Data breaches that originate in an organization’s supply chain are more prevalent than ever. According to the 2022 Verizon Data Breach Investigations Report, 62% of network intrusions came through an organization’s partner.
For this reason, it’s critical that you conduct a rigorous and extensive analysis of a vendor’s security posture – before they are onboarded. However, for most organizations this is a costly and lengthy process. Gartner reports that it takes most companies an average of 90 days to complete vendor due diligence. This can undermine your business’ efforts to accelerate growth and remain competitive.
But it doesn’t have to be that way. Let’s look at a few best practices you can adopt today to onboard new vendors securely and at the speed of business.
1. Don’t treat every vendor the same
One way to save time during vendor onboarding due diligence is by grouping or tiering your vendors based on how critical they are to your organization.
Not all vendors will have the same risk threshold. For example, a company that provides an important service or has access to your sensitive data (like a payroll provider) would be a higher priority than a company that does not have immediate access to proprietary information or performs a mission-critical function (such as a food service business).
By moving beyond a “one-size-fits-all” approach during the due diligence process and tiering your vendors in this way, you can determine if a vendor needs a more in-depth evaluation and focus your resources where they’re needed most.