Third party IT data breaches major risk for companies, finds Deloitte

Image

Almost nine in 10 (87%) organisations have faced a disruptive incident involving third parties in the last three years, such as loss of data or failure to deliver a service or product in time, according to research by Deloitte which suggests many businesses are failing to manage the risks involved in using external suppliers for essential services

 

The firm’s 2016 global survey on third party governance and risk management is based on the responses of over 170 senior members of management from a variety of sectors.

Of those organisations which reported experiencing a disruptive incident, 28% said they faced major disruption and 11% experienced a complete third party failure.

Looking at the impact of incidents experienced, Deloitte found that 26.2% resulted in reputational damage; 23% in financial or transaction reporting errors; 23% in noncompliance with regulatory requirements; 20.6% with a breach of customer sensitive data; and 10.3% in loss of business.

With cost savings, followed by quality improvements, cited as the key drivers for using third parties, Deloitte found that 73.9% of respondents believe that third parties will play a highly important, or even critical, role in the year ahead, up from 60.3% a year or more earlier.

However, of the organisations surveyed, nearly all (94.3%) felt low to moderate levels of confidence in the tools and technology currently used to manage their third party risk, with similar sentiment expressed in supporting risk management processes (88.6%).

Kristian Park, partner and global head of third party governance and risk management at Deloitte, said: ‘With reliance on third parties set to grow, now is the time to address the “execution gap” between risk and readiness.

‘The good news is that third party risk management is starting to feature consistently in board-level discussions. Our latest survey found over half (51.1%) of respondents were united in their ambition to have integrated third party risk management systems in place in the year ahead.

‘Rolling out common and unified standards remains a challenge as businesses are increasingly decentralised. Encouragingly, though, 86% of those surveyed have already started.’

 The Deloitte survey found that the most popular way of assessing risk from third parties was to make visits to third party locations, cited by 69.5%, while in-house internal audit was favoured by 62.7%.

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe