Your Vendor's Security Is Your Security — Managing Cybersecurity Risk in Third-Party Relationships
The Cybersecurity Risk Reality
Third-party vendors with poor security practices pose a huge risk—regardless of an organization's internal security controls. A threat actor exploiting a vendor's weak cybersecurity eventually accesses an organization's sensitive data, making the third-party vendor's security risks the associated organization's security risks .
Why Cybersecurity Risk Matters
Third-party providers might introduce risks of malware infiltration or system hacks via unsecured access points .
High-profile examples:
- Target data breach 2013: compromised third-party vendor exposed over 40 million credit card details
- SolarWinds hack 2020: hackers infiltrated and severely compromised the Orion IT monitoring platform and many of its users
- MoveIt breach 2023: threat actors exploited vulnerabilities to exfiltrate data from approximately 2,300 entities, costing more than $10 billion
Assessing Cybersecurity Risk
Questionnaire focus areas :
- What security controls do you have in place?
- How do you store or process sensitive data?
- What is your authentication policy? Is MFA mandatory?
- How often do you conduct backups?
- Do you have an incident response plan?
- How do you communicate with customers and stakeholders in the event of a security incident?
Security certifications :
- Does the vendor follow industry-recognized best practices?
- Does the vendor have security certifications (ISO 27001, SOC 2)?
- Have audit and assessment reports been reviewed?
NIST Cybersecurity Framework can be used when designing questionnaires .
Continuous Cybersecurity Monitoring
Security rating services provide independent security posture assessments .
Outside-in scanning can identify security posture without vendor cooperation .
Threat intelligence provides real-time insights into emerging threats .
The Fourth-Party Cybersecurity Risk
A vendor's subcontractors may introduce significant vulnerabilities. Understanding inter- and intra-dependent activities (including those of subcontractors) is a significant facet of vendor supply chain risk .
Cyber Risk Quantification
Quantify cybersecurity risk in financial terms:
- Loss exposure: industry average data breach cost ($4.88M)
- Probability: based on vendor security rating
- Expected loss: Exposure × Probability
Conclusion
Third-party vendors with poor security practices pose a huge risk—regardless of an organization's internal security controls . Organizations that assess and monitor vendor cybersecurity risk will protect themselves from breaches that exploit vendor vulnerabilities.
Action Items for Your Organization
- Assess vendor cybersecurity practices
- Review security certifications and audit reports
- Implement continuous security monitoring
- Quantify cybersecurity risk in financial terms
- Address fourth-party cybersecurity risk