Guest post by Lee Bristow, Chief Technology Officer at Phinity Integrated Risk Management
As the value of personal data increases, so too does the consequence of data breaches. The responsibility of ensuring client and supplier data is kept safe, has become tantamount to a bank securely holding our cash.
This is an ethical Catch-22.
The business case for ethics and robotics
Most businesses, from global giants to SMEs, are more reliant on third parties to provide core business services. This is dependent on the sharing of essential client data with these parties. Hence, as a user, when signing away your data, you could be handing it over to unknown entities.
Who is responsible for this data? A client signs a deal with the contracting company, and it’s up to them to take ethical and legal responsibility to protect their clients’ information. It’s also the contracting business that will shoulder the dire consequences of resulting bad press and reputational damage for compromised data.
It’s no longer time that’s money
Data leads to money, one way or another.
The old chestnut that ‘data is the new oil’ springs to mind. As data value increases, so too does its desirability. More people want it. And more people are willing to go to criminal lengths to get it.
The convenience that the internet offers to us average users has also created leverage for scoundrels, who don’t even need to organise a getaway car anymore. Bonnie and Clyde robbing banks have been replaced with scammers and hackers hidden deep within the internet.
Data is less secure than ever
April 2020 saw an unusually high increase in cyber-attacks as people worked remotely, thanks to Covid. In that year, there was a general upsurge in data security breaches in the EU and UK of 10% (Lexology).
A survey in 2021 by the Ponemon Institute found that 51% of organisations experienced a data breach caused by third parties, resulting in the misuse of sensitive data.
There’s no doubt that using third parties massively increases risk.
And as more operations are outsourced, the complexity of relationships intensifies. So you’ve got a wobbly combination of greater relationship complexity and increased risk.
Third party risk management (TPRM)
Historically, the procurement department was responsible for third party contracts. Made sense.
But as the convolutions of these relationships become ever more intricate, and the risks spread their tendrils across the organisation, does it still do so?
An example of this was one of South Africa’s largest banks, Nedbank.
Using the services of SMS marketing provider, Computer Facilities, it experienced a data breach affecting 1.7 million of Nedbank’s clients. While the press pointed at Netbank, it wasn’t in fact the bank’s information security provision that was at fault.
However, Nedbank had engaged the supplier.
This begs the question: who was accountable? IT? Procurement? Marketing? Client services? The list goes on. It’s no longer just one division’s problem. From an information security issue, TPRM has become a privacy issue.
Large organisations tend towards rigidity in managing third parties. Their size simply doesn’t allow for flexibility in dealing with smaller start-ups. The only mitigation here, really, is for a more ethical attitude towards TPRM, and the use of automation.
More than just the law
While legal contracts are essential to third party relationships, they won’t repair the damage when the horse has bolted.
There are a few considerations when looking at mitigation strategies for data breaches: organisation size, jurisdiction, and types of service being supported. Organisations must do thorough due diligence on third party vendors, which it seems they’re not.
In the Ponemon survey, it was found that 51% of companies had not been assessing security and privacy practices and processes before granting access to sensitive and confidential data.
Deloitte ran some research on the current approaches to TPRM and the findings are grim. Fo...