Lack of visibility creates "cascade" of security risk, says Kiteworks
Briefly

Lack of visibility creates "cascade" of security risk, says Kiteworks
"Organizations are flying blind when it comes to tracking data breaches, AI use, and their third-party counts. According to a survey of 461 organizations across North America, Europe, APAC, and the Middle East by Kiteworks, 46% of companies that don't know their third-party count also don't know their breach frequency. Meanwhile, 48% of those that are uncertain about breaches can't quantify litigation costs, 36% of those unaware of AI usage are implementing zero privacy technologies,"
""Our survey reveals a fundamental truth about modern data security: What you don't know doesn't just hurt you - it multiplies exponentially," said Tim Freestone, CMO of Kiteworks. "Organizations operating blind face dramatically worse outcomes across every metric we measured. The cascade effect is undeniable: unknown third-party relationships lead to missed breaches, which prevent compliance demonstration, which results in massive costs.""
"When it comes to third parties, having between 1,001 and 5,000 appears to be the danger zone. Of these firms, 24% face at least seven breaches a year - the worst of any segment. Meanwhile, 46% report the highest supply chain risk, and 42% said they take between 31 and 90 days to detect breaches. And this is costing companies dear, with organizations with faster detection showing significantly lower litigation costs."
Many organizations lack basic visibility into third-party counts, breach frequency, AI usage, and detection timelines. Firms uncertain about third-party relationships often cannot quantify breach frequency or litigation costs. Companies with 1,001–5,000 third parties report the highest breach rates, elevated supply-chain risk, and longer detection windows of 31–90 days. Faster breach detection correlates with substantially lower litigation costs; more than three-quarters of organizations experiencing over 10 hacks face litigation costs of at least $3 million. AI governance is weak: only 17% have full technical AI governance and 36% with unknown AI usage deploy no privacy-enhancing technologies. Energy, utilities, technology, life sciences, and pharma show the highest risks.
Read at IT Pro
Unable to calculate read time
[
|
]