If your organization outsources to vendors, you are probably involved in a lot of due diligence. You may be looking at and verifying credit checks, getting background reports, monitoring legal standings and litigation, ensuring that third parties pay their bills and don’t employ criminals, and more.
But are you paying attention to the cyber security posture of your vendor? This is a new risk factor companies are beginning to worry about—and rightfully so.
In today’s business landscape, data is being shared with many vendors and housed in their networks, so it is incredibly important to take every precaution necessary to protect your data. Even if you have a strong standing relationship with your vendor, how do you really know that they’re protecting their own information appropriately, let alone handling yours with care? The steps laid out below will help you ensure that you’re mitigating vendor risk, from pre- to post-contract.
Pre-Contract Diligence
Ask yourself this question: “Are all of my vendors protecting our data appropriately, in accordance with the relationship we’ve established?” If you’re hesitant on answering “yes” for even a moment, you could have a vendor risk problem.
Take the first step toward a better VRM program today by downloading this free guide.
During your pre-contract phase, you’ll want to be sure a particular vendor is on the “up and up” before you sign a deal with them. This is typically done by determining:
- The extent of their access to your network and data.
- The sensitivity of the data they have access to.
If they have access to a large deal of data, or even a small amount of highly sensitive data, follow these steps:
- Build the expectations of how you expect the vendor to secure your data into your contract. In other words, write up your vendor contracts so they are legally airtight. You’ll want to make sure there’s a clause for incident notification if something goes wrong. (We’ll return to this concept in step seven.)
- Ask your vendor to provide documentation of what they’re doing with respect to IT and data security.
- Perform an interview or an on-site visit. This isn’t always necessary—and can be extremely costly—but in some cases, it’ll give you assurance that what your vendor is saying on paper is what they’re actually doing in practice.