TPRM Archives - 8iSoft | Smart Security Solutions https://www.8isoft.com/tag/tprm/ AI-powered vulnerability remediation and management platform Fri, 14 Mar 2025 14:54:06 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.3 /wp-content/uploads/2022/12/cropped-8iSoft-Logo_512-1-32x32.png TPRM Archives - 8iSoft | Smart Security Solutions https://www.8isoft.com/tag/tprm/ 32 32 Third-Party Risk Management in Banking Industry  https://www.8isoft.com/third-party-risk-banking/ Fri, 14 Mar 2025 14:54:05 +0000 https://8isoft.com/?p=5052 Banks and financial institutions depend heavily on outsourcing to third-party...

The post Third-Party Risk Management in Banking Industry  appeared first on 8iSoft | Smart Security Solutions.

]]>
Banks and financial institutions depend heavily on outsourcing to third-party vendors for essential services. Banks partner with a range of suppliers like IT service providers, payment and administrative services, data analytics firms, and cloud storage providers. While these partnerships enhance operational efficiency, they also introduce significant risks to financial institutions. 

When third-party vendors fail to meet security or compliance standards, banks face vulnerabilities that can lead to data breaches, financial losses and reputational damage. For instance, in the 2024 Truist Bank Data Breach, a breach in a third-party debt collector exposed customer data including names, addresses, dates of birth, social security numbers, driver’s license numbers. Given the sensitive nature of financial data and complex regulatory requirements, Third Party Risk Management (TPRM) is critical for the banking industry. 

I. Key Third-Party Risks in Banking 

Banks handle vast amounts of sensitive financial data, making them prime targets for cybercriminals. Below are the primary third-party risks in the banking sector: 

  • Cybersecurity Risks: Third-party vendors often have access to critical IT systems and sensitive customer data, creating vulnerabilities. Financial institutions have been targeted through third-party service providers, resulting in data breaches that compromise customer information. 
  • Compliance Risks: Banking industry regulations such as the GDPR and FFIEC guidelines impose strict requirements on data protection, risk assessment, and vendor management. Compliance for banks is important as failing to meet them can lead to significant fines and penalties, impacting the bank’s operations and finances. 
  • Operational Risks: Banks rely on third-party vendors for crucial services, from technology solutions to payment processing. Any disruption from these vendors can lead to service outages, affecting customer experience and continuity in operations. 
  • Reputational Risks: Public trust is fundamental to financial institutions. A failure by a third-party vendor that results in data exposure or non-compliance can damage a bank’s reputation, making customers and investors question its reliability. 

II. Regulations Impacting TPRM in Banking 

The banking industry is bound by numerous compliance requirements. These regulations are designed to ensure stability, security, consumer protection, and prevent financial crimes. Key regulations on third party risks include: 

  1. FFIEC (Federal Financial Institutions Examination Council): The FFIEC issues guidelines specifically for third-party risk management in financial institutions. FFIEC mandates that financial institutions conduct vendor cybersecurity risk assessments and continuous monitoring, to ensure that third parties meet FFIEC standards for security and data integrity.  
  1. GLBA (Gramm-Leach-Bliley Act): Banks must ensure that third-party providers handling sensitive customer data comply with the GLBA’s Privacy and Safeguards Rules, which require strict data security measures to prevent unauthorized access and data breaches. 
  1. OCC (Office of the Comptroller of the Currency): The OCC’s guideline for ‘Third-Party Relationships: Risk Management Guidance’ require banks to implement a TPRM program that thoroughly assesses vendors’ risk exposure. It outlines expectations for vendor due diligence and ongoing monitoring. 
  1. GDPR (General Data Protection Regulation): Banks must ensure that third-party vendors processing EU personal data adhere to GDPR requirements for data protection and privacy.  
  1. PCI DSS (Payment Card Industry Data Security Standard): Banks and financial institutions must ensure that any third party involved in card processing complies with PCI DSS to protect against data breaches and safeguard cardholder information. 
  1. FINRA (Financial Industry Regulatory Authority): FINRA’s regulations extend to third-party vendors providing financial services to broker-dealers. Financial institutions need to verify that their third-party providers align with FINRA’s standards, particularly in customer data protection and cybersecurity. 
  1. SOX (Sarbanes-Oxley Act): Financial institutions need to ensure that third-party vendors follow internal control standards and provide accurate financial reporting.   

