Earlier this month, Bitsight released it’s
Third Annual Bitsight Insights Industry Benchmark Report which looks at the security performance of 6 key industries: Federal Government, Healthcare, Retail, Finance, Education and Energy/Utilities. Within this report, you can see how performance varies across these industries in areas like their response times to remediate security events and their susceptibility to high profile SSL vulnerabilities like POODLE and FREAK.
While the information in this report does not cover every industry, it does provide a good example of ways that organizations can begin to use industry data in their
vendor risk management programs. Below, I have outlined three ways that the industry and peer data found within the Bitsight Security Ratings Platform can help with this critical aspect of vendor management.
1) Contract Negotiation & Vendor Selection
Whether you are selecting a new vendor or renewing a contract with an existing vendor, it’s never too late to introduce security performance metrics into the conversation! Naturally, when you are considering who to begin/continue doing business with, you want to enter the negotiations with knowledge of their performance and make sure you are choosing the safest partner possible.
Comparing a vendor’s performance against others in their industry will give you insight into important factors such as: is this vendor more or less secure than others in their industry? Does this vendor have reliable, consistent performance over time? Is this vendor responsive in addressing known security vulnerabilities? Use this information to negotiate contract terms with your vendors and set standards for what you expect for security performance in a third party relationship.
2) Drive Performance Improvement & Acknowledge Good Results
If you have an existing relationship with a vendor, performance benchmarking can also be a helpful tool for driving more frequent, data-driven check-ins. With access to continuous performance data, you no longer need to wait for annual or periodic assessment results. When you are monitoring performance on a continuous basis, you can immediately be alerted to issues facing your vendors, and see how they are faring in performance against the rest of their industry.
Additionally, if you have a “problem” vendor, you can more easily determine where to assign additional resources to help remediate the risks in this relationship. When a vendor demonstrates noticeable improvements in performance, you can also reward them with acknowledgment and appreciation for their efforts to protect your data.
3) Communicate Performance in Business Terms
More and more often, security professionals are being asked to explain security performance with metrics that are easy for the rest of the business to understand - i.e. are we more or less at risk than we were before?
With board members also wanting visibility into third party security performance, security benchmarking enables these discussions to enter the boardroom. Industry standard metrics allow you to benchmark vendors and assess the performance of your entire vendor portfolio, organized and tiered based on your own designations. Reports show performance changes over time for vendors and industries, and can shine light into the events and vulnerabilities putting your data at risk. Your leaders will finally be able to understand how third party relationships are impacting your security posture and decide whether risk thresholds for the business are being exceeded.
There are many other ways that industry data can be used in a comprehensive vendor risk management program, but these options represent a few of the ways our customers have found value from Bitsight Security Ratings and the benchmarking data they provide. Through this understanding of industry trends, organizations can see how their specific vendors are doing relative to their peers and focus on the vendors that pose the greatest risks, thus improving their overall security performance.