Your third-party code providers don’t have enterprise-grade security. A web supply chain attack can breach your institution without ever touching your servers and result in fines that top $230M.
This is a must-read if your institution has web or mobile applications and uses third-party code or services.