Produce (if you don't already have one) a list of security measures companies that interact with your data must have in place. Send it to them, giving them a reasonable amount of time to implement the security (say, 2 weeks?)
If they fail to meet the security measures, block they're IP.
If your data is that sensitive and you don't want it to get into other companies hands, it's a reasonable request.
Just because they're a "big" company, doesn't mean IT is properly staffed. They may have 1 poor guy managing everything and it might have been a (albeit big) oversight.
Comments
Produce (if you don't already have one) a list of security measures companies that interact with your data must have in place. Send it to them, giving them a reasonable amount of time to implement the security (say, 2 weeks?)
If they fail to meet the security measures, block they're IP.
If your data is that sensitive and you don't want it to get into other companies hands, it's a reasonable request.
Just because they're a "big" company, doesn't mean IT is properly staffed. They may have 1 poor guy managing everything and it might have been a (albeit big) oversight.