< ciso
brief />
Tag Banner

All news with #third party risk tag

99 articles

Defense Contractors Report Rising Scores, Falling Confidence

📊 The CyberSheath 2026 State of the DIB Report finds average SPRS scores reached a five-year high, yet contractor confidence in those self-assessments dropped significantly. The study highlights tensions between improved reported cybersecurity maturity under CMMC self-assessments and growing doubts about score accuracy. Contractors want easier DFARS implementation and more vendor options while still supporting minimum mandated standards.
read more →

Police Conceal Use of Flock License Plate Cameras

🚨A usage policy for Flock automated license plate reader (ALPR) cameras in Wapello County, Iowa, instructs officers to refrain from informing vehicle occupants or routinely documenting ALPR use in reports. The document explicitly orders: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE” and to avoid mentioning it in reports unless absolutely necessary. This secrecy echoes prior law enforcement efforts to conceal surveillance tools such as IMSI-catchers.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

UK Manufacturing Cyber Resilience Falls Short

🛠️ A new Make UK report finds that around 30% of UK manufacturers experienced a cyber incident in the past year, often through their supply chain. The study highlights significant operational and financial impacts, including production delays and material shortages, while many firms still lack formal response plans, CISO roles or clear cyber insurance coverage. The report urges board-level attention and improved supplier assurance.
read more →

AWS CyberVadis 2026 Report Eases Supplier Due Diligence

🔒 Amazon Web Services (AWS) completed the 2026 CyberVadis assessment and achieved the highest score (Mature) across all evaluated areas, demonstrating commitment to elevated cloud-security expectations. The report and scorecard are now available to help customers reduce third-party due-diligence burdens and map AWS controls to common industry frameworks. Customers can download the full assessment via the CyberVadis portal or AWS Artifact and contact their AWS account team with questions.
read more →

Open Source Growing Up: Enterprise Trust and Risk

🔍 Open Source's informal era is ending as enterprises and regulators demand accountability, continuity, and demonstrable maintenance. The community will split: projects that adopt enterprise-grade practices—reachable maintainers, disclosure paths, and continuous proof-of-life—and projects that remain community-driven without those guarantees. Vendors and foundations will increasingly provide contracts, long-term support, and retirement pathways to bridge gaps while the free, volunteer-led ecosystem continues alongside.
read more →

Operationalize third‑party cyber risk, don’t rely on heroics

🔒 Third-party risk often fails in practice because security teams are looped in too late, turning reviews into last-minute blockers. The author recommends establishing formal intake, clear timelines, and joint workflows with procurement, legal, and finance so security can assess vendors before contracts are signed. Emphasis is placed on using contracts to enforce remediation and adapting processes for risks introduced by AI and shadow IT.
read more →

Canada Signs UN Cybercrime Convention, Driving Cooperation

🛡️ Canada signed the UN Convention against Cybercrime to strengthen international cooperation on electronic evidence, mutual legal assistance, and capacity building. The treaty emphasizes 24x7 contact points, human-rights safeguards, and technical assistance for countries with limited cybercrime capabilities. Fortinet highlights the need for sustained public-private partnerships to operationalize the treaty and accelerate cross-border disruption.
read more →

Ernst & Young discloses support system data breach

🔒 Ernst & Young has notified clients of a data breach after a third-party support ticket system used by its IT staff was compromised. The company says support tickets may have contained documents with client tax information and that unauthorized access occurred between March 28 and April 12. EY detected anomalous activity on April 23, engaged external cybersecurity experts, secured systems, and notified law enforcement. Affected clients are offered 24 months of identity monitoring through Experian.
read more →

Lidl warns customers after third‑party data theft

🛡️ Lidl has alerted customers in Germany, Belgium and the Netherlands after personal data was stolen from a third‑party IT provider. The retailer said the online shop itself was not affected but a separately stored file containing names, phone numbers, emails, birth dates and customer numbers was accessed. Lidl stated passwords, payment details and delivery addresses are not impacted and urged vigilance against phishing. Forensics experts and authorities have been engaged and customers are advised to verify senders and avoid clicking unknown links.
read more →

