Prioritizing vendors based on risk is considered a vendor risk management best practice. But how do you do this? To start, let’s look at a commonly referred-to equation:
Risk = Threat x Vulnerability x Consequence
While this risk equation may be helpful in some ways, it’s also tough to use. Why? Because it’s extremely difficult—if not impossible—to assign a value to threat and vulnerability. Most organizations should assume a high level of threat and vulnerability, no matter what. (So, if you are assuming each variable in this equation is assigned a value between zero and one, threat and vulnerability would both have a value of one.) Simply put, there will always be individuals with malicious intentions who may target your organization, who can exploit common vulnerabilities in your IT systems. It’s hard to do much to change this reality.
That leaves the final part of the equation: consequence. The difference here is that you know the consequence to you if a vendor is knocked offline for a number of days, or if your data is somehow compromised or stolen due in part to one of your vendors. Because of this, you can assign a value to consequence. By understanding the consequence of a cyber incident affecting your vendors, you can truly begin to focus your vendor risk management program on those organizations that are most critical to you and adopt vendor management best practices.
All of this begs a simple question: “What should I be doing to make my vendor management practices a little more focused on risk?”. Below, we’ve outlined five critical best practices that your organization can get started with today.
4 Important Vendor Management Best Practices
- Perform a risk assessment. A risk assessment helps organizations understand what kind of data is valuable to them—whether that is pricing information, R&D, customer data, financial data, or something else. This information should be identified and located - does it all live in-house, or do we trust some third and even fourth parties to keep and store that data? Past that, it’s vital to then understand who has access to that data and limit privileges as much as possible. It’s pretty obvious that third-party vendor risk management plays a huge role here because it’s very important for you to know what is happening to your data when it’s outside of your organization.