Earlier this week I had the privilege of attending the invitation-only BNY Mellon 2015 Third Party Risk Management Symposium. The keynote speaker was General Keith Alexander, former Director of the National Security Agency. General Alexander painted a big (scary) picture of our national security and then quickly tied his remarks to the topic at hand: vendor security. He predicted that nation states like North Korea will come after the financial services industry with distributed denial of service (DDOS) attacks, combined with “wiper” malware, through their vendors’ networks. (Wiper malware was used in the recent attacks against Sony-- the first time this type of attack was used against a business operating in the U.S.)
Financial firms are frequently themselves the targets of information security attacks and have been working together through organizations like the FS-ISAC to further improve. The general’s statement reinforced the fact that they need to start treating their vendors and business partners as extensions of their own enterprises.
The Challenges of Managing Vendor Risk
It’s not easy to manage risks across your vendor portfolio, especially when your organization has thousands or even tens of thousands of vendors. The challenges were highlighted in all three panels, whose titles reveal what’s top-of-mind for the largest financial institutions in the world:
- Building a Third Party Risk Management Program for the Future – Be Prepared!
- Taking a Proactive Stance on Third Party Risk Management to Meet Regulatory Compliance
- Third Party Assessments – Are They Enough?
Panelists and audience members from global organizations-- ADP, Citigroup, Credit Suisse, Goldman Sachs, and Wells Fargo, to name a few-- contributed to the lively discussions. Some have more mature vendor risk management (VRM) programs than others, but all acknowledged that developing these programs is especially challenging given the threat landscape and increasing regulatory scrutiny.
Classifying Vendors
Classification of vendors is one of the key steps to take in VRM, and one panelist gave some hints to how they tier their vendors. They develop an inherent risk rating based on the following: