When it comes to third-party risk management (TPRM), many organizations are just beginning to figure out the core components of their program — and some are not implementing any measures to monitor their third parties at all.
According to Ponemon’s November 2018 report “Data Risk in the Third-Party Ecosystem”, 54% of organizations saying their companies do not monitor the security and privacy practices of vendors with whom they share sensitive or confidential information (or they are unsure), but only 29% trusting the vendor to tell them of a breach. That being said, where do these companies who are just starting out in their risk management journey actually start when putting a TPRM program into place?
It’s widely known that risk from the supply chain, or third parties, is one of the most pressing risks for businesses worldwide. However according to Ponemon’s report, most organizations, don’t have the confidence, resources, or inventory to be able to even start a TPRM program, and of those that do have a program only 35% rate it as highly effective. If they do have an existing program, it is oftentimes inefficient in terms of procedures and processes; sometimes it can take up to several weeks to complete risk assessments or vendor cyber risk assessment questionnaire with a small team (sometimes even just one person!) in place. Ultimately, this slows down the business in day-to-day operations.
While point-in-time cyber security risk assessments are not an accurate representation of the dynamic risk present across all functions of an organization, it’s important for companies to realize that implementing a mature TPRM program with continuous monitoring of vendors takes time. While this is the standard, not every organization is ready to implement it on day one. You need a plan to get there. The path that organizations take to get to those mature third-party risk management programs starts with launching their program. While it may seem reactive at first, eventually, it will expand to more continuous, automated processes that allow their organization to scale.