With increased emphasis on third party risk management coming down from regulators and executive boards alike, cyber risk in the extended enterprise is shaping up to be a hot topic in 2014.
Bitsight board member Mike Duffy recently contributed an article to Risk Universe on the topic. In the article, "Rating Cyber Risk Vendors," Duffy explains why organizations are looking to cyber risk rating services to help manage their vendor security risk. Citing examples of recent high profile third party breaches, such as the JP Morgan Chase UCard breach, and increasing concerns amongst boards and executives about cyber risk, Duffy says now is the time for organizations to consider investing in new ways to manage this risk.
The article goes on to explain the limitations of current solutions and how relying on questionnaires and audits alone leaves organizations with blind spots as certain things are overlooked or emerge in the changing threat landscape: