When your organization decides to work with vendors, you agree to take on any potential cyber risk associated with that company. Unfortunately, these risks are on the rise. The massive SolarWinds and Kaseya supply chain hacks are headline grabbing examples. But even vulnerabilities in seemingly harmless devices like the GPS technology used by major organizations around the globe can cause significant supply chain risk.
It’s essential that these threats must be identified and mitigated during the vendor due diligence process. But if you are like most organizations, the process of assessing cyber risk across your extended supply chain is time-consuming and inefficient.
If you're looking for tips for improving vendor due diligence to combat growing third-party threats, consider the following best practices.
4 effective vendor due diligence practices
1. Set vendor risk tolerance thresholds
Traditional vendor due diligence assessment efforts tend to be one-size-fits-all, meaning the most critical vendors get the same treatment as less critical vendors – creating more work for security and risk management teams, and delaying vendor onboarding.