CRITICALVulnerability
Global
Stop depending on heroics and start operationalizing third-party risk
·Source: CSO Online
Updated:
Executive Summary
In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and cybersecurity expert between the end-user purchaser and the ven
Analysis
In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and cybersecurity expert between the end-user purchaser and the vendors they want to work with: A typically high-pressure position when you’re perceived as a roadblock to a business goal. As a consultant, we are helping clients establish a formal third-party risk management program often for the very first time. Alternatively, you are providing vCISO or trusted adviser services to perhaps evaluate a specific product or service that lies fairly deep down in the purchasing timeline. That distinction is important, because how quickly security gets involved often determines how much friction everyone experiences. The number one problem I see? Security is always last to know. When security enters too late A business team determines what kind of tool it needs. Operations want efficiency. Finance is ready to fund it. Momentum builds. Then someone says, “Wait a minute… What about cybersecurity and compliance? At that point, our role is to ask the questions that should have been asked earlier: What data will this vendor touch? Where will it reside? What controls exist and are needed? Does the vendor’s security posture (and its product) match the client’s obligations and risk tolerance? Being the one applying the brakes at the 11th hour is not a role anyone relishes. But that often becomes what third-party cyber risk management turns into when there is no formal intake and review process. This is something that I have witnessed time and again with clients. The team is excited about a new platform and reasonably anticipates a quick go/no-go. Instead, the review process turns into weeks of ping-ponging with the vendor: Responses to questionnaires, security documentation, clarifying calls, proof or non-provision of compliance, legalese and data flow discussions. That delay can feel painful to all involved if the end user organization does not have a mature process already in place. The business sees friction. The vendor sees hurdles. Security sees unresolved risk. The key to getting in early is working with your legal and finance, or procurement teams to bring you in as early as possible. These will be your partners in making sure the assessment is done before anything is signed. In my experience, once the ink is dry on the contract, you have lost all leverage in being able to get action from the third-party. A mature assessment will build in contract language to address gaps or weaknesses. This is the only thing that works in getting the outcomes you are looking for. Building a repeatable review process At root, we’re trying to help end-user organizations build structures around vendor evaluations to ensure a repeatable process; something that is defensible and aligned to their business operations. This is not a simple product review. We are helping them translate security, compliance and operational requirements into a workable framework for making a deployment decision. A lot of end-user organizations lack the internal time, expertise or leverage to push solution providers on technical controls, audit evidence, shared responsibility or gaps in documentation. As the intermediary between them and the vendor, we do that legwork for them. Because we can ask the questions that need to be asked and how those answers should be interpreted. When one listens to a polished sales narrative, it is not the same thing as sustainable assurance for compliance. The most important part here is making sure the assessment timelines are clear and consistent, and the purchaser is aware of them. It is also critical that the end user is aware of where the assessment is and if it is sitting with the internal team or the customer. The internal budget holder is always the key to getting action from the vendor, as they typically see the security team as an impediment to the sale. Done well, third-party cyber risk management is not about blocking business. It’s really about getting clients onto their projects faster and with fewer surprises and less business risk. Expanding beyond security to add business value Today, any employee with a budget expects to bring in new technology on a very tight timeline. But I’ve seen this lead to many problems: the biggest of which is failing to solve the business problem. Purchasers fall in love with the interface, one specific feature, the price, the salesperson — you name it, I’ve seen it. Often not even defining what they are trying to solve prior to a purchase. The business problem and success criteria should be defined before any purchase is made, and security can be one of the criteria for scoring, provided the vendor meets a qualifying security score. AI makes the challenge more urgent AI is shaking up the world of third-party risk in two ways at once. One is that vendors have been speed-dialing AI into their respective solutions. Secondly, AI tools are being brought into the workplace without IT authorization [ shadow AI ], often happening before security or compliance teams are made aware. Essentially, the age-old third-party risk problem of security teams learning last is moving more quickly and on a larger scale. It’s not only because AI tools are new that causes organizations to worry. It is that people can start using them at once, usually entering sensitive business data into systems that have not been vetted for privacy, retention period and whether models trained on this data will be available for other users to access. Proactive vendor governance is therefore all the more crucial. With no front-end process for intake and assessment, the organization will always be reacting after the fact. This is where a lot of companies need to reset their expectations. Third-party cyber risk management is an ongoing process that does not work as a side task of procurement, nor can it live entirely in security. It needs to be operationalized across the business. The organizations that do this best set up workflows for bringing in new vendors, identify data exposure early, assign review responsibilities and earmark exceptions before signing a contract. Companies that fall behind depend on heroics. Somebody sees a risk late, hustles to gather documentation from two parties in different time zones and then fights the vendor for answers while trying to make a sound judgment on limited information. It can work once or twice, but it’s not a program. What you can do is simple: build up the process before urgency hits. Know who owns intake. Know when security gets involved. Know what evidence is required. Understand how the AI tools will be assessed before they start entering the workspace. Balancing the needs for compliance, operational realities and the pace of technology adoption enables the business to make decisions about the vendors they depend on with confidence. The reality is that there are vendors that are good at securing your data, and there are vendors that haven’t even thought about it and all kinds in between. The goal of a good process is to identify which kind of vendor you are dealing with and hold them accountable for any risk. One of the most important features of a mature third-party risk program that is most often ignored is using the contract to hold vendors accountable. A third-party program without this step rarely produces the expected outcomes because there are no financial teeth to the requirements. Third-party risk management is not about eliminating friction but shifting it to the right place where it can make an actual difference and organizing it in a way where one can manage it. This article is published as part of the Foundry Expert Contributor Network. Want to join?