Over recent weeks, the ongoing spread of the COVID-19 coronavirus has forced companies around the country to make difficult decisions about how they can do their part to protect their employees — as well as their communities as a whole.
In an effort to halt the spread of the virus, more and more organizations are instituting a mandatory work from home (WFH) policy, but, in doing so, they’re being faced with a variety of new challenges that make maintaining the desired cybersecurity posture — both internally and within their third-party network — more complex than ever. Furthermore, more organizations are seeking to acquire software ad technology to help accommodate new business requirements. In order to prevent unknown risk from entering your ecosystem, it’s critical that you have a plan in place to rapidly assess, monitor, manage, and mitigate third-party risk.
More risk, less control
When organizations work remotely on such a widespread scale, they open themselves up to new and evolving threats. At a basic level, it’s increasingly difficult for an IT team to enforce stringent security controls and policies when employees are operating from disparate locations on various networks and devices. While some team members may be working on unpatched machines that haven’t been connected to the corporate VPN in days or weeks, others may connect to unsecure, shared WiFi networks while at home.
To make matters worse, opportunistic hackers are taking advantage of the ongoing fear surrounding the pandemic. Bad actors are targeting individuals with phishing emails that appear to come from an official source, such as the Centers for Disease Control (CDC). These emails contain a malware-ridden attachment that infects the computer in question and steals the individual’s personal information.
These risk factors are hard to assess and mitigate in your own organization — and even more difficult to monitor when it comes to your third- and fourth-party network, where you have less visibility and control.
Vendor assessment challenges
Given the current risk outlook during the coronavirus pandemic, the need for companies to collect cybersecurity data about their vendors has never been more critical. That being said, recent travel bans and widespread WFH policies prevent on-site evaluations from being a viable option, completely upending traditional ways of assessing third-party risk. In addition, organizations that have previously leveraged consultants to aid in their evaluation processes now need to rethink their approach. As most consultants will no longer be traveling, it’s more difficult than ever for companies to rely on these outside agencies for assessment insights — meaning many security leaders will need to come up with new policies and procedures to bring these programs in-house.
Of course, any current or new manual assessment processes will be slower and more stressful than ever due to the disconnects and challenges that come with a newly remote workforce. This is a challenge in the current environment with business requirements necessitating rapid software and technology acquisition. Furthermore, even with the latest video conferencing capabilities, brainstorming sessions and planning meetings will be increasingly difficult when everyone’s in a different location and relying on potentially flawed home WiFi networks.
In order to promote efficient and effective vendor assessment and onboarding processes in these conditions, it’s critical to streamline and automate wherever possible. Many organizations will need to completely rethink their assessment schedule and policy to include more remote monitoring capabilities. By leveraging a dynamic, standardized cyber risk KPI, like security ratings, to assess each potential vendor’s security posture side-by-side, you can immediately identify areas of risk that require attention — and make data-driven evaluation decisions with the limited remote resources you have today.