Impact of Non-Compliance 

Non-compliance with these regulations can lead to severe consequences, including substantial fines, legal actions, restrictions on business operations and reputational damage. For example, failing to adhere to GDPR standards for data protection in Europe can result in fines of up to 4% of annual global revenue. 

III. Challenges in Third Party Risk Management for Financial Institutions 

Vendor Resistance to Risk Assessments 

Many vendors may resist undergoing frequent audits and assessments due to concerns over time and resources required. Financial institutions can address this by setting clear expectations from the start, emphasizing that these assessments are necessary for continued partnerships. 

Rapidly Changing Regulatory Landscape 

With new regulations constantly emerging, banks need to keep their TPRM programs up to date. This is especially challenging for global financial institutions that must constantly monitor and comply with many different international regulations. 

Cross-Border Data Sharing 

When working with international vendors, banks must navigate complex data transfer laws for each country. For proper cross-border data handling, banks need strict controls to ensure they stay compliant with each country’s privacy regulations. 

IV. Best Practices for Implementing a TPRM Program in Financial Services 

Use Third Party Risk Management Software 

To effectively manage third-party risks, banks and financial institutions should adopt a TPRM software like Alliance that offers automation and continuous monitoring capabilities. The ideal vendor risk management software should automate risk assessment and risk scoring, track vendor compliance in real time with continuous monitoring and provide alerts on any new vulnerabilities or regulatory changes.   

Set Clear Vendor Management Policies 

Banks should establish clear policies that define risk tolerance levels, vendor due diligence requirements and compliance standards. These policies should align with regulatory requirements and be communicated to all third-party partners. 

Conduct Regular Vendor Risk Assessments 

Assess risks both before onboarding a vendor and periodically afterward. These assessments should evaluate vendors’ security practices, financial stability, regulatory compliance, and business continuity plans.  

Ensure Strong Contractual Agreements 

Contracts with third-party vendors should include detailed clauses on compliance obligations, data protection standards, and penalties for non-compliance. This ensures that vendors are legally obligated to adhere to risk management practices that align with the bank’s standards. 

Regularly Review and Update Risk Management Frameworks 

Financial institutions must keep their risk management frameworks adaptable to respond to new regulations and emerging threats. Regular assessments and updates to TPRM frameworks ensure that banks stay compliant and secure. 

Educate and Train Staff 

Employee training is crucial for minimizing third-party risks, as employees need to understand potential vulnerabilities associated with third parties and how to address them. Training programs should cover compliance standards, data privacy laws, vendor security protocols and incident response procedures.  

Conclusion 

The European Banking Supervision have warned that the number of outsourcing contracts with third parties and the budget allocated by banks for outsourcing has increased significantly. This rapid growth of digitalization in fintech highlights the need for strict third-party risk management. Staying proactive to supply chain risks with TPRM software like Alliance is critical for ensuring that third party relationships contribute positively to the banks’ innovation and growth without compromising security or regulatory compliance. 

The post Third-Party Risk Management in Banking Industry  appeared first on 8iSoft | Smart Security Solutions.

]]>
A Guide to Third Party Risk Management in Manufacturing Industry  https://www.8isoft.com/tprm-in-manufacturing/ Wed, 20 Nov 2024 07:42:20 +0000 https://8isoft.com/?p=4942 Introduction   From raw material providers to logistics and tech partners,...

The post A Guide to Third Party Risk Management in Manufacturing Industry  appeared first on 8iSoft | Smart Security Solutions.

]]>
Introduction  

From raw material providers to logistics and tech partners, the manufacturing industry relies heavily on third party vendors and suppliers to maintain production flow and efficiency. However, as this dependency increases, so do the risks associated with them.  

In the last few years, third party risks have increasingly impacted the manufacturing sector. One infamous incident is the 2022 Nissan Data Breach, where a poorly configured database in the car manufacturer’s software vendor had exposed over 18,000 customer records including personal and financial details. Managing these risks through proper third party risk management (TPRM) has thus become an essential in modern manufacturing. 

I. Understanding Third-Party Risks in Manufacturing Industry 

Third-party relationships in the manufacturing supply chain introduce a wide range of risks. Below are some of the most common risks that manufacturers encounter when working with external vendors and suppliers. 

Types of Third-Party Risks: 

  • Operational Disruptions: Cyberattacks on key suppliers can halt production, impacting productivity and revenue.
  • Cybersecurity Risks: Vendors with access to sensitive data can be a source of cyber threats, leading to data breaches or other cybersecurity incidents. 
  • Compliance Risks: Vendors who fail to meet cybersecurity standards can place the manufacturer at risk of non-compliance with industry regulations, resulting in fines or legal issues. 
  • Reputational Damage: A cybersecurity breach at a vendor’s site can harm the manufacturer’s reputation, affecting customer confidence and business relationships. 

Common Scenarios in Manufacturing 

Some typical examples when third-party issues may arise are: 

  • Data Breach: A cybersecurity vulnerability within a third party system could expose sensitive manufacturing or customer data. 
  • Supply Chain Cyber Threats: Compromised vendors may unknowingly introduce malware or other security risks into the manufacturer’s network. 
  • Non-Compliance with Cyber Standards: A vendor’s failure to meet cybersecurity standards could impact the manufacturer’s compliance status, leading to penalties or operational restrictions. 

II. Why is Third Party Risk Management Important for Manufacturing  

Third Party Risk Management (TPRM) is critical for protecting the manufacturing supply chain, offering a structured approach to identifying, assessing, and managing risks posed by vendors and suppliers. Here’s how TPRM enhances safety, productivity, and compliance: 

  • Supply Chain Risk Monitoring: Manufacturers often rely on a complex web of global suppliers, exposing them to increased risk of disruption. A TPRM software like Alliance allows for proactive risk assessment and monitoring, helping to reduce vulnerabilities across multiple suppliers. 
  • Compliance with Industry Standards: The manufacturing sector operates under specific standards, such as ISO 9001 for quality management and CTPAT (Customs-Trade Partnership Against Terrorism) for import/export security. A strong TPRM program ensures that vendors meet these standards, reducing the likelihood of compliance-related disruptions. 
  • Cybersecurity as a Priority: TPRM in manufacturing emphasizes securing data shared with third party vendors and ensures compliance with cybersecurity standards, safeguarding against cyber threats. 

III.  Key Components of an Effective TPRM Program for Manufacturing 

Implementing a strong TPRM program involves several components tailored to the unique needs of the manufacturing industry: 

  • Risk Assessment & Classification: Identifying and classifying vendors based on the level of risk they pose is essential. Manufacturers should categorize third party vendors into high, medium, or low-risk groups, focusing more on those deemed critical. 
  • Due Diligence Vendors: A comprehensive onboarding process and due diligence are crucial for ensuring that each vendor aligns with the company’s compliance, quality, and cybersecurity requirements. This process may involve audits, certifications, and background checks. 
  • Continuous Monitoring: Risk management is an ongoing process, and TPRM programs should include continuous risk monitoring of vendors. Metrics such as incident response time, service-level agreement (SLA) compliance, and audit outcomes provide insights into vendor performance over time. 
  • Cybersecurity Protocols for Third Parties: As manufacturers share data and access with third parties, they must ensure these vendors adhere to strict cybersecurity protocols. These may include encryption standards, regular security assessments, and requirements for multi-factor authentication. 
  • Incident Response Plans: It’s essential to prepare for potential disruptions by having a risk mitigation and incident response plan. This includes outlining strategies for addressing vendor-related issues, such as alternative suppliers for critical materials and predefined steps for managing data breaches. 

Conclusion  

In the face of rising third-party risks, manufacturers need a proactive approach to compliance and risk management. With a third party risk management software like Alliance TPRM, manufacturers gain deeper visibility and control over managing third party vendors, helping them mitigate this risk.  By prioritizing Third Party Risk Management, manufacturers can better strengthen their supply chains against potential vulnerabilities, monitoring suppliers, managing risks and meeting compliance needs– all in one place. 

The post A Guide to Third Party Risk Management in Manufacturing Industry  appeared first on 8iSoft | Smart Security Solutions.

]]>
2024 Top Third-Party Data Breaches and Lessons Learned  https://www.8isoft.com/2024-top-third-party-data-breach/ Mon, 28 Oct 2024 02:50:49 +0000 https://8isoft.com/?p=4872 Introduction  As more businesses depend on third party vendors and...

The post 2024 Top Third-Party Data Breaches and Lessons Learned  appeared first on 8iSoft | Smart Security Solutions.

]]>
Introduction 

As more businesses depend on third party vendors and service providers, the risk of data breaches from these partners is growing quickly. A recent 2024 Third Party Risk Management study revealed that 61% of companies have experienced third-party data breaches over the past year—a 49% increase from 2023 and three times higher than in 2021. It’s a clear wake-up call that stronger Third-Party Risk Management (TPRM) solutions are needed to protect supply chains, cloud systems and sensitive data. 

The increase in third-party breaches comes down to a few factors. Companies now rely heavily on external vendors to manage sensitive data, perform critical functions, and maintain IT infrastructures. However, many vendors do not follow strict security protocols, leaving data more vulnerable to cyberattacks. As these attacks become more sophisticated, businesses must adopt advanced enterprise risk management practices to protect themselves from potential threats. 

Third-Party Data Breaches in 2024 

Here’s a look at nine recent data breaches in 2024, along with key lessons businesses can take from each incident. 

1. Truist Bank Data Breach (October 2024) 

  • What Happened? A third-party debt collection service provider for Truist Inc., Financial Business and Consumer Solutions, Inc. (FBCS), experienced a breach that exposed Truist Bank’s sensitive data. 
  • Data Compromised: Sensitive Truist Bank information, including client data, was exposed to unauthorized access. 
  • 💡 Tip: This highlights the importance of vetting third party vendors for strong security practices, as the risks posed by third-party service providers can have significant consequences for your business. To minimize these risks, continuous monitoring of third party data and risk handling is essential. Using a third-party risk management software like Alliance TPRM can help automate and streamline the process, providing real-time, continuous monitoring of your vendors’ security practices. 

2. Toyota Data Breach (September 2024)  

  • What Happened? In a major Toyota breach, a cybercriminal group known as ZeroSevenGroup hacked into an undisclosed third party supplier of Toyota’s U.S. branch, leaking 240GB of sensitive data on a hacking forum. 
  • Data Compromised: This Toyota security incident exposed customer and employee data, contracts, financial information, and network credentials. 
  • 💡 Tip: Securing both internal networks and third-party systems is essential. Strong encryption and access controls should be in place to limit the risk of exposure. 

3. Infosys McCamish, Bank of America Data Breach (September 2024) 

  • What Happened? Infosys McCamish, a subsidiary handling insurance and financial services for major clients like Bank of America and Fidelity, was hit by the Lockbit ransomware, leading to the exposure of sensitive customer data. 
  • Data Compromised: Financial and personal data of Bank of America and Fidelity customers. 
  • 💡 Tip: Organizations need robust incident response plans and regular vulnerability assessments, particularly when handling high volumes of financial data. Ransomware defenses must include advanced threat detection systems. 

4. Fortinet Data Breach (August 2024) 

  • What Happened? Unauthorized access to a third party cloud-based file drive used by Fortinet exposed customer data. 
  • Data Compromised: The Fortinet breach exposed limited data related to a small number of their customers 
  • 💡 Tip: Businesses must ensure their third-party cloud storage solutions implement stringent security measures, including multi-factor authentication (MFA) and regular audits. 

5. CMS/WPS Insurance Breach (July 2024) 

  • What Happened? The Centers for Medicare & Medicaid Services (CMS) notified nearly a million Medicare beneficiaries of a breach at a CMS contractor that handles Medicare claims, Wisconsin Physicians Service Insurance Corporation (WPS). The breach occurred due to a vulnerability in MOVEit software, a third-party application used by WPS for transferring files for Medicare. 
  • Data Compromised: Protected health information (PHI) and personally identifiable information (PII) of Medicare beneficiaries (name, social security number, taxpayer identification number, date of birth, Medicare beneficiary identifier, health insurance claim number, etc.) 
  • 💡 Tip: Regular patching and software updates are critical to prevent known vulnerabilities from being exploited. Vendor security testing is essential to reduce exposure to such risks. 

6. Ticketmaster Breach (July 2024) 

  • What Happened? Ticketmaster suffered a data breach after an unauthorized third party obtained access to customer payment and account information from a cloud database hosted by a third-party data services provider. 
  • Data Compromised: Ticketmaster payment info and personal data, including credit card details and account information of customers, were exposed. 
  • 💡 Tip: Implementing strict access control measures and conducting regular cloud audits can help mitigate the risk of unauthorized access. 

7. Shopify Data Breach (July 2024) 

  • What Happened? Shopify experienced a breach due to a third-party app’s vulnerability, exposing customer information. 
  • Data Compromised: Customer data like Shopify IDs, full names, email addresses, mobile phone numbers, order counts, total money spent, SMS and email subscriptions. 
  • 💡 Tip: Ensure that third-party applications integrated into platforms like Shopify follow strict security protocols. Continuous monitoring and vulnerability scanning of third-party apps is critical to reduce the risks of unauthorized data access. 

8. American Express Data Breach (June 2024) 

  • What Happened? A third-party merchant processor exposed American Express credit card data due to a security lapse. 
  • Data Compromised: The Amex data breach exposed customer credit card data, putting individuals at risk for fraud. 
  • 💡 Tip: Payment processors must strictly adhere to PCI DSS (Payment Card Industry Data Security Standard). Card companies should implement robust monitoring to detect fraud early. 

9. Cisco Duo Security Breach (May 2024) 

  • What Happened? A telecom provider experienced a phishing attack and exposed Cisco Duo MFA codes. 
  • Data Compromised: Cisco Duo MFA authentication codes and logs were accessed by attackers. 
  • 💡 Tip: Even multi-factor authentication (MFA) solutions are vulnerable to phishing attacks, necessitating additional layers of defense such as phishing-resistant MFA solutions and better user education. 

How Alliance Can Help Prevent Third-Party Data Breaches 

To mitigate the growing risk of third-party breaches, companies must adopt a robust Third-Party Risk Management (TPRM) solution. Alliance TPRM is a risk management software specifically for third party vendors and suppliers. It offers businesses an easier and more efficient way to manage vendors, ensuring compliance with information security and regulatory standards. 

With Alliance, you can streamline the whole cycle of the supply chain risk management process: 

  1. Vendor Risk Assessment: Automatically assess potential vendors with detailed risk assessments to ensure they meet stringent security and compliance standards before engagement. 
  2. Continuous Monitoring: Alliance provides real-time monitoring of third-party activities, enabling quick detection of any potential risks or compliance issues. 
  3. Risk Identification: Use AI to identify and address vulnerabilities early, facilitating proactive measures to prevent disruptions to the supply chain. 
  4. Centralized Management: Easily manage all supplier documents (contracts, certificates, compliance reports, etc.) on one platform for improved operational efficiency. 
  5. Regulatory Compliance: Ensure that vendors comply with security and ESG governance standards.  

By integrating a solution like Alliance TPRM, businesses can prevent third-party breaches, protect sensitive data, and maintain strong vendor relationships. 

The post 2024 Top Third-Party Data Breaches and Lessons Learned  appeared first on 8iSoft | Smart Security Solutions.

]]>
Managing Third Party Risks: How to Prevent Third Party Data Breach  https://www.8isoft.com/how-to-prevent-third-party-data-breach/ Tue, 28 May 2024 05:25:18 +0000 https://8isoft.com/?p=4574 What is a Third Party Data Breach & How Does...

The post Managing Third Party Risks: How to Prevent Third Party Data Breach  appeared first on 8iSoft | Smart Security Solutions.

]]>
What is a Third Party Data Breach & How Does it Affect you?  

Third Party Data Breach Definition | Third Party Data Breach vs. Data Breach 

A third party data breach is a specific type of data breach that occurs when a third party vendor has been breached, resulting in the unauthorized access, disclosure, or compromise of your sensitive data. 

A data breach refers to when your sensitive data is accessed without authorization. This can happen through various means, including cyberattacks, insider threats, or accidental exposures.

In a third party data breach, the breach occurs not within your organization’s own systems, but through a third party that has access to your data. The definition of a third party is any organization that provides goods or services for your use. Some examples of a third party vendor include: 

  • Software as a Service (SaaS) providers like Customer Relationship Management (CRM) systems 
  • Suppliers 
  • Marketing agencies 
  • Outsourced Functions
  • Contractors like an external accounting firm managing financial data or law firm providing legal services 

Consequences of Third Party Data Breaches 

When a third-party vendor or partner causes a data breach, it damages the trust in business relationships and could lead to strained communication, renegotiation of contracts or even termination of the relationship. Rebuilding these relationships takes time and effort, making it harder to work together in the future. Besides that, there are several other risks that can arise from a data breach caused by third parties: businesses also face financial losses, legal and regulatory compliance penalties, operational disruptions and damage to their reputation, which overall compromises customer trust and loyalty. 

