• bitcoinBitcoin(BTC)$78,948.000.31%
  • ethereumEthereum(ETH)$2,490.950.04%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$750.94-0.36%
  • rippleXRP(XRP)$1.421.60%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$103.50-0.09%
  • tronTRON(TRX)$0.3389640.08%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.00%
  • zcashZcash(ZEC)$1,236.187.62%
  • HyperliquidHyperliquid(HYPE)$85.711.59%
  • dogecoinDogecoin(DOGE)$0.090094-0.28%
  • RainRain(RAIN)$0.016006-5.86%
  • USDSUSDS(USDS)$1.000.02%
  • whitebitWhiteBIT Coin(WBT)$81.623.59%
  • moneroMonero(XMR)$497.98-4.29%
  • chainlinkChainlink(LINK)$12.25-3.76%
  • leo-tokenLEO Token(LEO)$9.18-0.10%
  • cardanoCardano(ADA)$0.217850-1.05%
  • stellarStellar(XLM)$0.187370-1.96%
  • bitcoin-cashBitcoin Cash(BCH)$256.90-0.60%
  • daiDai(DAI)$1.00-0.01%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • USD1USD1(USD1)$1.00-0.01%
  • CantonCanton(CC)$0.1065041.15%
  • litecoinLitecoin(LTC)$54.12-2.75%
  • uniswapUniswap(UNI)$6.66-6.50%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.40-0.03%
  • hedera-hashgraphHedera(HBAR)$0.078885-2.10%
  • avalanche-2Avalanche(AVAX)$7.90-2.58%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • suiSui(SUI)$0.81-2.48%
  • nearNEAR Protocol(NEAR)$2.444.50%
  • shiba-inuShiba Inu(SHIB)$0.000005-1.57%
  • crypto-com-chainCronos(CRO)$0.0599821.09%
  • paypal-usdPayPal USD(PYUSD)$1.000.01%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • MemeCoreMemeCore(M)$1.192.35%
  • tether-goldTether Gold(XAUT)$4,386.41-0.24%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • BittensorBittensor(TAO)$256.980.44%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • okbOKB(OKB)$114.05-2.07%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.150.31%
  • mantleMantle(MNT)$0.642.33%
  • AsterAster(ASTER)$0.75-2.26%
  • polkadotPolkadot(DOT)$1.188.07%
  • aaveAave(AAVE)$128.52-2.34%
  • pax-goldPAX Gold(PAXG)$4,391.68-0.25%
  • Pump.funPump.fun(PUMP)$0.0044412.22%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Breaches happen: It’s time to stop playing the blame game and start learning together

December 3, 2023
in AI & Technology
Reading Time: 5 mins read
A A
Breaches happen: It’s time to stop playing the blame game and start learning together
ShareShareShareShareShare

Are you ready to bring more awareness to your brand? Consider becoming a sponsor for The AI Impact Tour. Learn more about the opportunities here.


What do you do after a vendor or partner suffers a breach? After your heart skips a beat (or two), this is a common question you might ask.  

YOU MAY ALSO LIKE

Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer

OpenAI Says Internal AI System Resolved the Navier–Stokes Problem – Unite.AI

As a recent study indicates, more than half of all organizations have been the victim of a third-party breach over the past two years. Unfortunately, the overwhelming reaction to such an incident is to ostracize the victim. In fact, up to 83% of consumers admit that they pause or end their spending with an organization after an incident. While understandable, that reaction misses the opportunity the industry has to learn and grow together after details of an incident become available. 

Breaches continue to happen — even after organizations have a commercially reasonable security program in place. No one is impenetrable. One key aspect to consider when evaluating potential partners and vendors is understanding their capability of responding effectively to and willingness to be transparent when a security incident occurs.

Punishing a partner or vendor for suffering a breach only continues to incentivize organizations to cover up their security incidents. Instead, today’s businesses need to foster an environment of understanding, transparency and information sharing. Embracing these values will help bolster security practices across the economic landscape. 

VB Event

The AI Impact Tour

Connect with the enterprise AI community at VentureBeat’s AI Impact Tour coming to a city near you!

 

Learn More

The shift away from blame

The shift toward understanding is already happening on an employee level. Increasingly, employees are no longer automatically vilified for accidentally clicking on a phishing link or responding to a spoofed email. Security professionals understand that attack tactics like phishing are a numbers game: If attackers target enough people, the odds are good that someone will eventually take the bait. Phishing attacks are only getting craftier and more believable. It’s only natural to acknowledge the reality human trust — and human error — play in our risk landscape. 

