Onboarding third-party vendors that will have access to your network and data can have dire consequences if you don’t have the ability to gauge vendor risk.
In a recent joint survey between Bitsight and IDG Research Services, more than 260 IT managers and professionals, nearly 70% said they were “extremely concerned” or “very concerned” about the security risks posed by third-party vendors and suppliers. Another study found that nearly two-thirds of breaches involve a third party.
One way to calculate risk is by using a continuous monitoring and risk assessment tool, which allows ongoing awareness of information security, vulnerability and threats that a vendor may pose. The trick is to be able to monitor vendors in real-time.
If you are not continuously monitoring vendor risk, then you’re probably performing point-in-time assessments, which are typically only snapshots of an organization's security posture. For example, if you are looking to onboard a vendor, you can have them complete a risk assessment, a penetration test or a vulnerability scan- all at considerable costs. And more costs are added if the vendor ultimately experienced a security event, and the organization is back to the start, going through another point-in-time assessment. This type of security is no longer sufficient because cyber criminals are creating new malware at an alarming rate and new vulnerabilities continue to populate the cyber risk landscape. Bottom line, if organizations are not looking at their vendor’s security before, during and after onboarding, it's likely that they may miss some sort of negative security event.
In a white paper called, “Don’t Let ‘Trusted’ Vendors Become Cyber-Breach Enablers,”Bitsight and IDG found that only 10% of respondents said that they use a dynamic, automated system to monitor security posture on a continuous basis and report results back to vendors and suppliers to demonstrate and address security gaps and analyze and determine fourth-party/subcontractor IT risks.
1. Validating Security Performance
Continuous monitoring is not a check-the-box activity like the traditional risk assessments previously described. In the past, organizations performing a risk assessment would simply check the box and say, ‘yes we have a firewall,’ and ‘yes we have antivirus software.’ Continuous monitoring takes the bias out of that exercise and provides organizations with confidence that the vendor does actually have a firewall or antivirus solution in place. It's a proof point. A company could say on their risk assessment that there are no infections on their network as of today, but a continuous monitoring tool can prove that to be right or wrong. With continuous monitoring, companies get validation regarding the truth of the security posture.
2. Keeping Up With the Security Landscape
It's not enough to use a spreadsheet to track every aspect of your vendors security anymore. Things change too quickly and most security professionals agree that a static assessment or a point-in-time assessment doesn't truly capture the security risk of the company. Continuous monitoring allows you the ability to measure security trends and get a more granular view of your vendors performance, which you can compare to yesterday, to three months ago, or even to last year. You can see how a security program at an organization is maturing or not.