In today’s interconnected world, supply chains are growing exponentially. As a result, third-party risk has become a big focus for senior management. But what about the vendors that your suppliers rely on and the threat of fourth-party risk?
Fourth-party risk is the process of assessing and managing risks, such as cybersecurity vulnerabilities or compromise, in your extended vendor ecosystem. Fourth parties are the vendors behind your vendors; the additional layer of suppliers beyond your immediate third-party partners.
The importance of fourth-party cyber risk management
While your vendor’s subcontractors provide your business with core capabilities and sources of competitive advantage, they also extend its attack surface in ways that are not always understood. They may even lack direct relationships with all of the parties involved.
To mitigate vendor cyber risk, organizations must go beyond third-party risk management to achieve a new level of risk awareness and reduction.
The challenges to knowing your extended ecosystem
A study by Gartner finds that 60% of organizations work with more than 1,000 third parties. Try to imagine the size of the fourth-party ecosystem behind that. It’s almost impossible to fathom.
This risk surface also continues to expand in ways which are not understood – most notably in the area of cybersecurity. Without a clear understanding of the business relationships and security posture of your extended ecosystem, outages, disruptions, and compromises can threaten your organization. You may also be held liable for data loss and struggle to achieve any level of cyber resiliency.
Unfortunately, many organizations are using flawed approaches to overcome these challenges.
According to research by financial services firm EY, 28% of organizations fail to monitor subcontractors at all, while 80% rely on their third parties to passively monitor fourth parties through contracts, SLAs, warranties, and self-assessments. Each of these methods show a point-in-time snapshot of the parties’ security postures. As such, they may not be entirely up-to-date or accurate.
Fourth-party cyber risk management is also hampered by many of the solutions offered by security and risk management firms. Many simply provide their clients with an inventory or list of their fourth-party suppliers under the guise of a “fourth-party risk management” solution.
In reality, you can’t claim to be managing fourth-party risk until you’re also managing and monitoring the connections between the fourth parties and their associated partners.
The impact of “concentration risk”
To better understand how your organization can manage fourth-party risk, cyber or otherwise, you need to know what you’re looking for.
Start by identifying areas of concentration risk--critical areas of risk in your supply chain that could impact your business in the event of a breach or other cyber-attack. Concentration risk (also known as aggregate risk) is becoming an increasingly large problem that can create a nasty ripple effect throughout your entire supply chain.
Previously, the approach to mitigating concentration risk was to ask your vendors to provide additional information on what types of vendors and subcontractors they work with. This approach is problematic because the responses are subjective and not verifiable.
Furthermore, as the EY study finds, nearly 75% of organizations say that fourth-party concentration risk would be extremely challenging to report on or that they can’t report it at all, often because they don’t know all of their vendors.