4. What standards should my suppliers meet? How do I know they’re meeting them?
The answer to this question depends on the industry in which you operate. If you’re in the medical field, you’ll want to ensure that your vendors are HIPAA compliant; if you’re in the financial industry, then SEC guidelines,Service Organization Control (SOC) Type 2, PCI compliance, and more come into play.
To ensure that your vendors are meeting cybersecurity standards, work with stakeholders, including risk management, legal, and HR, to determine:
5. What’s the average size of a supplier risk management program? How many people do I need internally?
To be most effective, supplier risk management programs need dedicated resources to launch, manage, and scale them.
Depending on the size of your business—and your level of third-party risk exposure—this responsibility may fall on a single individual, a full team, or a larger group. However, there are many tools that can help you and your team balance limited resources with the growing need for vendor risk management.
6. Who should my main contact be with my suppliers?
Strive to have a single point of contact, from onboarding through the end of the contract term. Someone you can collaborate with to monitor and reduce risk.
He or she could be a chief information security officer, chief risk officer, IT leader, or any number of people depending on how the company is structured. You must be able to rely on this contact to get the appropriate team and information together and keep you in the loop should a problem ever occur. This person should have specific insights into IT operations, security components, and the elements of your contract.
Read how Alameda Alliance for Health strengthened its vendor partnerships using third-party collaboration and risk management best practices.
7. When should I go on-site to meet with my suppliers?
Many vendor risk management tasks can be completed digitally without the need for in-person collaboration. However, there may be instances where on-site visits are warranted. For example, during the selection of critical vendors (including those with high levels of network access), an on-site visit can help you understand a third-party’s operations and security practices and provide an opportunity to meet security and risk leaders.
8. If a major security event occurs, how can I know if my supply chain is impacted?
When a major event like SolarWinds or Log4j occurs you need to quickly assess the impact across your supply chain and what your suppliers are doing to mitigate risk.
Calling your point of contact is one option, but these attacks often happen at scale and getting answers quickly isn’t always easy. A better approach is to use monitoring tools that detect and highlight critical vulnerabilities and quickly pinpoint which vendors in your portfolio are impacted. With these insights, you can prioritize vendor outreach at speed, remediate risk faster, and build stronger vendor relationships.
Once the contract is signed, it’s critical that you understand your vendors’ changing risk profiles. Annual cybersecurity audits can help with this task, but they are often handled by third parties, take time to perform, and are costly.
A cybersecurity audit program has a time and a place, but it shouldn’t be the be-all, end-all solution. Consider reserving in depth audits for your most critical vendors or those who have a track record of security issues.
Augment this approach with continuous monitoring so that you can keep a pulse on the cyber health of every vendor in your portfolio—quickly and confidently.