• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » One Third of Retail Breaches Begin With Third-Party Vulnerabilities, Study Finds

One Third of Retail Breaches Begin With Third-Party Vulnerabilities, Study Finds

November 20, 2014
BitSight Technologies

That's the finding of research released by BitSight Technologies, which
measured the security performance of 300 major U.S. retailers from Nov. 1, 2013 to Nov. 1, 2014.

"While it's encouraging that a majority of the breached retailers have improved their security effectiveness, there is more work to be done, especially in the area of vendor risk management," said Stephen Boyer, co-founder and CTO of BitSight. "This trend in retail highlights the importance of proactive measures such as industry and peer benchmarking, as well as continuous monitoring of one's supply
chain. We are seeing retail take steps in the right direction, with the formation of the Retail Information Sharing and Analysis Center to increase intelligence sharing among retailers in the U.S., but more improvements are needed."

The BitSight platform uses publicly available data to rate the security performance of an organization on a daily basis. Observed security events and configurations, such as communication with a botnet, malware distribution, and email server configuration, are assessed for severity, frequency and duration and used to generate objective security ratings. BitSight security ratings range from 250 to 900, with higher ratings equating to higher security performance.

BitSight uses a wide breadth of high-quality publicly available security data to calculate security ratings data on specific companies and industries.

Other key findings include:

--  Retail still under wide scale attack - Of the 300 major U.S. retailers     analyzed by BitSight from Nov. 2013 to Nov. 2014, 58 percent experienced a decline in overall security performance with an average 90-point decrease. The 34 percent of retailers that improved saw an average 70-point increase, while eight percent of retailers saw no net change in their Security Ratings over the past year.

--  Retailers breached in the last year see improvement - BitSight analyzed the security performance of 20 large retailers that had a high-profile breach within the last year. Of these retailers, nearly 75 percent saw an average increase of 50 points to their security rating score, since the point of their breach.

--  Securing the supply chain remains a big challenge - BitSight observed     that nearly a third of all breaches in the retail sector began with a compromise at a third-party vendor. Retailers share sensitive data with hundreds to thousands of business partners globally; organizations can take steps in securing their own networks, but ignoring risks posed by third-party partners can leave them exposed   and vulnerable to breaches.

--  Infection increases in almost all threat vectors - In the span of a year, the retail industry on average suffered from an increase in infections in every individual threat indicator monitored by BitSight, with the exception of spam propagation. Malware distribution accounted for the largest increase, followed by botnet infections.

Source: BitSight Technologies

    RELATED CONTENT

    RELATED VIDEOS

    Global Supply Chain Management Supply Chain Security & Risk Mgmt Food & Beverage Retail
    KEYWORDS BitSight Technologies Data Breach Food and Beverage Global Supply Chain Management Retail Retail Information Sharing and Analysis Center retail supply chain SC Security & Risk Mgmt Supply Chain Analysis & Consulting Supply Chain Management: Retail Supply Chain Risk Management
    • Related Articles

      One Third of Manufacturing CFOs See Recession Continuing Until Second Half of 2010

      Third of Online Retail Sales Take Place on Mobile Devices, Study Says

      Successful Companies Partner with Third-Party to Enhance Visibility and Control, Research Firm Says

    • Related Directories

      Tecsys, Inc.

    BitSight Technologies

    More from this author

    Subscribe to our Daily Newsletter!

    Timely, incisive articles delivered directly to your inbox.

    Featured Product

    Popular Stories

    • A TRUCK WITH ITS CONTAINER DOOR OPEN SITS UNDER A SIGN THAT READS INTERNATIONAL BORDER COMMERCIAL TRUCKS

      Importers Into Mexico Can No Longer Delay Complying With New Customs Declaration Law

      Data Management (Big Data/IoT/Blockchain)
    • 018_how_3pls_can_get_started_with_ai_v1-(540p).png

      Watch: How 3PLs Can Get Started With Automation

      Logistics Outsourcing
    • An employee in a warm suit crouches down to get boxes of food ready for shipping at a warehouse

      Packaging Optimization Is Boosting Cold Chain Growth

      Air Cargo
    • A FIGURE IN CAMOUFLAGE LOOKS THROUGH A SCOPING DEVICE AT A SHIP IN THE DISTANCE, BELCHING SMOKE

      Strait of Hormuz Ship Transits Are Rising Thanks to U.S. Help

      Global Gateways
    • Heat Haze Distorts Video of Semi-Trucks Driving Down an Interstate Surrounded by Mountains on a Sunny Day

      The Biggest Challenges Facing Logistics Operators This Summer

      Logistics

    Digital Edition

    2026 esg cover main scb q2 2026 cover

    SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

    VIEW THE LATEST ISSUE

    Case Studies

    • Recycled Tagging Fasteners: Small Changes Make a Big Impact

    • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

      Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

    • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

      Moving Robots Site-to-Site

    • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

    • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

    Visit Our Sponsors

    4flow Arkieva Blue Yonder
    Carton Cloud CoEnterprise Dassault
    Duravant E2Open General Logistics Systems
    Hy-Tek iGPS Korber
    Lyngsoe Procurability Quinyx
    SAP Sikick Systech
    S&P Global Mobility TADA TransImpact
    US Bank Werner Enterprises WSI
    • More From SCB
      • Featured Content
      • Video Library
      • Think Tank Blog
      • SupplyChainBrain Podcast
      • Whitepapers
      • On-Demand Webinars
      • Upcoming Webinars
    • Digital Offerings
      • Digital Issue
      • Subscribe
      • Manage Email Preferences
      • Newsletters
    • Resources
      • Events Calendar
      • 2026 Event Coverage
      • SCB's Great Supply Chain Partners
      • Supplier Directory
      • Case Study Showcase
      • Supply Chain Innovation Awards
      • 100 Great Partners Form
    • SCB Corporate
      • Advertise on SCB.COM
      • About Us
      • Privacy Policy
      • Contact Us
      • Data Sharing Opt-Out

    All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

    Design, CMS, Hosting & Web Development :: ePublishing