You’ve likely heard your fair share of mortifying headlines around IT vendor management mistakes. Many of the highly publicized breaches in the last several years happened simply because the companies did not follow basic best practices for IT vendor risk management (VRM).
But our goal isn’t to point fingers. We simply want to help you avoid making those same mistakes! The following nine tips and tricks will help you organize your IT vendor management processes—and they may help you avoid being in the spotlight for embarrassing reasons.
1. Know who your vendors are and what they have access to.
Many organizations don’t have a complete list of their vendors. Or, even if they do have such a list, they don’t know what kinds of data their vendors have access to and whether their vendors have direct access into their network. These are major issues. You should be taking the cybersecurity posture of your vendor very seriously to avoid any unwanted consequences.
2. Know how vendors are connected to you.
If you can recall the highly publicized Target breach of 2014, you’ll remember that Target had contracted out to Fazio HVAC to wirelessly monitor their refrigerated units. Target knew Fazio HVAC had a connection, but they didn’t know the extent of the connection—and they certainly didn’t realize someone could get access to their entire corporate network through one HVAC company. It’s perfectly reasonable to provide third parties with access to your network—but you have to be able to limit their access to what they truly need. Frankly, anything else is negligent.
3. Know which vendors have your sensitive data.
This is a combination of knowing who your vendors are and analyzing what constitutes sensitive data. This could be health care records, research and development, credit card numbers, or a number of other “crown jewels.” Make sure you understand where your most sensitive data is going and who could potentially get their hands on it.