And it gets worse: A low 31% of
respondents include security provisions
in contract negotiations with external
vendors and suppliers. It is imperative
that organizations hold third-party
partners to the same—or higher—
cybersecurity standards that they set for
themselves. Compliance should be
mandated in contracts.
Finally, an organization’s size matters
when it comes to handling insider threats
of all types. Larger organizations not
only understand the potential impacts of
insider incidents, but they also tend to
have more mature security practices
than smaller companies and, as a result,
are also more likely to have an
information security department that is
in charge of responding to incidents. We
also found that large organizations
(those with 10,000 or more employees)
use advanced technologies such as
malware analysis, threat subscription
services, and threat modeling to address
overall cybersecurity risks.