Graham Croock | Director | CyriskCo Advisory | mail me |
Many organisations in today’s digital landscape rely heavily on third-party vendors who help carry out delegated operations. A third-party vendor could be a company or entity that provides certain services to your business.
Monitoring your own business’s internal cybersecurity posture is often mandatory. Still, companies often overlook their vendors’ cybersecurity posture, resulting in hackers breaching security and compromising systems and data.
Often, by default, they need to have access to sensitive data such as company, customer, and employee information. Third-party vendors typically operate according to a service level agreement, enabling them to provide products or services to your business or your customers on your organisation’s behalf.
In today’s digital world, connected systems are the norm and digital assets in the form of databases, intellectual property and hardware are accessed by vendors and service providers using Application Programmable Interface’s (API) and connected networks as well as hardware such as removable hard drives and laptops, and so on. This creates a significant problem in that this data is now exposed to a broader attack surface, which requires additional and enhanced control.
It is important to note that when we do business with a vendor or service provider, it is not safe to assume we are doing business just with the party under contract. Vendors rely on other parties, and this further widens the attack surface. If we rely on a chain, all the links must be tested, not just the primary or initial link of the ‘supply chain’.
As much as these vendors and service providers become an essential part of any organisation’s business operations, they can often contribute to additional significant cyber risk. As previously stated, vendors and service providers are often provided with access to vitally sensitive company data and critical systems that can expose your organisation to serious cyber threats if mismanaged. Therefore, regular cyber risk assessments must be conducted on these vendor’s systems to ensure adequate resilience to protect your business data.
Vendor cybersecurity assessments help to improve operational efficiencies and cyber resilience in a cost-effective manner. An independent and objective third-party cyber risk assessment, as a key component of the vendor management process, will contribute significantly to the enhanced security of your company’s systems, data, and information.
What is vendor cybersecurity assessment?
A third-party cyber risk assessment is essentially a formal risk assessment designed to provide an in-depth review of your vendors’ resilience posture in the context of cyber and information security.
The assessment is an evaluation coupled with an approval process that organisations use to determine if prospective vendors and suppliers can continuously comply with pre-defined standards and procedures required to maintain appropriate levels of cyber resilience. In addition, the assessment helps your business understand the level of risk associated with using a particular third or fourth-party vendor’s product or service.
A vendor cyber security assessment must address all threats that affect the digital assets and assess the control environment’s effectiveness. By understanding the assets, threats and controls, the assessment provides an informed assessment of the cyber resilience and the information security posture. It is then possible to determine and make an informed decision as to whether a vendor or service provider should be allowed access to systems and data.
Best practices for vendor relationship and risk management
In the fast-changing and interconnected digital world, relying on business partners or vendors to provide critical services is necessary. It, therefore, requires effective Vendor or Service provider Risk Management strategies, policies, systems and processes, supported by appropriate tools and techniques.
Since your business cyber and information security is only as strong as your weakest vendor’s control environment, management of their security posture must be governed by the inclusion of appropriate and specific terms embedded in SLA’s. These contractual provisions must specifically provide for the continuous assessment of their cyber security posture, defined in terms of your business’s appetite for risk.
A limitation of traditional third-party cybersecurity assessments is that they are usually static and address risks only a point-in-time view of a vendor’s performance. As a result, vulnerabilities in a third-party’s IT infrastructure can emerge between annual assessments and put your business at risk.
It is necessary that given the rate at which digital transformation is progressing, businesses must plan to continuously monitor their Information, Communication and Technology (ICT) vendors and service providers in near real-time from the moment they’re onboarded. Continuous monitoring puts effective cyber and information security management back into the hands of your management teams.
If you can independently verify your third-party security performance against a quantifiable cybersecurity baseline, you don’t need to rely on your vendors being timely, forward, and honest in their security reporting.
A well developed and implemented ‘security ratings platform’ can provide you with a data-driven, quantifiable baseline or a cybersecurity benchmark of third-party cybersecurity performance. This can be used effectively to monitor security consistency and compliance for the life of the relationships with vendors and service providers.
To effectively manage vendor and service provider cyber and information security risk, it is necessary to implement and use appropriate system driven tools and techniques.
To do so, the following key processes must be established:…
The full article is reserved for our subscribers!
Read the full article by Graham Croock, Director, CyriskCo Advisory, as well as a host of other topical management articles written by professionals, consultants and academics in the August/September 2021 edition of BusinessBrief.
admin@bbrief.co.za | +27 (0)11 788 0880 |



























