Skip to content
DWB_Master_Logo_2022-08-05_WithTrademark_Dual_Dark_Web
  • Platform
  • Professional Services
  • Markets
  • News & Views
  • About
    • Company Overview
    • Leadership
    • Partners
    • Careers and Culture
    • Awards
  • Contact
  • Platform Login
  • Platform
  • Professional Services
  • Markets
  • News & Views
  • About
    • Company Overview
    • Leadership
    • Partners
    • Careers and Culture
    • Awards
  • Contact
  • Platform Login
Request a Demo

Request a Demo

    Back to All News
    August 29, 2023-Vendor Due Diligence-Simon Eyre

    Exploitation of MOVEit software demonstrates the criticality of vendor due diligence

    This can be a hard truth for alternative investment managers to stomach: It’s not a matter of if you’re attacked, but when. Several investment managers learned this the painful way when a method exploiting MOVEit, a third-party file transfer software, was used to attack their firms.

    We know that securely transferring files between businesses can be a challenge. For many alternative investment firms, the default method for sending files is email, which results in mistakes and a loss of control once the send button has been clicked. Using a solution like MOVEit makes the file transfer process easier, and presumably safer. But unless a vendor due diligence procedure was performed on a third-party tool like MOVEit, there is no way to know if this file transfer method is truly secure.

    Over two-thirds of attacks that resulted in a loss of confidential data were due to third-party service providers[1]. While around 10% of the victims were related to the finance industry, once you include potential service providers those numbers rocket up to about 1,000 businesses affected and a large portion of the 50 million total individuals whose sensitive data was exposed[2].

    Here lies the most difficult part for the IT, operations, and compliance departments within a fund (or for your outsourced providers of those services): How can you ensure that your corporate cybersecurity standards maintain a comparable level at the service providers? Case in point, until this incident occurred with MOVEit, using this third-party vendor would not have raised any red flags.

    If you have performed vendor risk assessments and as part of that process, you have highlighted the technology involved in service delivery and you are better equipped to respond to an incident swiftly.

    Imagine the scenario:

    Cybersecurity Officer – “There is new threat intelligence to suggest the software MOVEit might be compromised. I’ve looked through our vendor due diligence and we use it with the fund admin provider.”

    Operating Officer – “Great, thank you. Let’s pull our files off the server until our back-office team can discuss with the fund admins and send files another way.”

    The above is a far smoother process than:

    “The back office has reported our fund admin was breached last week and we might have lost some data, we don’t know how or what might have happened yet.”

    Any good cybersecurity program begins with highlighting the key risks for a business. With over 60% of breach incidents[3] coming from third parties, addressing cybersecurity risk in your third-party vendors is paramount to keeping your firm and your investors’ assets safe.

    Sources:

    [1] https://konbriefing.com/en-topics/cyber-attacks-moveit-victim-list.html#:~:text=All%20details%20below-,How%20affected%3F,-Affected%20overall

     

    [2] https://konbriefing.com/en-topics/cyber-attacks-moveit-victim-list.html#:~:text=MOVEit%20breach%20victims

     

    [3] https://www.verizon.com/about/news/ransomware-threat-rises-verizon-2022-data-breach-investigations-report#:~:text=62%20percent%20of%20System%20Intrusion%20incidents%20came%20through%20an%20organization%E2%80%99s%20partner

     

    Tags:

    Vendor Due Diligence
    DWB_Master_Logo_2022-08-05_WithTrademark_White_Dual_Dark_Web

    Platform

    • Holistic Program Management

    • Vulnerability Management

    • Vendor Due Diligence

    • Portfolio Company Due Diligence

    • Cyber Risk Assessment

    • Regulatory Assessment

    • Cloud Security Assessment

    • Dark Web Monitoring

    • Penetration Testing

    Professional Services

    • Let’s Get Started

    • Cybersecurity Training

    • Cybersecurity Advisory

    • Policy Creation & Gap Analysis Advisory

    • Data Privacy

    • Business Continuity

    Markets

    • Private Equity, Venture Capital & Portfolio Companies

    • Hedge Funds

    • Family Offices & Asset Managers

    • Asset Allocators and Owners

    News & Views

    • Alerts

    • Awards

    • Media

    • Press Releases

    • Thought Leadership

    About

    • Company Overview

    • Leadership

    • Partners

    • Awards

    • Careers and Culture

    • Contact

    © 2023 Drawbridge. All Rights Reserved.

    Privacy Policy   |   Diversity Statement   |   Platform Login

    Cleantalk Pixel
    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT
    Scroll To Top