Third parties are essential to helping your business grow and stay competitive. But if you’re not careful, your trusted partnerships can introduce unwanted cyber risk and overhead into your organization.
Cyber security assessments are key to understanding the cyber risk that your vendors may pose whether you’re onboarding them or re-evaluating during an audit period.
Knowing that resources are often stretched and the pressure from management to quickly complete cyber security assessments is intense, we compiled five best practices that can help streamline the process and yield better risk reduction.
1. Look to industry-standard cyber security assessment methodologies
When it comes to your third-party cyber security assessments, there’s no need to reinvent the wheel. Consider borrowing from widely adopted assessment methodologies such as the SANS Top 20 Critical Security Controls or the NIST Framework for Improving Critical Infrastructure Cybersecurity. Both combine best practices and information security standards for reducing cyber risk that can be applied to your vendors. Alternatively, there’s Shared Assessments, a trusted source in third-party risk management that develops security risk assessment questionnaires for use by its members.
2. Tailor your assessments
No two vendors are the same, so why assess them in the same way? Using the same assessments for all vendors can be a drain on resources and increases the time and cost of completing the process. Instead, consider grouping vendors by criticality and tailoring your assessments accordingly.
A “critical” vendor may be one who has access to sensitive data or provides an important service, such as a payroll provider. They present a much higher level of risk than an office supply company that doesn’t have direct access to your network or employee data. Tiering vendors in this way can help you determine whether they need a more in-depth cyber security assessment. This way you’ll make better use of your resources, allocating them where more due diligence is required.
You can also go beyond your initial tiering and use data from Bitsight Security Ratings to compare vendors’ security profiles side-by-side. From here you can further prioritize which vendors need the most attention. Higher scores have been correlated with better security postures and perhaps indicate the need for a less rigorous cyber security assessment.