Causes of Third Party Data Breach  

A third-party data breach is caused by a third party vendor holding your company’s data getting hacked. Hackers target vulnerabilities in the third party’s system and gain access to it, compromising the security of your sensitive information. This breach can occur due to various factors, including inadequate network and information security measures, insider threats, or social engineering attacks targeting employees of the third party: 

  1. Inadequate Security Practices: Third-party vendors may have insufficient security measures in place to protect sensitive data, such as weak password policies, outdated software, lack of encryption protocols, and other vulnerabilities that can be exploited by hackers. 
  1.  Insider Threats: Employees or contractors of third-party vendors may pose an insider threat by intentionally or accidentally compromising data security. This could involve malicious actions such as stealing sensitive information or inadvertently exposing data through careless behavior or negligence. 
  1. Lack of Oversight: Businesses may fail to monitor their third-party vendors and may unknowingly partner with vendors that have weak security postures, increasing the risk of a data breach. 
  1. Shared Access and Permissions: Third-party vendors often require access to sensitive data or systems to fulfill their contractual obligations. However, granting excessive permissions or failing to implement proper access controls can increase the risk of unauthorized access and data exposure. 
  1. Social Engineering Attacks: Cyber attackers may use social engineering techniques to manipulate employees of third-party vendors into disclosing sensitive information or providing access to systems. Phishing emails, pretexting, and other tactics can trick unsuspecting employees into inadvertently facilitating a data breach. 

Understanding these causes can help businesses identify potential vulnerabilities in their relationships with third-party vendors and implement proactive measures to mitigate the risk of a data breach. 

How to Prevent Third Party Data Breach  

Preventing third-party data breaches requires a proactive approach to managing third party risks and mitigating them. Businesses can utilize third party risk management (TPRM) tools for this. 

Third party risk management (TPRM) tools like Alliance TPRM are specifically designed to assess and manage the security risks associated with third-party vendors and partners. These tools enable businesses to conduct comprehensive risk assessments, monitor vendor performance, and track compliance with security requirements and contractual obligations. By centralizing vendor risk information and providing visibility into the entire vendor ecosystem, tools like Alliance empower organizations to make informed decisions about vendor relationships and ensure that appropriate security measures are in place to protect sensitive data. 

Here is how Third-Party Risk Management (TPRM) tools like Alliance can help businesses strengthen their defense against third-party data breaches: 

  1. Comprehensive Risk Assessment: TPRM tools enable businesses to conduct comprehensive risk assessments of their third-party vendors and partners. By evaluating factors such as security practices, data handling procedures, and regulatory compliance, businesses can identify potential vulnerabilities and assess the level of risk posed by each vendor. 
  1. Continuous Monitoring: TPRM tools facilitate continuous monitoring of third-party vendors, allowing businesses to stay informed about changes in risk posture and security incidents. By proactively monitoring vendor performance and security practices, businesses can detect and respond to emerging threats or vulnerabilities in a timely manner. 
  1. Risk Prioritization: TPRM tools help businesses prioritize risk mitigation efforts based on the severity of vulnerabilities and the criticality of the assets involved. By focusing resources on high-risk vendors or systems, businesses can allocate resources more effectively and address the most pressing security concerns first. 
  1. Contractual Safeguards: TPRM tools also assist businesses in implementing robust contractual agreements with third-party vendors that include specific security requirements, responsibilities, and expectations. By incorporating provisions for data protection and breach notification into contracts, businesses can establish clear guidelines for vendor security and accountability. 
  1. Streamlined Compliance: TPRM tools help businesses streamline compliance efforts by providing centralized visibility into vendor compliance with regulatory requirements, industry standards, and contractual obligations. By automating compliance assessments and reporting processes, businesses can ensure that vendors meet the necessary security standards and mitigate compliance-related risks. 

Third Party Data Breach Example: Okta Breach 2023 

One notable example of a third party data breach is the Okta Data Breach in 2023. A cyberattack at Rightway Healthcare, a third-party vendor used by Okta for healthcare services, had exposed the personal and healthcare data of almost 5000 Okta employees. The data leak was of personal information files from April 2019 to 2020, and included data like names, social security numbers and health insurance plan numbers.  

As response, Okta stated that they would review their relationship with Rightway Healthcare. Okta also emphasized that this third-party data breach did not compromise the safety of any Okta customers, nor did it impact any Okta services. As for employees who were affected by the breach, they were offered two years of free credit monitoring, identity restoration and fraud detection services through Experian’s IdentityWorks product. 

Despite the breach stemming from a third-party vendor, Okta still suffered significant consequences from the breach. This shows just how important it is to ensure and maintain a strong security posture, not only within your organization but also among your partners — thus highlighting the critical importance of implementing Third Party Risk Management (TPRM) tools. With TPRM tools like Alliance, you could assess and monitor the security practices of your third-party vendors, reducing the risk of data breaches like the one experienced by Okta. 

The post Managing Third Party Risks: How to Prevent Third Party Data Breach  appeared first on 8iSoft | Smart Security Solutions.

]]>