You’re responsible for information security at your organization. You dedicate yourself every day to identifying weaknesses and patching vulnerabilities in your network. You’ve developed policies to protect employees from cyber threats. You’ve designed procedures for responding in the event of a data breach, and you’ve practiced those procedures with company stakeholders.
You feel confident that your organization is adhering to best practices for cybersecurity in your industry, and that’s a good thing, because your job can be on the line if an incident occurs.
It’s likely that your executive team is on board with your department’s cybersecurity and incident response activities. After all, they’ve seen the headlines and data breach statistics, and nobody wants to be the next big news story. But there’s another layer to information security that’s a little more difficult to communicate — the security of your third-party vendors.
You’ve taken every reasonable measure to protect your organization from cyber attacks — the last thing you want is for hackers to gain access to your network or sensitive data via a less-diligent vendor. How can you convince your C-suite that vendor security needs to be taken seriously?
Let’s take a look at some possible objections, and how to respond to each one.
Does anyone really get hacked through their vendors?
The rise of cybersecurity as a top concern for corporations has produced some “solutions” that might be considered excessive. Bad actors pushing scare tactics have been successful in tricking people into buying unnecessary consultations, managed services, and software before, so savvy CEOs will be on the lookout for bad deals. It’s possible that your executive team will view vendor risk management through this lens.
Thankfully, it’s easy enough to prove that vendor security threats are very real and very costly. For example, a 2014 data breach at Home Depot exposed 56 million consumer credit and debit card numbers, in addition to email addresses. The hackers in that breach used the credentials of a third-party vendor to gain access to Home Depot’s network. A smarter vendor risk management strategy could have saved the company millions.