Cybersecurity Risk in Vendor Relationships

Your Vendor's Security Is Your Security — Managing Cybersecurity Risk in Third-Party Relationships


The Cybersecurity Risk Reality

Third-party vendors with poor security practices pose a huge risk—regardless of an organization's internal security controls. A threat actor exploiting a vendor's weak cybersecurity eventually accesses an organization's sensitive data, making the third-party vendor's security risks the associated organization's security risks .

Why Cybersecurity Risk Matters

Third-party providers might introduce risks of malware infiltration or system hacks via unsecured access points .

High-profile examples:

  • Target data breach 2013: compromised third-party vendor exposed over 40 million credit card details 
  • SolarWinds hack 2020: hackers infiltrated and severely compromised the Orion IT monitoring platform and many of its users 
  • MoveIt breach 2023: threat actors exploited vulnerabilities to exfiltrate data from approximately 2,300 entities, costing more than $10 billion 

Assessing Cybersecurity Risk

Questionnaire focus areas :

  • What security controls do you have in place?
  • How do you store or process sensitive data?
  • What is your authentication policy? Is MFA mandatory?
  • How often do you conduct backups?
  • Do you have an incident response plan?
  • How do you communicate with customers and stakeholders in the event of a security incident?

Security certifications :

  • Does the vendor follow industry-recognized best practices?
  • Does the vendor have security certifications (ISO 27001, SOC 2)?
  • Have audit and assessment reports been reviewed?

NIST Cybersecurity Framework can be used when designing questionnaires .

Continuous Cybersecurity Monitoring

Security rating services provide independent security posture assessments .

Outside-in scanning can identify security posture without vendor cooperation .

Threat intelligence provides real-time insights into emerging threats .

The Fourth-Party Cybersecurity Risk

A vendor's subcontractors may introduce significant vulnerabilities. Understanding inter- and intra-dependent activities (including those of subcontractors) is a significant facet of vendor supply chain risk .

Cyber Risk Quantification

Quantify cybersecurity risk in financial terms:

  • Loss exposure: industry average data breach cost ($4.88M)
  • Probability: based on vendor security rating
  • Expected loss: Exposure × Probability

Conclusion

Third-party vendors with poor security practices pose a huge risk—regardless of an organization's internal security controls . Organizations that assess and monitor vendor cybersecurity risk will protect themselves from breaches that exploit vendor vulnerabilities.


Action Items for Your Organization

  • Assess vendor cybersecurity practices
  • Review security certifications and audit reports
  • Implement continuous security monitoring
  • Quantify cybersecurity risk in financial terms
  • Address fourth-party cybersecurity risk