Search

UBS Breach Highlights Third-Party Risk

The recent cyber attack on Chain IQ, a procurement service provider used by UBS and Pictet, serves as a stark reminder of the escalating risks associated with third-party vulnerabilities in the interconnected business landscape. This incident, which led to the leak of sensitive employee data from approximately 130,000 UBS staff, including the CEO's direct phone number, highlights a critical area where even financially robust organizations can be exposed. While both banks confirmed that no customer data was affected, the breach underscores the pervasive challenge of securing the entire supply chain.
bank

The Growing Threat of Third-Party Breaches

The UBS incident is not an isolated case. A report from SecurityScorecard reveals that an astonishing 96% of Europe’s largest financial services organizations have been impacted by a security breach at a third-party organization within the last two years. This figure represents a 25% increase compared to two years prior, indicating a rapidly worsening trend. Furthermore, 97% had experienced a breach via a fourth party – their partners’ partners. This pervasive vulnerability exists because organizations are increasingly reliant on a multitude of external suppliers for various systems, including critical administrative functions like human resources, which often handle sensitive employee data.

 

Experts in the banking sector point out that despite significant investments in internal security, organizations become reliant on their suppliers’ security postures once services are acquired. They often lack direct control or visibility into the day-to-day security activities of these third parties, creating “weak links” that attackers actively exploit.

 

Strengthening Your Defenses: A Proactive Approach to Supply Chain Security

For small and medium enterprises (SMEs) and larger corporations alike, the UBS breach is a powerful call to action. Addressing third-party risk is paramount to preventing cyberattacks and protecting valuable data. Here’s how businesses can enhance their cybersecurity program development to mitigate these risks:

 
  • Comprehensive Cyber Risk Management: Implement robust cyber risk management frameworks that specifically include third-party and fourth-party assessments. This involves understanding the security posture of every vendor and sub-vendor with access to your systems or data.
     
  • Thorough Security Assessments and Audits: Conduct regular cybersecurity assessments and security audits of your suppliers. This should include security gap assessments to identify vulnerabilities in their systems and processes before a breach occurs. Consider requiring penetration testing from your critical vendors.
  • Vendor Due Diligence and Contractual Obligations: Before engaging with any supplier, perform extensive due diligence. Ensure contracts include stringent cybersecurity requirements, right-to-audit clauses, and clear protocols for incident response and data breach notification.
  • Managed Security Services: Leverage managed security services that can extend monitoring and threat detection capabilities across your entire digital ecosystem, including third-party integrations. This provides continuous oversight where your direct control might be limited.
  • Data Privacy Services and Compliance: Reinforce your data privacy services and ensure compliance services like GDPR compliance, ISO compliance , and NIST compliance are extended to how your vendors handle data. Even employee data leaks can have significant regulatory and reputational consequences.
  • Cybersecurity Best Practices for All: Promote cybersecurity best practices throughout your organization and encourage your suppliers to do the same. This includes ongoing security awareness programs and threat intelligence sharing.
     

The UBS incident is a stark reminder that in today’s interconnected world, an organization’s security is only as strong as its weakest link. Proactive cybersecurity consulting services and a focus on third-party risk are no longer optional but essential components of a resilient defense strategy.