Vendor risk management is top of everyone’s mind in light of the recent SolarWinds supply chain attack and concerns around weak points in the COVID-19 vaccination supply chains. Both exemplify the need for organizations of all types to take steps to fortify their vendor risk management processes.
Of course, that’s easier said than done, especially as supply chains continue to grow. According to Gartner, 60% of companies work with more than 1,000 third parties. When supply chains are that extensive it can be challenging for even the most vigilant organizations to have complete visibility into the security postures of all of their partners.
To make things a bit easier, we’ve put together a list of four best practices that every organization should follow as they look to strengthen their vendor risk management practices.
1. Continuously monitor third-party vendors
Traditional point-in-time cyber security assessments don’t tell the full story of a vendor’s potential for risk. They only give organizations a brief snapshot in time and thus provide poor and incomplete visibility into security risks. Plus, they can be time-consuming to complete and in many cases biased, whether intentionally or unintentionally.
Continuously monitoring third-party vendors is a much more complete and accurate way to gauge a vendor’s true security posture. Through continuous monitoring, organizations can be immediately alerted to any potential vulnerabilities throughout their entire supply chain. When these weaknesses are exposed, security teams can react quickly and focus their efforts on mitigating these exposures in near real-time. There’s no need to wait for an out of date, once a year security assessment.
With continuous monitoring, companies can also deliver periodic risk reports on individual vendors or in aggregate. They can use these reports to gain an accurate representation of their vulnerabilities and strengths at any time.
This can be a particularly useful practice in the wake of a major supply chain attack, such as the SolarWinds incident, to ensure that there have been no hard to detect intrusions within third parties.
2. Use security ratings to gauge risk
When it comes to continuous monitoring, security ratings can be an indispensable tool. Security ratings measure the performance of a company’s overall risk management capabilities, with a higher score indicating a better approach (and more trustworthy organization).
Bitsight offers the only independently verified security ratings database. In fact, according to AIG Research, a company’s Bitsight security rating can be used to reliably predict a company’s future security performance. For example, an organization with a security rating of 400 or lower is five times more likely to experience a breach than a vendor with a rating over 700. You can use these easy to understand cyber risk metrics to determine where your weakest links are and make better decisions about which vendors to use.