Welcome!

News Feed Item

Loss Impact of Third-Party Risks Can Easily Exceed $10 Million Reveals MetricStream Research

The report, "How Organizations Are Managing Third-Party Risks," surveyed executives in 40+ organizations across 15 industries to identify dominant trends in third-party risk management

PALO ALTO, Calif., March 20, 2017 /PRNewswire/ -- MetricStream Research has released its latest report, "How Organizations Are Managing Third-Party Risks," where approximately one in five respondents indicated that their organization has faced significant risk exposure due to a third party in the last 18 months; of those who shared loss data, 25% said that the loss impact was greater than $10 million. The report is based on a 2016 survey of executives in 40+ organizations, across 15+ industries, including financial services, retail, health care, pharmaceuticals, insurance, manufacturing, and telecom.

As companies outsource their processes or services, they expose themselves to a range of third-party risks, including data security risks, business disruptions, legal liabilities, corruption and bribery risks, and compliance risks – all of which have a major impact on profits and brand value. Fourth-party risk management is also emerging as a key area of focus, with organizations being held responsible not just for the actions of their immediate third parties, but also for the actions of their third parties' vendors and suppliers. Adding further impetus are regulations from authorities such as the Office of the Comptroller of the Currency (OCC) and the Consumer Financial Protection Bureau (CFPB), as well as mandates such as the UK Bribery Act and the Health Insurance Portability and Accountability Act (HIPAA), which stipulate stringent requirements for third-party governance.

To find out how organizations are managing their third-party risks in this regulatory climate, MetricStream surveyed professionals from risk management, compliance, legal, supplier management, audit, IT, and other business functions. The survey covered four primary areas: the responsibility for and ownership of third-party risks; the process of third-party risk assessment; the impact of third-party risk incidents and measures taken to resolve issues; and the role of technology in managing third-party risks.

Below are the key findings from the report:

  • 21% of respondents reported that their organizations faced risk exposure due to third parties in the last 18 months; of those who shared financial impact data on the losses, 25% said that the loss impact was greater than $10 million
  • The top three parameters on which third-party risks are assessed include:
    • Data protection
    • Financial viability
    • Maintaining service level agreements
  • Of the organizations with a dedicated third-party risk management function, 59% indicated that third-party risk management is included within their organizations' broader enterprise risk management function
  • 44% of respondents reported that their organizations don't have a dedicated third-party risk management function or a centralized third-party information repository
  • Nearly half of the respondents (48%) still use office productivity software to manage third-party risks
  • 73% of respondents do not track their fourth parties

Commenting on the survey findings, French Caldwell, Chief Evangelist, MetricStream said, "Increased enforcement from regulators like the US Department of Justice and the UK Serious Fraud Office underscores the importance of third-party risk management. However, as the survey results demonstrate, many organizations still don't have dedicated resources or effective tools to manage their third-party risks. If companies want to build truly beneficial relationships with their vendors or suppliers, they need to be more vigilant – and that means monitoring third parties more frequently based on the associated level of risk, establishing clearly defined roles and processes for third-party governance, and implementing integrated systems that give organizations the risk visibility they need to make informed decisions about their third parties."

To access the MetricStream Research report on third-party risk management, click here.

About MetricStream

MetricStream, the independent market leader in enterprise and cloud applications for Governance, Risk, Compliance (GRC) and Quality Management, makes GRC simple. MetricStream apps improve business performance by strengthening risk management, corporate governance, regulatory compliance, vendor governance, and quality management for hundreds of thousands of users in dozens of industries, including Financial Services, Healthcare, Life Sciences, Energy and Utilities, Food, Retail, CPG, Government, Hi-Tech and Manufacturing. MetricStream is headquartered in Palo Alto, California, with an operations and R&D center in Bangalore, India, and sales and operations support in 12 other cities globally. (www.metricstream.com)

Media Contact:
Molly Palm
US: +1 (925) 451-1468
[email protected]

To view the original version on PR Newswire, visit:http://www.prnewswire.com/news-releases/loss-impact-of-third-party-risks-can-easily-exceed-10-million-reveals-metricstream-research-300425498.html

