As cyberattacks surge, you’re charged with protecting your organization’s expanding digital footprint. But what about the risk posed by vendors?
It’s estimated that 60% of organizations now work with more than 1,000 third parties. If not properly vetted, these companies can expose your organization to risk.
But evaluating each vendor – before and throughout the relationship – is a task often dreaded by security and legal teams because of the time and effort required by this vital due diligence.
It doesn’t have to be that way. Instead of stretching yourself thin trying to manage every third-party vulnerability, you can save time and resources by prioritizing risk management based on your cyber risk appetite.
What is cyber risk appetite?
Cyber risk appetite is defined as the amount of risk your organization is willing to accept as it pursues its objectives. Defining your risk appetite matters because it helps executives make informed and confident decisions about who you do business with and how and where security resources are allocated. It also drives more efficient risk management.
Let’s look at five ways you can define your cyber risk appetite and hold your vendors to that threshold – without overburdening your security team.
1. Establish an acceptable vendor risk threshold
One way to establish the risk you're willing to take with your vendors in a consistent and uniform way is through a security rating. Bitsight Security Ratings, which range from 250 to 900, provide an objective, external metric of a vendor’s cybersecurity posture. These ratings can be used to set an acceptable risk threshold that a third-party must achieve to be considered during the selection process. If a vendor falls below a set threshold, you can save time and effort by focusing instead on companies that have robust security controls in place.
To further define a risk threshold, consider tiering your vendor pool based on their risk and criticality to the business. For example, a payroll provider with access to sensitive data would be classified a top-tier vendor and held to a higher standard of security performance. However, a food service company would belong in a lower tier with a less stringent risk threshold.
Tiering requires consultation with your legal, finance, and compliance teams, but you can fast-track the process using Bitsight’s tier recommender service. The service uses tiering best practices and provides a suggested tier for each vendor determined by the nature of the third-party and the risk they pose.