News

Understanding Cybersecurity Risks in Federal Contracts

Understanding Cybersecurity Risks in Federal Contracts

SecurityScorecard’s Findings on Federal Contractor Breaches

Recently, SecurityScorecard revealed significant insights into the cybersecurity landscape facing the top-tier federal contractors. Their report indicates that a staggering 58% of breaches are linked to third-party attack vectors. This statistic brings to light a serious vulnerability within federal supply chains, which are crucial for national security.

The Growing Threat of Third-Party Attack Vectors

In a world where cyber threats are evolving rapidly, the impact of third-party vendors cannot be overstated. Attackers are increasingly targeting these suppliers, which often possess less robust security measures compared to their larger clients. The breach of sensitive information observed at the U.S. Treasury Department highlights just how perilous this risk can be.

The Call for Enhanced Cybersecurity

Security experts, including Ryan Sherstobitoff, Senior Vice President of Threat Research and Intelligence at SecurityScorecard, emphasize the urgent need for enhanced cybersecurity measures across the board. The vulnerability of federal contractors poses a significant challenge for government security, necessitating a collaborative approach from both public and private sectors.

Key Statistics from the SecurityScorecard Report

The report presented some alarming statistics that expose the gravity of the situation:

  • 35% of contractors have faced publicly reported breaches, with 14% having experienced multiple incidents.
  • A staggering 58% of these breaches were facilitated by third-party attack vectors, significantly higher than the global average of 29%.
  • Notably, ransomware attacks accounted for 41.25% of breaches while increasing to 46.5% in incidents involving third parties.
  • Moreover, 28% of contractors reported that they had at least one malware infection within the past year.
  • State-sponsored threats contributed to 35% of breaches, with an uptick to 39.5% in third-party-related incidents.
  • Application security emerged as the most critical vulnerability for 41% of contractors, indicating that organizations need to bolster defenses in this area significantly.

Strategic Recommendations for Defense

In light of these findings, SecurityScorecard’s STRIKE team recommends several strategies for federal contractors to enhance their cybersecurity practices:

  • Implement Comprehensive Cyber Maturity Model Certification (CMMC): The CMMC framework is vital for ensuring contractors meet high cybersecurity standards. Expanding its application could address vulnerabilities across civilian agencies.
  • Streamline Third-Party Risk Management: Optimizing TPRM practices to target potential exposure of U.S. government interests can lead to enhanced vetting processes.
  • Evaluate Fourth-Party Risk Management: Since many breaches stem from fourth-party vendors, agencies should assess contractors' TPRM efforts thoroughly.
  • Mandate Disclosure of Breach Histories: Transparency regarding past breaches could bolster vetting processes and improve overall cybersecurity.
  • Focus on Key Vulnerabilities: Contractors should prioritize addressing application security, DNS health, and patching strategies.
  • Enhance Defenses Against Diverse Threats: With ransomware posing significant risks, all contractors need to reinforce their defenses against both ransomware and state-sponsored attacks.

Methodology Behind the Study

The conclusions drawn by SecurityScorecard were based on rigorous evaluations of their ratings and publicly available breach histories among the top 100 federal contractors. The data highlights critical patterns that reveal substantial third-party cyber risks to the government.

About SecurityScorecard

Founded in 2014, SecurityScorecard has rapidly established itself as a leader in cybersecurity ratings and resilience. The company has developed patented technologies used by over 25,000 organizations worldwide for various purposes, including enterprise risk management and regulatory oversight. By fostering better cybersecurity understanding, SecurityScorecard aims to enhance the overall security landscape for businesses and government agencies alike.

Frequently Asked Questions

What percentage of breaches involve third-party attack vectors?

The report indicates that 58% of breaches impacting federal contractors involve third-party attack vectors.

What are the main vulnerabilities identified in federal contractors?

Application security was identified as the most significant vulnerability, accounting for 41% of contractor issues.

How can federal contractors improve their cybersecurity practices?

By implementing measures such as the CMMC framework and enhancing third-party risk management protocols.

What role do state-sponsored groups play in cybersecurity breaches?

State-sponsored groups accounted for 35% of attributable breaches overall, increasing risk in third-party incidents to 39.5%.

Why is better transparency in breach histories important?

Improved transparency is key to enhancing security vetting processes and ensuring better compliance with cybersecurity standards.

About The Author

About Investors Hangout

Investors Hangout is a leading online stock forum for financial discussion and learning, offering a wide range of free tools and resources. It draws in traders of all levels, who exchange market knowledge, investigate trading tactics, and keep an eye on industry developments in real time. Featuring financial articles, stock message boards, quotes, charts, company profiles, and live news updates. Through cooperative learning and a wealth of informational resources, it helps users from novices creating their first portfolios to experts honing their techniques. Join Investors Hangout today: https://investorshangout.com/

The content of this article is based on factual, publicly available information and does not represent legal, financial, or investment advice. Investors Hangout does not offer financial advice, and the author is not a licensed financial advisor. Consult a qualified advisor before making any financial or investment decisions based on this article. This article should not be considered advice to purchase, sell, or hold any securities or other investments. If any of the material provided here is inaccurate, please contact us for corrections.

Top 10 Most Recent News Articles

USPS Rolls Out Christmas Cookie Stamps Nationwide

Updated Category News Views 5

USPS Delivers Nostalgia with Cookie-Themed Stamps Let's talk stamps, folks. The U.S. Postal Service has rolled out its newest Christmas Cookies Forever stamps, bringing a dash of sugary nostalgia to mailboxes nationwide. The release was celebrated at the Smithsonian National Postal Museum, spotlighting a tradition as sweet as the sugar cookies themselves. These aren't...

Continue Reading
Papa John's Faces Class Action Over Misleading Info

Updated Category News Views 5

Trouble Brewing for Papa John's Investors Rolling the dice in the stock market sometimes feels like playing the lottery, doesn't it? This time around, it's Papa John's (NASDAQ: PZZA) serving up a slice of turmoil for its investors. The pizza chain's got itself tangled in a class-action lawsuit, and it's the shareholders who're left with a bitter taste. Investors Cry Foul...

Continue Reading
Insta360 Expands with Times Square Flagship Store

Updated Category News Views 5

Insta360 Times Square Opening Marks Bold Expansion I dropped by Times Square today, and what do I see? Insta360 planting its flag right in the heart of New York City. Now, this isn't your run-of-the-mill grand opening—it’s the first flagship store outside of Asia, and it screams of big ambitions. Nestled at 1515 Broadway, the store is smack in the middle of one of the...

Continue Reading
Chery Auto's Bold Green Tech Showcase at 2026 Summit

Updated Category News Views 3

Chery Auto Puts Eco Tech at Front and Center You know, Chery Auto isn't just manufacturing cars anymore—it's shaping an entire lifestyle. For the uninitiated, they’re calling in everyone worth knowing to their headquarters in Wuhu, China, come October 18 through 24. The 2026 Chery International User Summit is kind of a big deal this year with nearly 20 new green...

Continue Reading
Flying Car Regulatory Sandbox Begins in UAE

Updated Category News Views 7

Pioneering Flying Cars in the Desert In a move that seems right out of a science fiction screenplay, ARIDGE—the bigwig of flying cars from Asia—has taken a giant leap. They’ve cozied up with the UAE, locking arms to cook up the world's first regulatory sandbox for personal flying cars. Now, don’t laugh—sandbox isn't just for toddlers. It’s the playground where...

Continue Reading
China's Tech Success Echoes in Global Living Rooms

Updated Category News Views 4

A New Player in Global Tech If you've been sleeping on China's tech scene, it's time to wake up. Moonshot AI just launched Kimi K3, the largest open-source model by parameters we've seen, a significant leap in artificial intelligence that's catching even the eyes of folks who hardly touch technology—like retirees in Italy. Rapid AI Advancements China's story isn't about...

