Following a series of high-profile hacks in recent years, third-party cyber risk management has taken a front seat. And, with the help of effective tools, many risk managers are making progress towards program maturity.
But what about fourth-party supplier risk?
The same level of analysis and monitoring should be used when evaluating your extended ecosystem, i.e. your vendor’s vendors. Yet most organization's end their monitoring with their third parties, trusting those organizations are monitoring their suppliers with the same diligence.
Unfortunately, that’s not always the case. And because the supply chain is so extensive, even a small vulnerability somewhere down the line can cause havoc for your business.
Why you need to manage fourth-party supplier risk
Your vendors’ suppliers provide core capabilities and competitive advantages to your business, but they also extend its attack surface in ways that aren't always apparent. This is especially true if they are part of a connected digital supply chain and have access to your sensitive data. Any breach of their network or systems, could expose you to risk. You may also be held financially and regulatory liable for data loss.
But understanding this risk surface is incredibly hard. Most companies work with more than a thousand third parties. Try to imagine the fourth-party ecosystem behind those relationships.
Best practices for monitoring your fourth-party ecosystem
Having the right security practices, tools, and data to monitor your fourth-party ecosystem is critical to your organization's overall cybersecurity hygiene. But with hundreds of thousands of fourth parties to monitor, where do you start?
A best practice is to identify areas of fourth-party concentrated or aggregated risk. Think of these areas as critical elements of your supply chain that could impact your business in the event of a cyber incident. For example, say your company sources technology parts from five different suppliers, but those suppliers rely on the same vendor to supply them with raw materials. If that vendor experiences a ransomware attack, the ripple effect can carry through the supply chain to your business.
Keeping an inventory of your vendors' suppliers can help mitigate concentrated risk, as would contractually requiring your vendors to monitor the security postures of those companies.
But how can you validate that they are actually following through? Even if they do monitor their suppliers, chances are they’re only capturing a point-in-time view of cyber risk.
You need a way to gain visibility into fourth-party risk, continuously monitor for emerging risks, and communicate program performance and risk exposure to stakeholders.
Let’s look at three ways to simplify that process: