1. Determine the type of network and data access each vendor has
The first step to understanding the inherent cybersecurity risk that each vendor poses is to conduct an inventory of your third-party relationships.
It sounds logical, but with an uptick in shadow IT and cloud services, two thirds of companies fail to maintain a vendor inventory. Without one it is hard to grasp the complex web of interconnected business relationships in your digital supply chain and the level of data and network access granted to each of your vendors.
One way to overcome this challenge is to continuously monitor your extended digital ecosystem. For instance, with Bitsight you can quickly discover the vendors you do business with – and their relationships with subcontractors. With this insight, you can discover which vendors have access to what systems, track the flow of sensitive data across your supply chain, and identify risky business connections – such as third, fourth, and nth parties who have less than stellar security postures.
From here, you can tier your vendors based on how closely they work with company data and establish standards for evaluating those in the top tier instead of wasting resources on lower-tier vendors that don’t have access to sensitive information.
2. Gain visibility into a vendor’s prior cybersecurity performance
The historical security performance of your third parties is a useful indicator of future performance. A vendor might not have had a cyber incident or data breach in the past year, but what if they suffered a serious breach in each of the five years prior?
Unfortunately, this information can be hard to glean. Questionnaire-based cyber security assessments are helpful, but the information provided by third parties is often subjective and risk managers must take each vendor at their word.
A better way to determine a vendor’s historical security performance is to use Bitsight for Third-Party Risk Management. In addition to detecting cyber risk in a vendor’s current digital environment – such as vulnerabilities and malware – Bitsight reflects their overall security performance. Analyzing historical data can help your security and risk management teams determine if a vendor requires more diligent assessment during the onboarding process or more frequent audits through the contract term.