CyberGRX/Ponemon Report

When I read through the CyberGRX/Ponemon Report, it was surprising to me how 60% of the respondents to the survey felt ‘like their current process was only somewhat or not effective in vetting third parties’.  How accurate do you think that 60% figure is?  Do you have thoughts on where the deficiencies are or what could be improved?
