending More on Vendor Security and Cyber Risk Management

Survey of 500+ infosec practitioners shows most take “trust but verify” approach to vendors

SALT LAKE CITY--(BUSINESS WIRE)--Whistic and RiskRecon, a Mastercard company, today announced the release of a joint research report showing three out of five companies are increasing spending on cyber risk management to “trust but verify” vendors. The research in “The Modernization of Cybersecurity | How Technology is Changing the Way Businesses View Vendor Assessment and Cybersecurity” report looks at how recent investments in technology have impacted vendor security and cyber risk management.

“Vendor security and cyber risk practitioners are the first line of defense against potential security incidents and without a continued investment in technology, they are fighting a losing battle,” said Nick Sorensen, CEO of Whistic. “That’s why we were encouraged to see more and more businesses are prioritizing these programs with not only technology spend, but executive visibility into how they are run and what response and remediation strategies should be.”

More than 500 cyber risk and infosec practitioners were surveyed for the report.
Key findings include:

Cyber risk and vendor security management are top priorities. The survey shows 80% of respondents have cyber risk and vendor security programs in place and 60% report they have incorporated more technology into their programs over the past five years.

Additionally, as the threat of third-party security incidents continues to increase, the issue is a top concern even at the highest levels of companies as 71% of respondents report program metrics to internal leadership outside of security business functions.

Investment in technology results in increased program maturity. Overall, 64% of respondents indicate their cyber risk and vendor security programs are either mature or advanced. However, program maturity depends heavily on the size of the organization as 66% of enterprises have advanced stage programs, while just six percent of startups are at that level and 64% have early to non-existent programs.

Trust but verify is still a staple in the industry. When it comes to security questionnaires, 53% of respondents say they trust what their vendors send them. Despite that trust, 61% of respondents say they still verify vendor responses using a third-party validation tool.

"The reliance on third parties is only increasing, and organizations must understand the threats coming from their vendor ecosystem,” said Kelly White, founder, RiskRecon, a Mastercard Company. “We have seen too many large-scale cyber incidents in the past few years for firms to overlook proper third-party risk management. Your organization is only as secure as the vendors you work with."

You can access the full findings of the report here.

About Whistic

Located in the heart of the Silicon Slopes in Utah, Whistic is the network for assessing, publishing and sharing vendor security information. The Whistic Vendor Security Network accelerates the vendor assessment process by enabling businesses to access and evaluate a vendor’s Whistic Profile and create trusted connections that last well beyond the initial assessment. Make security your competitive advantage and join businesses like Airbnb, Okta, Betterment, and Qualtrics who are leveraging Whistic to modernize their vendor security programs. For more information, visit https://www.whistic.com/.

About RiskRecon

RiskRecon, a Mastercard Company, enables you to achieve better risk outcomes for your enterprise and your digital supply chain. RiskRecon’s cybersecurity ratings and assessments make it easy for you to understand and act on your risks, delivering accurate, risk-prioritized action plans custom-tuned to match your risk priorities. Learn more about RiskRecon and request a demo at www.riskrecon.com.

Contacts

Cheryl Conner or Paul Murphy
SnappConner PR
801-806-0150
info@snappconner.com

Whistic


Release Summary
New @Whistic/RiskRecon report finds 60% of companies are spending more on vendor security. Most take “trust but verify” approach to vendors.
Release Versions

Contacts

Cheryl Conner or Paul Murphy
SnappConner PR
801-806-0150
info@snappconner.com

More News From Whistic

Whistic Drives Proactive Vendor Security Through the Whistic Trust Catalog in Partnership with Google Cloud

SALT LAKE CITY--(BUSINESS WIRE)--Whistic, the network for assessing, publishing and sharing vendor security information, today announced a collaboration with Google Cloud to provide customers with a transparent security profile, which includes a full Google Cloud Assessment Report. Google Cloud customers can now leverage Whistic’s Trust Catalog to view the latest security information. More organizations are undergoing digital transformation initiatives and migrating to cloud service providers s...

Whistic Wins Awards for Best Cyber Security Risk Management Solution and Best Place to Work for in Utah

SALT LAKE CITY--(BUSINESS WIRE)--Whistic, the network for assessing, publishing and sharing vendor security information, is being honored this month for the value and effectiveness of its vendor security risk management solution and as one of the Best Places to Work for in Utah. American Security Today acknowledged Whistic on November 16 with its Platinum Homeland Security Award for Best Cyber Security Risk Management Solution. Utah Business also named Whistic to its roster of Best Places to Wo...

Whistic Integrates the 2023 Shared Assessments (SIG) Questionnaire into Vendor Security Network

SALT LAKE CITY--(BUSINESS WIRE)--Whistic, the leading vendor security network for both buyers and sellers, today announced the release of the Shared Assessments 2023 Standardized Information Gathering (SIG) Questionnaire for users of the Whistic Assess and Whistic Profile product offerings. The 2023 SIG assimilates third-party risk assessments by providing a database of predictable, standardized questions organized by risk control domains, mapping reference and risk control categories. “Whistic...
Back to Newsroom