In today’s security ratings services market, a few companies have offerings described as “swaps” or “slots.” When considering third party monitoring, this gives organizations the option to “trade out” which vendors they are monitoring when they see fit. But, does this type of disjointed monitoring actually proactively mitigate risk (which is the goal of utilizing a security ratings service) or just shift it around and hide it? This approach poses several problems.
As data breaches originating on third party networks occur more and more frequently, businesses have increasingly built out Vendor Risk Management (VRM) programs. Developing these programs to account for cyber risk is no easy feat: Bomgar’s 2017 Secure Access Threat Report found that the average number of vendors accessing a company’s network has doubled in just one year to 181 per week, with 67 percent of companies experiencing a data breach because of unsecured vendor access. With supply chains expanding and businesses increasingly sharing data, organizations need continuous visibility into the third parties they work with to safeguard their own data. With hundreds or thousands of vendors introducing new risks, security teams need to be able to continuously monitor the networks of their vendors.
As mentioned above, other security ratings firms may provide a number of slots for vendors that can be changed at any moment. The issue? This does not allow users to gain continuous visibility into companies as they constantly swap them out. By adhering to this “swapping” method, organizations lose visibility into significant changes in the security performance of their supply chain as they shift focus on another subset of vendors.
Traditional assessments such as penetration tests, security audits, and questionnaires don’t provide this continuous visibility, and neither does attempting to swap vendors in a security ratings portal. This continuous visibility into vendor networks is the key to proactively mitigating cyber risk. Moreover, conducting these “swapping” exercises across the supply chain is both costly and resource-intensive. “Swapping” out vendors for others is not a sustainable model — eventually your number of vendors may become so great that your team can’t handle swapping some in and some out constantly.