Site navigation

JPMorgan CISO Calls for ‘Urgent’ Overhaul of Third-party Vendor Security

Elizabeth Greenberg

,

third-party security
Following several high-profile incidents, a cyber leader calls for greater care and responsibility from third-party vendors when it comes to security.

The chief information and security officer (CISO) of JPMorgan Chase, Patrick Opet is calling out third-party vendors to boost their security practices following major service disruptions across financial services.

JPMorgan Chase understands the importance of third-party security first-hand: in 2024, the company dealt with a third-party software issued which affected more than 450,000 people. In the same year, the CrowdStrike software incident also impacted the bank’s trade, as it caused 8.5 million windows devices to malfunction.

Despite these high-profile cases, third-party risk is not on everyone’s radar: a BlueVoyant survey from this year found that nearly two-third of UK businesses don’t qualify third-party risk as a priority, or only as somewhat of a priority.

Still, third-party risks were found to have driven cyber insurance claims, according to research from Resilience, and have been seen to plague insurance companies themselves.

Opet posited in an open letter that the growing reliance on software-as-a-service is “quietly enabling cyber-attacks” and “is creating a substantial vulnerability that is weakening the global economic system.”

His letter called for insurances that third-party vendors will prioritise security over speed to market, recognising the fierce competition driving this rush to delivery as the SaaS sector continues to expand.

Specifically, Opet explains how reliance on third-parties has fundamentally reshaped how companies are integrating services, leaving them overall more vulnerable to incidents and attacks.

The boundaries and segmentations – such as the ones between APIS and backend core systems – which Opet calls “essential” have been largely eroded, with companies opting for open authentication (OAuth) allowing open, often unchecked access between third-parties and sensitive internal systems.

When functioning correctly, these systems can boost productivity, Opet cedes, but if compromised, these methods can give attackers “unprecedented access to confidential data and critical internal communications.”

According to Opet, this problem is only getting worse as third-parties often rely on fourth-parties, expanding these risks. This exponentially increases the risk inherent to vulnerable systems as if grants attackers new avenues of attack.


Recommended reading


“Critically, the explosive growth of new value-bearing services in data management, automation, artificial intelligence, and AI agents amplifies and rapidly distributes these risks, bringing them directly to the forefront of every organization,” Opet wrote.

To mitigate these growing fears – and real threats – Opet is calling for third parties and those soliciting them to practice ‘secure and resilience by design’ – though he wants this to be more than just a slogan.

It will require continuous checks and balances, as well as an ecosystem which addresses trustworthy integration more vigorously.

“We must establish new security principles and implement robust controls that enable the swift adoption of cloud services while protecting customers from their providers’ vulnerabilities,” Opet said, saying that traditional segmentation and tiering may not be sufficient in the modern landscape.

Better systems can look like more “sophisticated authorisation methods, advanced detection capabilities, and proactive measures to prevent the abuse of interconnected systems.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data