If an employee living in fear of punishment or reprisal accidentally clicks a phishing link, that employee may decide to do everything possible to cover it up and pretend it never happened. On the other hand, a business that encourages (and even celebrates) self-reporting of those errors and greets them with understanding will find that employees are much more willing to acknowledge when they have made a mistake and learn from it.  

This doesn’t eliminate the need to train employees to recognize attacks — it acknowledges the reality that the sooner an organization knows about a potential breach, the sooner they can do something about it. In fact, IBM’s 2023 Cost of a Data Breach Report found that early detection is one of the most important factors that can limit the impact of a breach. Combined with the implementation of technology that can help stop these phishing emails from reaching employee inboxes in the first place, these efforts can make a real difference. 

Understanding at scale

While businesses have found success implementing those policies on an individual scale, they have not generally applied that same posture to partners, vendors and other third parties. A breach can happen to any organization, including those that have taken all commercially reasonable precautions — and understand whether those precautions have been taken should be a standard part of any business’s vetting process. Jettisoning a good and reliable partner because of an attack may ultimately bring on more risks, including operational challenges.  

Of course, it’s important to recognize the difference between a business that suffers a breach unexpectedly and a business that engages in an ongoing pattern of risky or negligent behavior (or seeks to actively cover up or retract details surrounding a breach). But the advent of compliance frameworks, security questionnaires and benchmarks and more well-rounded security programs has made it much easier to assess a potential partner’s breach readiness.

That said, if a breach does occur, it’s also important to know what happened and how it was dealt with. How businesses choose to communicate about cyber incidents plays a key part in assessing and maintaining trust within the relationship. 

Just as employees are now encouraged to self-report potential issues, encouraging businesses to be upfront about their challenges wouldn’t just make it easier for businesses to assess their partners’ security capabilities — it would help lessen the impact of future breaches. The more information security teams have to work with regarding attack tactics, techniques and procedures (TTPs), the better the odds they will be able to detect, recognize and remediate them when facing a similar attack themselves.

Rather than punishing vendors for being victimized by attackers, we should be encouraging them to be more open, honest, transparent and vulnerable — in the human sense. 

Envisioning a secure and transparent future

Adopting a more understanding attitude toward breaches doesn’t mean organizations should stop doing their due diligence. On the contrary, businesses should always verify the compliance status of their partners and vendors, and security questionnaires and security reports and attestations will continue to play an important role in confirming that organizations are being careful with their data.

But the truth is, even an organization that has done everything right can still suffer a breach. It’s time to stop victim blaming. It’s time to treat each other the same way we treat employees who act in good faith: With the understanding that no one is perfect and an acknowledgement that embracing honesty and transparency will benefit everyone in the long run.

Matt Hillary is CISO of Drata.

DataDecisionMakers

Welcome to the VentureBeat community!

DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

You might even consider contributing an article of your own!

Read More From DataDecisionMakers

Credit: Source link

ShareTweetSendSharePin

Related Posts

Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer
AI & Technology

Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer

September 9, 2026
OpenAI Says Internal AI System Resolved the Navier–Stokes Problem – Unite.AI
AI & Technology

OpenAI Says Internal AI System Resolved the Navier–Stokes Problem – Unite.AI

September 9, 2026
How To Watch Apple Unveil The New iPhones On September 9
AI & Technology

How To Watch Apple Unveil The New iPhones On September 9

September 9, 2026
NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models – Unite.AI
AI & Technology

NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models – Unite.AI

September 9, 2026
Next Post
Palestinian American student shot in Vermont paralyzed from the chest down

Palestinian American student shot in Vermont paralyzed from the chest down

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Huskeys Raises M Series A to Build the Security Control Layer for the AI Driven Network – Unite.AI

Huskeys Raises $27M Series A to Build the Security Control Layer for the AI Driven Network – Unite.AI

September 2, 2026
Google DeepMind Releases Gemini 3.8 Flash and Gemini 3.8 Flash Cyber: One Core Model, Two Access Envelopes

Google DeepMind Releases Gemini 3.8 Flash and Gemini 3.8 Flash Cyber: One Core Model, Two Access Envelopes

September 2, 2026
Lindsay Clancy trial latest: Judge declares a mistrial – follow live – BBC

Lindsay Clancy trial latest: Judge declares a mistrial – follow live – BBC

September 4, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!