Continue Reading
Tragedy Highlights Need for E-bike Safety Overhaul

Updated Category News Views 5

A Dire Wake-Up Call in the East Village We're staring hard at a heartbreaking mess in the East Village. A 15-year-old girl lost her life while riding an electric Citi Bike, hit by an industrial truck. Let's not dance around it—this is a gut punch, the kind you never want to ever hear about, and one that comes with a bitter flavor of 'what if?' Age Verification: A...

Continue Reading
Quay Dominates 2026 Sunglasses Review for Variety

Updated Category News Views 4

Sunglasses Designed for Every Face Type When it comes to picking the right pair of shades, face shape is only part of the equation. Expert Consumers just dropped their 2026 verdict, spotlighting Quay as the go-to brand for those wider faces, tricky nose bridges, and the noggins that run a tad larger than average. Forget what you heard about one-size-fits-all. This...

Continue Reading
BarrelPick.com Launches for Bourbon Aficionados

Updated Category News Views 4

Just when you think you've seen all the ways to enjoy bourbon, along comes BarrelPick.com with a tantalizing new proposition. They're throwing down the gauntlet for bourbon lovers everywhere by letting you buy an entire barrel, let it sit around for a bit, watch it mature, and then call the shots on when it finally sees the light of day in a bottle. Talk about skipping...

Continue Reading
GAC's Cambodia Plant: A Strategic Manufacturing Shift

Updated Category News Views 3

Setting the Stage for New Industrial Growth On September 17, a milestone was etched in the sands of Cambodia when the GAC Cambodia KD Plant officially flipped the switch. This ain't just another factory throwing doors open; it's a fresh chapter in regional manufacturing power plays. We had some big hitters in attendance, like Cambodian Prime Minister Hun Manet, showing...

Continue Reading

Top 5 Most Recently Viewed Articles

Dallas Cowboys Join Forces with AHA to Promote CPR Training

Updated Category News Views 144

Dallas Cowboys Players Advocate for Lifesaving CPR Education The collaboration between the American Heart Association and the National Football League (NFL) aims to enhance awareness about CPR (Cardiopulmonary Resuscitation) during the annual observance of World Restart a Heart Day. This important initiative is spearheaded by the announcement of the 2025 Nation of...

Continue Reading
Similarweb Ltd. Unveils Major Secondary Offering of Shares

Updated Category News Views 57

Similarweb Ltd. Launches Notable Secondary Offering Similarweb Ltd. (“Similarweb”) (NYSE: SMWB), a leading name in digital market intelligence, has kicked off an important underwritten public offering. This offering includes 3,500,000 ordinary shares, made available by a selling shareholder. The goal is to strengthen the market while offering investors a chance to...

Continue Reading
Mullen Group Ltd. Declares Consistent Monthly Dividend Payment

Updated Category News Views 152

Mullen Group Ltd. Declares a Monthly Dividend Mullen Group Ltd. has made an exciting announcement regarding its commitment to rewarding shareholders. The board of directors has declared a monthly dividend of $0.07 per Common Share. This dividend is a testament to the company's ongoing success and dedication to maintaining shareholder value. Details of the Dividend Payment...

Continue Reading
Socotra Sets New Standards in Insurance Technology Reliability

Updated Category News Views 400

Socotra Achieves Remarkable Reliability Metrics for 2024 Socotra, a leader in cloud-native insurance core technology, announced impressive reliability metrics for the upcoming year. Customers utilizing Socotra's platform have experienced an average of less than 32 minutes of downtime for both planned and unplanned events. This performance is a testament to the innovative...

Continue Reading
MEXC Launches AO with Major Prize Pool for Innovation

Updated Category News Views 166

MEXC Welcomes AO: A New Era in Decentralized Computing MEXC, a leading global cryptocurrency trading platform, is excited to announce the listing of AO (AO) on both spot and futures markets. This strategic listing marks a significant milestone in the evolution of decentralized computing and AI technology. To celebrate this occasion, MEXC is offering a remarkable rewards...

Continue Reading