#third-party risk
16 stories taggedthird-party risk.

Quest Apartment Hotels Investigating Customer Data Breach Tied to Third-Party Provider
Personal details of Quest guests, including names, email addresses and some dates of birth, were exposed after criminals broke into a database through a flaw in an outside supplier's system.

SickKids Says Third-Party Software Flaw Exposed Employee and Applicant Data
Toronto's largest paediatric hospital confirms a breach affecting HR records. Patient files were not touched.

A Survey Company May Have Leaked Scottish Government Workers' Personal Details
A contractor hired to run a government training exercise lost staff data from Scotland's public prosecution service. The real worry: dozens of other agencies probably handed over the same information.

LexisNexis Pulls Three Services Offline After Vendor Server Break-In
The data analytics giant disconnected Nexis Diligence, Metabase API and Newsdesk after spotting suspicious activity on a third party's servers, and is rebuilding the systems from scratch.

Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk
A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means, and why it matters to everyone.

Your Company's Vendor Problem Starts Before Anyone Calls Security
When businesses pick software first and ask security questions second, they hand criminals a head start. Here is why fixing that order matters, and what a grown-up process actually looks like.

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software
A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain is a masterclass in how cloud software trust goes wrong.

Your Bank May Be Sending Your Loan Details to TikTok Without Knowing It
New research finds that tracking tools baked into banking websites are quietly forwarding customers' personal and financial data to advertising platforms, sometimes before anyone clicks 'accept cookies'.

Ernst & Young Client Data Stolen in Third-Party Platform Breach
Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

Ernst & Young Tells Clients Their Tax Data Was Taken From a Support Ticket System
The Big Four firm says an outside party pulled documents from a third-party helpdesk platform between late March and mid-April. Affected clients get 24 months of identity monitoring through Experian.

Risk Ledger Raises £24 Million to Expand Its Supply Chain Security Network
The London firm wants more organisations checking each other's security hygiene in one shared space. Now it has the money to push into the US and build AI review tools.

What separates a good security engineer from a great one in 2025
New research and industry voices spell out exactly what companies should demand when hiring the people who keep their systems safe, and why the old checklist of certifications no longer cuts it.

Your Vendors Are a Risk You Cannot Ignore. Here Is How Boards Should Own It.
Most companies review their suppliers and tick the boxes. Far fewer can actually say how much financial damage a vendor failure would cause them. That gap is the problem.

Education Sector Faces Rising Threats from Third-Party Software Breaches
Schools and universities struggle with cybersecurity as breaches through third-party applications rise, highlighting the need for better vendor risk management.

TrustCloud Wants to Kill the Security Questionnaire. Here's the Pitch.
Continuous analysis of security, infrastructure, and governance data sounds compelling. Whether it replaces the questionnaire grind depends on what 'real-time' actually means at the data layer.