According to an Opus and Ponemon Institute study, 59% of companies have experienced a data breach caused by one of their vendors or third parties — while only 16% claim they effectively mitigate third-party risks. Don’t be a part of these alarming statistics: In order to protect your organization’s valuable information, it’s critical that you set up the necessary security expectations from the onset of a new vendor relationship. Now, as an increasing percentage of businesses are moving to the remote office model, having these security conversations early on is even more critical — because residential IPs account for more than 90% of all observed malware infections and compromised systems.
Of course, simply telling your new third-party partner that you have specific requirements — or asking them to describe the controls they have in place — is not enough. In order to build a strong third-party risk management program, you must explicitly define all of your expectations in a legally binding vendor contract.
Common mistakes to avoid
When you first launch a third-party risk management program, it can be difficult to know what type of contract language you should establish to protect all the assets in your digital ecosystem. Start off on the right foot by avoiding the don’ts listed out below.
DON’T: Begin a vendor relationship before agreeing to security expectations
Your specific security requirements — and enforceability of those requirements — isn’t something to consider after the fact. Work closely with your legal department to create contract language that guarantees your third parties will uphold their end of the bargain when it comes to security performance, monitoring, and remediation. Make sure both sides have agreed to the expectations before you begin your partnership.
DON’T: Use general language
When developing your contract, avoid generalities — like “reasonable security measures” — that offer little to no clarity into the practices you actually expect the vendor to implement. After all, “reasonable” could mean something different to your organization and the third party in question. Instead of using this type of vague language, refer to specific standards and frameworks you want them to abide by.
DON’T: Forget to consider your vendor’s vendors
Fourth parties, or your vendor’s vendors, have a direct effect on your risk outlook, as well. Don’t go into a new partner relationship without the desired visibility and context into your extended ecosystem. Make sure to add language into your vendor contract that stipulates that all security guidelines that apply to your third-party vendor also apply to their subcontractors.