If your organization is entering into a relationship with a vendor or partner, vendor due diligence is key to mitigating third-party risk. Vendor due diligence allows risk management and compliance teams to make informed decisions about who your organization does business with and protect it against potential liabilities, such as exposure to corruption laws or reputational impacts.
Performing vendor due diligence around third-party relationships has become increasingly important. As your business increases its reliance on third parties, it’s critical that these vendors are vetted thoroughly for cyber risk.
What is vendor due diligence in cyber security?
During the third-party onboarding process, it is a security professional’s job to evaluate a potential vendor’s security policies and practices.
Typically, this screening process might follow a pre-agreed “new vendor due diligence” checklist or assessment. However, this can introduce frustrating delays or procedural roadblocks into the onboarding process. Security risk assessments (which may include risk assessment questionnaires, penetration testing, and even site visits) are time-consuming and hard to scale across the dozens if not hundreds of vendors that your organization works with. According to Gartner, 60% of organizations work with more than 1,000 third parties.
This type of vendor due diligence in cyber security is often a one-and-done process that can expose your organization to vulnerabilities. That’s because point-in-time assessments fail to account for evolving risk and changes in your vendors’ cybersecurity postures, leaving you open to possible cyberattacks.
How can you adapt your processes to streamline vendor due diligence in cyber security? Let’s look at four best practices.
4 best practices for vendor due diligence in cyber security
1. Tier vendors by criticality
One way to save time during vendor onboarding due diligence is by grouping or tiering your vendors based on how critical they are to your organization. For example, a company that provides an important service or has access to your sensitive data would be a higher priority than a company that does not have immediate access to proprietary information or performs a mission-critical function.
Instead of adopting a one-size-fits-all approach to the evaluation process, tiering helps you determine whether a vendor needs a more in-depth assessment – such as a site visit -- or requires fewer touchpoints.
Tiering requires consultation with your legal, finance, and compliance teams, but you can fast track the process using Bitsight’s tier recommender service. The service uses tiering best practices and provides a suggested tier for each vendor – saving more time and effort on your part.