Lidl discloses online shop customer data breach

🔒 Lidl notified customers in Germany, Belgium, and the Netherlands that attackers accessed a separately stored file at a third‑party service provider and stole personal data from users of its online shop. The retailer said the shop's systems were not affected, but it cannot yet exclude the theft of passwords, billing or payment details. Lidl and the service provider have reported the incident to authorities and engaged forensic experts, while warning customers to watch for phishing and identity fraud.
read more →

Google Cloud designated a UK critical third party

🛡️ Today Google Cloud announced that on July 10 the U.K. Treasury designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector. The designation acknowledges the systemic impact of services used by U.K. firms and places Google Cloud EMEA under direct oversight by the Bank of England, PRA, and FCA. Google Cloud commits to constructive engagement with regulators and to help customers meet operational resilience and third‑party risk requirements.
read more →

AWS designated a critical third party for UK finance

🔐 Amazon Web Services EMEA Sarl (AWS) has been designated a critical third party (CTP) to the UK financial sector under the CTP regime that came into force on January 1, 2025. The regime gives the Bank of England, PRA, and FCA powers to set requirements and exercise direct oversight over designated providers. AWS will self-assess its designated Systemic Third-Party Services (STPS) against the criteria and engage with regulators while supporting customers’ operational resilience.
read more →

Improving security across Microsoft partner ecosystem

🔒 This post by Raji Dani, Microsoft Deputy CISO, explains how Microsoft secures its partner ecosystem—especially Microsoft Cloud Solution Providers (CSPs)—to reduce risk to downstream customers. It outlines vetting, mandatory security requirements for authorization, granular delegated administrative privileges (GDAP), telemetry and rapid access revocation capabilities. The article emphasizes shared responsibility between Microsoft and partners and a continual roadmap to raise security standards.
read more →

KDDI breach may expose millions of ISP email logins

📧 KDDI Corporation disclosed a breach affecting an email system shared with five Japanese ISPs after discovering unauthorized access on June 17. The company attributes the intrusion to a vulnerability in unnamed third-party software and says it immediately blocked the attacker and implemented defenses. Up to 14.22 million current, former, and inactive customer email addresses and passwords may have been exposed, though some credentials were stored hashed or encrypted. KDDI is notifying regulators and working with affected ISPs while advising customers to reset passwords and enable 2FA where possible.
read more →

CMC analysis of Canvas incident impacts education

🔍 The UK Cyber Monitoring Centre (CMC) has published its review of the Canvas incident affecting Instructure’s Learning Management System, finding ~160 UK higher education institutions impacted and around 9,000 worldwide. The analysis highlights that financial losses arose mainly from response, recovery and risk management rather than prolonged outage. The CMC reinforced best-practice recommendations for the sector, including MFA enforcement, separation of application and data layers, careful third‑party control and clearer vendor communication.
read more →

Nintendo confirms TinyPulse survey data stolen

🛡️ Nintendo of America confirmed that threat actors accessed survey data from the third-party TinyPulse service used for internal employee surveys, but its own systems were not compromised. The company said the information is limited to a small subset of employees and mostly dates back several years. Nintendo is working with the service provider while denying any access to customer or financial data.
read more →

Lessons from 22,000 Breaches for Incident Preparedness

🔍 The 2026 Verizon DBIR analyzed over 22,000 confirmed breaches across 145 countries and concludes that organizations cannot patch fast enough to prevent every incident. Exploitation of vulnerabilities became the leading initial access vector as critical flaws and their remediation windows grew, while ransomware and third-party breaches surged. The report urges realistic, technical tabletop exercises that rehearse containment, communication, and coordination under time pressure.
read more →

SoFi Hong Kong confirms third-party data breach

🔒 SoFi Hong Kong reported a third-party data breach after detecting unauthorized access to a vendor-hosted database on April 30, 2026. The company engaged a third-party cybersecurity firm and is investigating while notifying affected customers. SoFi has not disclosed the vendor identity, the number of impacted customers, or the exact data exposed. Customers were advised to monitor accounts, enable two-factor authentication, and take extra precautions.
read more →

Oxford University reports CareerConnect credential breach

🔒 Oxford University disclosed a data breach after its third-party provider, Group GTI, reported that the CareerConnect platform was compromised on May 28. The attackers accessed users' first and last names, email addresses, and encrypted passwords for accounts not using Single Sign-On; GTI has invalidated those passwords and will require resets. The university said no course materials, uploaded files, appointments, or financial data appear affected, but warned users to watch for phishing attempts.
read more →