CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Digital cityscape with glowing padlock symbols representing cybersecurity and data protection network
Shane Stevens
Shane Stevens November 11th, 2024

Recent Report Reveals Software & IT Vendors Are Top Security Risk for Houston Energy Sector Businesses

A new SecurityScorecard and KPMG report reveals software and IT vendors account for 67% of third-party breaches in the US energy sector, highlighting urgent cybersecurity risks

Security Alert
The Biggest Cyber Threat to Houston Energy Is Not a Lone Hacker. It Is the Software Vendors the Sector Trusts.

A SecurityScorecard and KPMG report finds software and IT vendors drive most third-party breaches in energy. Here is what it means, and how to cut the risk.

TL;DR
A SecurityScorecard and KPMG report names software and IT vendors as the top cybersecurity risk to the US energy sector - responsible for 67% of all third-party breaches. Third-party risk drives 45% of energy breaches (vs 29% globally), and 90% of companies breached more than once were compromised through a vendor. The MOVEit flaw alone caused 39% of third-party breaches. The fix is disciplined vendor risk management, segmentation, and continuous monitoring.
🚨 What the Report Found 🔗 Why Vendors Are the Weak Link 🛡️ How to Reduce the Risk 🚀 How CinchOps Helps

Software and IT vendors are the top cybersecurity risk to the energy sector because energy companies now run on third-party software, and a single vendor breach can spread across every customer that uses the same tool - as a SecurityScorecard and KPMG report makes clear.

A report from SecurityScorecard and KPMG has found that software and IT vendors pose the greatest cybersecurity threat to the US energy sector, responsible for 67% of all third-party breaches. It lands at a critical moment: the energy sector is more digitized and more software-dependent than ever, and Houston sits at the center of that industry. This is what the report found, why vendors are the weak point, and how energy firms can respond.

The short version: You can run a tight security program and still get breached through a vendor you trusted. In energy, that is now the most likely way in - which makes third-party risk management a core control, not a checkbox.

What the Report Found

The numbers point in one direction: the supply chain is the soft underbelly of energy security.

Third-party risk drives nearly half of energy sector breaches, software and IT vendors cause the bulk of them, and repeat victims are almost always compromised through a vendor.

ENERGY SECTOR: THIRD-PARTY RISK 67% of third-party breaches trace to software / IT vendors 45% of energy breaches are third-party (vs 29% global) 90% of repeat-breach firms were hit through a vendor 39% from the MOVEit flaw alone 19% of energy firms carry weak security Source: SecurityScorecard & KPMG · CinchOps · cinchops.com
Key findings from the SecurityScorecard and KPMG report on energy sector cybersecurity.
  • Vendors cause most of it. Software and IT vendors are behind 67% of all third-party breaches in the sector.
  • Energy runs hotter than average. Third-party risk drives 45% of energy breaches, well above the 29% global average.
  • Repeat victims share a pattern. 90% of companies breached more than once were compromised through a third-party vendor.
  • Most are strong, a minority are not. 81% of energy companies hold strong A or B security ratings, but the remaining 19% with weak postures put the whole supply chain at risk.

Why Vendors Are the Weak Link

One shared tool, one shared flaw, and the blast radius covers the whole industry.

The energy sector depends on a common set of software tools, so a single vulnerability - like MOVEit - cascades across many companies at once, and attackers use a breached vendor to move laterally into everyone connected to it.

The MOVEit file-transfer vulnerability (CVE-2023-34362) alone accounted for 39% of all third-party breaches in the study - one flaw in one widely used tool. As Scott Johnson, VP of Product Management at Black Duck, put it in Energy Digital, "most energy companies are now software companies that deliver energy to their customers via their software and technology." That digital shift is necessary, but it creates new attack vectors.

Deryck Mitchelson, Global CISO at Check Point Software, framed the stakes: "Supply chain attacks pose a significant threat to the energy sector, where critical infrastructure relies on a complex web of suppliers, vendors and partners to maintain operations." Once attackers breach one vendor, they can move laterally across networks and reach multiple energy companies from a single foothold.

MeasureGlobal AverageEnergy Sector
Breaches that are third-party29%45%
Third-party breaches from software/IT vendors—67%
Repeat-breach firms hit via a vendor—90%
Single largest cause (MOVEit, CVE-2023-34362)—39% of third-party breaches

How to Reduce Third-Party Risk

The report's recommendations map to four practical controls any energy firm can put in place.

Cutting third-party risk comes down to vetting and monitoring vendors, demanding secure-by-design software, segmenting networks, and running proactive security monitoring.

  • Enhanced third-party risk management. Prioritize software and IT vendor assessments, monitor vendor security postures continuously, and set strict security requirements for every new vendor relationship.
  • Secure-by-design procurement. Demand built-in security from technology vendors, verify their compliance with best practices, and require security in base products rather than as paid add-ons.
  • Network segmentation. Enforce strong access controls, limit vendor access to critical systems, and keep clear boundaries between operational technology and IT networks.
  • Proactive security monitoring. Stand up Security Operations Center capabilities, enable thorough logging across every environment, and maintain visibility into both on-premises and cloud systems.
Energy companies keep hardening their own front door while leaving the vendor side gate wide open. When 90% of repeat breaches come through a third party, watching your vendors is not extra credit - it is the assignment.
Shane Stevens, CEO, CinchOps - LinkedIn

Close the Vendor Side Gate

CinchOps helps Houston energy firms manage third-party risk with cybersecurity and managed IT - vendor assessments, zero-trust access, segmentation, and 24/7 monitoring aligned to Secure-by-Design principles.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure the Energy Sector

CinchOps is a Katy, Texas managed IT services provider serving small and mid-sized businesses across the Houston metro, with a multi-layered approach aligned to Secure-by-Design and DOE supply-chain principles for energy operations.

  • Security-first IT management. Proactive monitoring and patching of all systems, regular vulnerability assessments, and 24/7 threat monitoring and response.
  • Vendor security management. Assessment and ongoing monitoring of third-party security postures, tracked vendor access levels, and zero-trust principles for vendor access.
  • Secure infrastructure design. Network segmentation to limit breach impact, least-privilege access controls, and advanced endpoint protection across systems.
  • Compliance and documentation. Alignment with CISA Secure-by-Design principles, regular compliance audits, and detailed records of security controls.

The energy sector faces rising scrutiny and evolving threats. If your firm depends on a web of software vendors - and it does - that risk is manageable with the right partner. Talk to CinchOps about strengthening your supply-chain security posture.

100% Free

Free Security Assessment

See where your vendors expose you. Get a FREE security assessment that maps your third-party risk and shows exactly what to tighten first.

Get Your Free Assessment

Frequently Asked Questions

What is the biggest cybersecurity risk to the energy sector?

According to a SecurityScorecard and KPMG report, software and IT vendors are the biggest risk - they account for 67% of all third-party breaches in the sector. Because energy companies increasingly run on shared software, a single vendor vulnerability can cascade across many organizations at once.

What is third-party or supply-chain cyber risk?

It is the risk that a breach reaches you through an outside vendor, supplier, or partner rather than a direct attack on your own systems. In energy, third-party risk drives 45% of breaches - well above the 29% global average - and 90% of companies breached more than once were compromised through a vendor.

What was the MOVEit breach?

MOVEit is a widely used file-transfer tool with a vulnerability (CVE-2023-34362) that attackers exploited across many organizations. In this study it accounted for 39% of all third-party breaches in the energy sector - a clear example of how one flaw in one common tool can hit the whole industry.

How can an energy company reduce third-party risk?

Prioritize software and IT vendor assessments, monitor vendor security postures continuously, demand secure-by-design products, segment networks to limit vendor access, and run proactive security monitoring with strong logging across on-premises and cloud systems. Managing vendor risk is now a core control, not an afterthought.

Does this apply to small and mid-sized energy firms in Houston?

Yes. Smaller firms use the same common software tools as large ones and are part of the same supply chain, so they inherit the same third-party exposure - often with fewer defenses. A managed IT and cybersecurity partner can put vendor risk management, segmentation, and monitoring in place without a large in-house team.

Discover More

CinchOps Cybersecurity Services
Critical Cybersecurity Gaps in the US Energy Sector
Digital Transformation in Oil and Gas
The Network Security Audit Process in 5 Steps
Security Compliance: What Regulations Mean for Your IT
Construction Industry Cybersecurity Risks

Sources

  • SecurityScorecard & KPMG, Energy Sector Third-Party Breach Research
  • CISA, Secure by Design
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

July 17th, 2025
Managed Service Provider Houston Cyberscurity
United Natural Foods Cyberattack: $400 Million Supply Chain Disruption

United Natural Foods Reports Cyberattack Impact on Operations and Financial Results – Supply Chain Resilience: Learning from United Natural Foods’ Cyber Incident

March 19th, 2026
Law Firm IT
How a Law Firm IT Partner Helps Houston Firms Meet Texas Bar Cybersecurity Standards

Managed IT Support Designed for Houston Law Firms – Law Firm IT Governance: Policies, Controls, and Documentation

July 29th, 2025
Managed Service Provider Houston Cybersecurity
Texas Digestive Specialists Hit by Major InterLock Ransomware Attack

Texas Gastroenterology Practice Suffers Major InterLock Ransomware Attack – Patient Information Potentially Compromised

August 5th, 2025
Managed Service Provider Houston Cybersecurity
CinchOps Houston Business Cyber Update: Key Insights from the CrowdStrike 2025 Global Threat Report

Professional Threat Analysis: What Business Leaders Need to Know About Current Cyber Risks – What CrowdStrike’s 2025 Report Means for Your Business

April 2nd, 2026
Identity Management
PwC Annual Threat Dynamics 2026: Identity, AI, and Ransomware Reshape the Threat Picture for Houston Businesses

Annual Threat Intelligence Report Outlines Practical Cybersecurity Priorities – Manufacturing, Construction, And Legal Sectors See Largest Ransomware Increases

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy