Managing cyber risk is more than just monitoring your own network for vulnerabilities and threats – you are just as prone to network attacks stemming from third parties. According to the 2022 Verizon Data Breach Investigations Report, 62% of network intrusions came through an organization’s partner.
If you’re just beginning to develop your third-party risk management (TPRM) program, here are five vendor cybersecurity practices to get you started.
1. Hold vendors accountable to a security standard
Before you onboard new vendors, set a minimum acceptable risk threshold that a third party must achieve to be considered a partner.
One way to do this in a consistent and uniform way is to use a security rating. Bitsight Security Ratings, which range from 250 to 900, provide a data-backed view of a vendor’s cybersecurity posture. If a vendor has a lower rating, they may require a more in-depth assessment than those that meet your risk threshold. For example, a payroll provider or cloud service provider may need to be held to a higher cybersecurity standard than, say, an office supplies company.
Tip: Click here to see average security ratings by industry, and then use this insight to inform your vendor risk thresholds.
Once you’ve established a risk threshold for your vendors, incorporate that metric into your vendor contracts alongside other operational service level agreements (SLAs). Then, use TPRM tools to alert you if a vendor’s security posture drops below pre-agreed thresholds.