Vendor Due Diligence and Cybersecurity Planning
Performing vendor due diligence is a critical part of cybersecurity planning. As you consider bringing on new partners, suppliers, or third-party vendors, it’s essential to address the inherent risks to which they may expose your network. Cyber risk must be a key area of vendor due diligence, since vendors increasingly have access to corporate networks and sensitive data.
As the average number of vendors continues to grow for most businesses, the time and cost of effective due diligence can easily overwhelm vendor risk management teams. According to Gartner, 60% of organizations now work with more than 1,000 third-party vendors, including partners, sub-contractors, and suppliers1. To keep up with the cybersecurity planning needs of the organization, third-party risk managers need solutions that automate processes to reduce risk across their third-party networks while accelerating proper due diligence.
Bitsight can help. Bitsight for Third-Party Risk Management provides continually updated security ratings based on publicly available cybersecurity data. These cybersecurity ratings simplify due diligence and reduce the time and cost required to assess and onboard new vendors. With Bitsight, you can simplify cybersecurity planning with solutions that help to focus resources, enable more informed decision-making, and reduce risk across your vendor portfolio.
A Vendor Due Diligence Checklist
As you work to onboard third parties, this checklist of information can help to make the most complete and thorough evaluation of the risk each vendor represents.
- Basic company information. This information is designed to ensure the company is legitimate and licensed to do business in your area. You’ll want to collect articles of incorporation, business licenses, and proof of location such as photographs or an on-site visit. Depending on the vendor’s proposed relationship to your network data, you’ll also want an overview of the company structure, bios of executives and board members, and references from credible sources.
- Financial information. Because you want to work with vendors who can provide value over time, you want to make sure each company is financially solvent and keeping up with financial requirements. Helpful information here includes tax documents, balance sheets, as well as details of loans and liabilities, major assets, and compensation structure.
- Political and reputational risk. When vendors run into political or reputational troubles, their scandals can quickly become your scandals. Vendors with access to sensitive company information or systems will need special scrutiny. Be sure to check the organization against key watch lists and global sanctions lists, and to check key personnel against lists of politically exposed persons and law enforcement lists. Identify the vendor’s risk-related internal policies and procedures, and review litigation history of the company.
- Cyber risk. Because data breaches that originate with third parties are increasingly common and expensive, assessing third-party cyber risk is paramount. Bitsight Security Ratings provide an objective view of a vendor’s risk and can verify the data presented in traditional cyber risk assessment questionnaires. To identify cyber risk, you may also run penetration tests and security awareness tests, review cybersecurity reports on history of data breaches, and traditionally perform a site visit to assess physical cybersecurity. A Bitsight Discover map can help to manage risk by continuously monitoring business connections to identify areas of concentrated cyber risk.
- Operational risk. Any operational risks within a third-party organization could negatively affect your own company. It’s helpful to review a vendor’s business continuity plan and disaster preparedness plan. You may also want to review employee turnover rates, lawsuits, and other indicators of toxic culture.
As you are performing the tasks in this checklist, Bitsight for Third-Party Risk Management can provide external key insights and metrics that make due diligence and cybersecurity planning faster, more cost-efficient, and more accurate.
1https://www.gartner.com/smarterwithgartner/a-better-way-to-manage-third-party-risk/