I Need IT Support Now
Digital cityscape with glowing padlock symbols representing cybersecurity and data protection network
Shane

Recent Report Reveals Software & IT Vendors Are Top Security Risk for Houston Energy Sector Businesses

A new SecurityScorecard and KPMG report reveals software and IT vendors account for 67% of third-party breaches in the US energy sector, highlighting urgent cybersecurity risks

Security Alert
The Biggest Cyber Threat to Houston Energy Is Not a Lone Hacker. It Is the Software Vendors the Sector Trusts.

A SecurityScorecard and KPMG report finds software and IT vendors drive most third-party breaches in energy. Here is what it means, and how to cut the risk.

TL;DR
A SecurityScorecard and KPMG report names software and IT vendors as the top cybersecurity risk to the US energy sector - responsible for 67% of all third-party breaches. Third-party risk drives 45% of energy breaches (vs 29% globally), and 90% of companies breached more than once were compromised through a vendor. The MOVEit flaw alone caused 39% of third-party breaches. The fix is disciplined vendor risk management, segmentation, and continuous monitoring.

Software and IT vendors are the top cybersecurity risk to the energy sector because energy companies now run on third-party software, and a single vendor breach can spread across every customer that uses the same tool - as a SecurityScorecard and KPMG report makes clear.

A report from SecurityScorecard and KPMG has found that software and IT vendors pose the greatest cybersecurity threat to the US energy sector, responsible for 67% of all third-party breaches. It lands at a critical moment: the energy sector is more digitized and more software-dependent than ever, and Houston sits at the center of that industry. This is what the report found, why vendors are the weak point, and how energy firms can respond.

The short version: You can run a tight security program and still get breached through a vendor you trusted. In energy, that is now the most likely way in - which makes third-party risk management a core control, not a checkbox.

What the Report Found

The numbers point in one direction: the supply chain is the soft underbelly of energy security.

Third-party risk drives nearly half of energy sector breaches, software and IT vendors cause the bulk of them, and repeat victims are almost always compromised through a vendor.

ENERGY SECTOR: THIRD-PARTY RISK 67% of third-party breaches trace to software / IT vendors 45% of energy breaches are third-party (vs 29% global) 90% of repeat-breach firms were hit through a vendor 39% from the MOVEit flaw alone 19% of energy firms carry weak security Source: SecurityScorecard & KPMG · CinchOps · cinchops.com
Key findings from the SecurityScorecard and KPMG report on energy sector cybersecurity.
  • Vendors cause most of it. Software and IT vendors are behind 67% of all third-party breaches in the sector.
  • Energy runs hotter than average. Third-party risk drives 45% of energy breaches, well above the 29% global average.
  • Repeat victims share a pattern. 90% of companies breached more than once were compromised through a third-party vendor.
  • Most are strong, a minority are not. 81% of energy companies hold strong A or B security ratings, but the remaining 19% with weak postures put the whole supply chain at risk.

Why Vendors Are the Weak Link

One shared tool, one shared flaw, and the blast radius covers the whole industry.

The energy sector depends on a common set of software tools, so a single vulnerability - like MOVEit - cascades across many companies at once, and attackers use a breached vendor to move laterally into everyone connected to it.

The MOVEit file-transfer vulnerability (CVE-2023-34362) alone accounted for 39% of all third-party breaches in the study - one flaw in one widely used tool. As Scott Johnson, VP of Product Management at Black Duck, put it in Energy Digital, "most energy companies are now software companies that deliver energy to their customers via their software and technology." That digital shift is necessary, but it creates new attack vectors.

Deryck Mitchelson, Global CISO at Check Point Software, framed the stakes: "Supply chain attacks pose a significant threat to the energy sector, where critical infrastructure relies on a complex web of suppliers, vendors and partners to maintain operations." Once attackers breach one vendor, they can move laterally across networks and reach multiple energy companies from a single foothold.

MeasureGlobal AverageEnergy Sector
Breaches that are third-party29%45%
Third-party breaches from software/IT vendors67%
Repeat-breach firms hit via a vendor90%
Single largest cause (MOVEit, CVE-2023-34362)39% of third-party breaches

How to Reduce Third-Party Risk

The report's recommendations map to four practical controls any energy firm can put in place.

Cutting third-party risk comes down to vetting and monitoring vendors, demanding secure-by-design software, segmenting networks, and running proactive security monitoring.

  • Enhanced third-party risk management. Prioritize software and IT vendor assessments, monitor vendor security postures continuously, and set strict security requirements for every new vendor relationship.
  • Secure-by-design procurement. Demand built-in security from technology vendors, verify their compliance with best practices, and require security in base products rather than as paid add-ons.
  • Network segmentation. Enforce strong access controls, limit vendor access to critical systems, and keep clear boundaries between operational technology and IT networks.
  • Proactive security monitoring. Stand up Security Operations Center capabilities, enable thorough logging across every environment, and maintain visibility into both on-premises and cloud systems.
Energy companies keep hardening their own front door while leaving the vendor side gate wide open. When 90% of repeat breaches come through a third party, watching your vendors is not extra credit - it is the assignment.
Shane Stevens, CEO, CinchOps - LinkedIn

Close the Vendor Side Gate

CinchOps helps Houston energy firms manage third-party risk with cybersecurity and managed IT - vendor assessments, zero-trust access, segmentation, and 24/7 monitoring aligned to Secure-by-Design principles.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure the Energy Sector

CinchOps is a Katy, Texas managed IT services provider serving small and mid-sized businesses across the Houston metro, with a multi-layered approach aligned to Secure-by-Design and DOE supply-chain principles for energy operations.

  • Security-first IT management. Proactive monitoring and patching of all systems, regular vulnerability assessments, and 24/7 threat monitoring and response.
  • Vendor security management. Assessment and ongoing monitoring of third-party security postures, tracked vendor access levels, and zero-trust principles for vendor access.
  • Secure infrastructure design. Network segmentation to limit breach impact, least-privilege access controls, and advanced endpoint protection across systems.
  • Compliance and documentation. Alignment with CISA Secure-by-Design principles, regular compliance audits, and detailed records of security controls.

The energy sector faces rising scrutiny and evolving threats. If your firm depends on a web of software vendors - and it does - that risk is manageable with the right partner. Talk to CinchOps about strengthening your supply-chain security posture.

100% Free

Free Security Assessment

See where your vendors expose you. Get a FREE security assessment that maps your third-party risk and shows exactly what to tighten first.

Get Your Free Assessment

Frequently Asked Questions

What is the biggest cybersecurity risk to the energy sector?

According to a SecurityScorecard and KPMG report, software and IT vendors are the biggest risk - they account for 67% of all third-party breaches in the sector. Because energy companies increasingly run on shared software, a single vendor vulnerability can cascade across many organizations at once.

What is third-party or supply-chain cyber risk?

It is the risk that a breach reaches you through an outside vendor, supplier, or partner rather than a direct attack on your own systems. In energy, third-party risk drives 45% of breaches - well above the 29% global average - and 90% of companies breached more than once were compromised through a vendor.

What was the MOVEit breach?

MOVEit is a widely used file-transfer tool with a vulnerability (CVE-2023-34362) that attackers exploited across many organizations. In this study it accounted for 39% of all third-party breaches in the energy sector - a clear example of how one flaw in one common tool can hit the whole industry.

How can an energy company reduce third-party risk?

Prioritize software and IT vendor assessments, monitor vendor security postures continuously, demand secure-by-design products, segment networks to limit vendor access, and run proactive security monitoring with strong logging across on-premises and cloud systems. Managing vendor risk is now a core control, not an afterthought.

Does this apply to small and mid-sized energy firms in Houston?

Yes. Smaller firms use the same common software tools as large ones and are part of the same supply chain, so they inherit the same third-party exposure - often with fewer defenses. A managed IT and cybersecurity partner can put vendor risk management, segmentation, and monitoring in place without a large in-house team.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506