Business leaders now realize that their data is being exposed to risk by their vendors, and that monitoring and remediating these threats is a necessary part of an effective cybersecurity program.
However, even companies with strong vendor risk management programs have an arbitrary barrier between procurement and security.
The job of choosing a vendor belongs to one team, and the job of assessing whether that vendor is exposing the organization to cyber risk belongs to another. In some cases, a vendor’s cybersecurity is not even a consideration during the procurement process.
The Problem with Siloed Procurement
When procurement teams fail to consider cybersecurity, they can put the organization at risk.
Let’s say your company is looking for a new video conferencing solution. You examine the organization’s needs and develop selection criteria. You put out an RFP. You select a few solutions for live demos. Finally, you choose a solution, write up a contract, and sign the deal.
At what point are IT and cybersecurity teams called in to analyze the risk of these vendors? At many companies, this analysis occurs after finalists have been selected and just before a deal is finalized. Of a shortlist of five video conferencing solutions, only one might have adequate cybersecurity performance to be accepted as a vendor. This vendor might be chosen by default, but are they really the best choice for the organization? And is “adequacy” always the best way to judge a vendor?
The issue is that cybersecurity performance is treated as a final check on selected candidates, rather than an integral part of the selection criteria. In reality, cybersecurity should be as much of a consideration as cost, services, experience, customer reviews, or any other method for selecting a third party.
This way, the companies that make it to the shortlist won’t need to be checked to make sure their cybersecurity performance is passing. Instead, they’ll be companies whose cybersecurity performance is best-in-class.
A Better Procurement Method
There are a few reasons why a procurement process would only include security due diligence towards the end of evaluations. Maybe it was just an oversight, or maybe IT and security just don’t have the bandwidth or resources to play a bigger part in the process. A procurement professional might argue that the timeline for a vendor risk assessment (sometimes a few weeks) would cause the process to drag on for too long.