As Third-Party Vulnerabilities Rise, CISOs Accelerate Push for Security Modernization
Panorays has released the latest edition of its annual CISO Survey for Third-Party Cyber Risk Management, highlighting significant concerns for security professionals.
Panorays has released the latest edition of its annual CISO Survey for Third-Party Cyber Risk Management, highlighting significant concerns for security professionals.
The survey indicates a rise in software supply chain attacks, as cybercriminals exploit the complexity of third-party components. The adoption of AI contributes to this increased threat surface, although it also provides new tools for defense.
According to the survey, 60% of the 200 U.S.-based CISOs reported an increase in third-party security incidents this year. Of these, 9% noted a significant rise, while 51% observed a slight increase. Third-party software risks are a major concern, with 23% of respondents identifying it as the primary risk to their organizations.
CISOs are increasingly aware of their reliance on third-party software vendors. A study by JumpCloud showed that enterprises use between 100 and 300 software-as-a-service applications, not accounting for cloud infrastructure and open-source components.
The survey indicates a rise in software supply chain attacks, as cybercriminals exploit the complexity of third-party components.
Visibility into third-party software supply chains is limited, with only 15% of respondents claiming full insight. Traditional vendor security questionnaires are still widely used, but 71% of CISOs find them inadequate for assessing third-party risk. As a result, two-thirds of CISOs are adopting AI-powered tools to enhance vendor risk assessment.
The adoption of AI tools is increasing, with CISOs recognizing the need for enterprise-wide risk management. AI enables automation in threat assessment, improving accuracy and reducing false positives.
Despite the benefits of AI, only 21% of CISOs have a comprehensive incident response plan for breaches related to external software suppliers. Larger organizations are more likely to have such plans, with 36% of CISOs at enterprises with 10,000 or more employees having proper incident response plans.
Panorays' founder and CEO, Matan Or-El, attributes the rise in third-party security vulnerabilities to the widespread adoption of AI tools but remains optimistic about AI's potential to address these challenges. "CISOs are increasingly seeing the value of AI-driven solutions to increase clarity around the evolving threat landscape," he stated.
Based on reporting by Cyber Security News.
