When it comes to vendor risk management, organizations ultimately need their vendors to meet the same standard of security performance they hold for their own organization. For years, the Finance industry has been a trailblazer in managing the risk posed by vendors, suppliers, and business partners. However, are vendors in the Finance supply chain meeting the same level of security performance held by Finance organizations?
To answer this question, Bitsight researchers looked at the security performance of more than 5,200 Legal, Technology, and Business Services global organizations whose security rating is tracked and monitored by hundreds of Finance firms using the Bitsight Security Rating platform. These industries represent a set of critical vendors and business partners in Financial Services supply chains, consisting of: legal organizations, accounting and human resources firms, management consulting and outsourcing firms, and information technology and software providers.
The Performance Gap
A significant gap exists between Finance firms and companies in their supply chain. As of September 1st 2017, the mean rating of Finance companies in this study was 710.

The spread of Bitsight Security Ratings amongst Finance Firms and monitored Legal, Technology, and Business Services organizations as of September 1st 2017.
However, the mean ratings for Legal Organizations, Technology Firms, and Business Services firms were 680, 670, and 660 respectively. While managing third-party cyber risk is a relatively new initiative for businesses, this performance gap illustrates the challenge Finance firms have in raising the security performance of key vendors and business partners.