SOURCE MetricStream

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Latest Stories
It is ironic, but perhaps not unexpected, that many organizations who want the benefits of using an Agile approach to deliver software use a waterfall approach to adopting Agile practices: they form plans, they set milestones, and they measure progress by how many teams they have engaged. Old habits die hard, but like most waterfall software projects, most waterfall-style Agile adoption efforts fail to produce the results desired. The problem is that to get the results they want, they have to ch...
No hype cycles or predictions of zillions of things here. IoT is big. You get it. You know your business and have great ideas for a business transformation strategy. What comes next? Time to make it happen. In his session at @ThingsExpo, Jay Mason, Associate Partner at M&S Consulting, presented a step-by-step plan to develop your technology implementation strategy. He discussed the evaluation of communication standards and IoT messaging protocols, data analytics considerations, edge-to-cloud tec...
Cloud Expo, Inc. has announced today that Andi Mann and Aruna Ravichandran have been named Co-Chairs of @DevOpsSummit at Cloud Expo Silicon Valley which will take place Oct. 31-Nov. 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. "DevOps is at the intersection of technology and business-optimizing tools, organizations and processes to bring measurable improvements in productivity and profitability," said Aruna Ravichandran, vice president, DevOps product and solutions marketing...
"When we talk about cloud without compromise what we're talking about is that when people think about 'I need the flexibility of the cloud' - it's the ability to create applications and run them in a cloud environment that's far more flexible,” explained Matthew Finnie, CTO of Interoute, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"Loom is applying artificial intelligence and machine learning into the entire log analysis process, from start to finish and at the end you will get a human touch,” explained Sabo Taylor Diab, Vice President, Marketing at Loom Systems, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
When growing capacity and power in the data center, the architectural trade-offs between server scale-up vs. scale-out continue to be debated. Both approaches are valid: scale-out adds multiple, smaller servers running in a distributed computing model, while scale-up adds fewer, more powerful servers that are capable of running larger workloads. It’s worth noting that there are additional, unique advantages that scale-up architectures offer. One big advantage is large memory and compute capacity...
We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
The Internet giants are fully embracing AI. All the services they offer to their customers are aimed at drawing a map of the world with the data they get. The AIs from these companies are used to build disruptive approaches that cannot be used by established enterprises, which are threatened by these disruptions. However, most leaders underestimate the effect this will have on their businesses. In his session at 21st Cloud Expo, Rene Buest, Director Market Research & Technology Evangelism at Ara...
In his session at @ThingsExpo, Eric Lachapelle, CEO of the Professional Evaluation and Certification Board (PECB), provided an overview of various initiatives to certify the security of connected devices and future trends in ensuring public trust of IoT. Eric Lachapelle is the Chief Executive Officer of the Professional Evaluation and Certification Board (PECB), an international certification body. His role is to help companies and individuals to achieve professional, accredited and worldwide re...
Wooed by the promise of faster innovation, lower TCO, and greater agility, businesses of every shape and size have embraced the cloud at every layer of the IT stack – from apps to file sharing to infrastructure. The typical organization currently uses more than a dozen sanctioned cloud apps and will shift more than half of all workloads to the cloud by 2018. Such cloud investments have delivered measurable benefits. But they’ve also resulted in some unintended side-effects: complexity and risk. ...
"We are a monitoring company. We work with Salesforce, BBC, and quite a few other big logos. We basically provide monitoring for them, structure for their cloud services and we fit into the DevOps world" explained David Gildeh, Co-founder and CEO of Outlyer, in this SYS-CON.tv interview at DevOps Summit at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
21st International Cloud Expo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Me...
SYS-CON Events announced today that Enzu will exhibit at SYS-CON's 21st Int\ernational Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Enzu’s mission is to be the leading provider of enterprise cloud solutions worldwide. Enzu enables online businesses to use its IT infrastructure to their competitive advantage. By offering a suite of proven hosting and management services, Enzu wants companies to focus on the core of their ...