{"id":2786,"date":"2024-03-25T09:00:00","date_gmt":"2024-03-25T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/mitigating-third-party-risk-requires-collaborative-approach"},"modified":"2024-03-25T09:00:00","modified_gmt":"2024-03-25T14:00:00","slug":"mitigating-third-party-risk-requires-a-collaborative-thorough-approach","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/25\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach\/","title":{"rendered":"Mitigating Third-Party Risk Requires a Collaborative, Thorough Approach"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt02af12e853149294\/66017f58413e8e040ace6378\/Collaboration_Andriy_Popov_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mitigating third-party risk may seem daunting when considering the slew of incoming regulations coupled with the increasingly advanced tactics of cybercriminals. However, most organizations have more agency and flexibility than they think they do. Third-party risk management can be built on top of existing risk governance practices and security controls that are currently implemented at the company. What&#8217;s reassuring about this model is that it means organizations do not have to fully scrap their existing protection to successfully mitigate third-party risk \u2014 and this encourages a culture of gradual, continuous improvement.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Third-party risk presents a unique challenge to organizations. On the surface, a third party can appear trustworthy. But without complete transparency into the inner workings of that third-party vendor, how can an organization ensure that data entrusted to them is secure?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Often, organizations downplay this pressing question, due to the longstanding relationships they have with their third-party vendors. Because they&#8217;ve worked with a third-party vendor for 15 years, they&#8217;ll see no reason to jeopardize their relationship by asking to &#8220;look under the hood.&#8221; However, this line of thinking is dangerous \u2014 a cyber incident can strike when or where it&#8217;s least expected.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Changing Landscape\">A Changing Landscape<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When a data breach strikes, not only can the organization be fined as an entity, but personal consequences may be issued as well. Last year,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.natlawreview.com\/article\/interagency-guidance-bank-risk-management-third-party-relationships\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the FDIC tightened its guidelines on third-party risk<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, setting the stage for other industries to follow suit. With the emergence of new technologies such as artificial intelligence, the outcomes of mismanaging data by a third party can be dire. Incoming regulations will reflect these serious consequences by issuing harsh penalties to those who haven&#8217;t developed strong controls.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides new regulations, the emergence of fourth- and even fifth-party vendors should incentivize organizations to secure their external data. Software isn&#8217;t the simple, internal practice it was 10 years ago \u2014 today, data passes through many hands, and with each added link to the data chain, security threats increase while oversight becomes more difficult. For example, doing proper due diligence on a third-party vendor is of little benefit if the vetted third party outsources private client data to a negligent fourth party and the organization is unaware of it.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Five Simple Out-of-the-Box Steps\">Five Simple Out-of-the-Box Steps<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With the right roadmap, organizations&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/it-s-time-to-rethink-third-party-risk-assessment-\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">can successfully mitigate third-party risk<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Better still, costly and disruptive tech investments aren&#8217;t always necessary. To start with, what organizations need when performing due diligence is a sensible plan, capable personnel willing to buy in, and heightened communication between the IT, security, and business teams.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first step is to thoroughly understand the vendor landscape. While this may seem obvious, many organizations, especially large companies with budgets to outsource, neglect this crucial step. While hastily establishing a third-party vendor relationship may save money in the short-term, all those savings will be erased if a data breach occurs and the organization faces hefty fines.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After researching the vendor landscape, organizations should determine which third-party roles are &#8220;critical&#8221; \u2014 these roles may be operationally critical or process sensitive data. Based on criticality, vendors should be grouped by tiers, which allows for flexibility in how the organization assesses, reviews, and manages the vendor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sorting vendors by their criticality can shed light on the overreliance organizations might have on their third-party vendors. These organizations must ask themselves: If this relationship were to suddenly cease, do we have a backup plan? How would we replace this function while seamlessly continuing day-to-day operations?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The third step is to develop a plan for governance. There must be synergy between the three main arms of an organization to effectively perform due diligence and manage risk\u2014the security team shines a light on holes in the vendor&#8217;s security program, the legal team determines legal risk, and the business team predicts the negative cascading effect on operations if data or operations is compromised. The key to creating solid governance is to tailor the plan to suit an organization&#8217;s unique needs. This is especially applicable to organizations in less regulated industries.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The governance step incorporates the drafting of contractual obligations. For instance, often in cloud computing, business leaders will mistakenly rush into signing a contract without understanding that certain security measures may or may not be included in the baseline package. Contractual obligations are often industry dependent, but a standardize security clause should be developed as well. For example, if we are evaluating a delivery company, there may be less focus on a vendor&#8217;s software development lifecycle (SDLC) process and more about their resiliency measures. However, if we&#8217;re evaluating a software company, we will want to focus on the vendor&#8217;s SDLC&#8217;s processes, such as how code is reviewed and what the safeguards to push to production looks like.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally, organizations need to develop an exit strategy. How does an organization cleanly separate from a third party while ensuring that their client data is scrubbed? There have been cases where a company severs ties with a vendor only to receive a call years later informing them that their former partner suffered a data compromise and that their client data was exposed \u2014 despite being under the assumption that this data was erased. Moral of the story: Do not assume. Besides an accidental data breach, there&#8217;s also the possibility that third-party vendors will use a former partner&#8217;s data for internal development, such as using that data to build machine learning models. Organizations must prevent this by stating in clear, specific, and legally binding terms how vendors will erase data in the event of the partnership ending, and what the consequences will be if they don&#8217;t.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Create a Culture of Shared Responsibility and Continuous Improvement&nbsp;\">Create a Culture of Shared Responsibility and Continuous Improvement&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Taking a team approach to performing due diligence means the chief information security oficer (CISO) doesn&#8217;t have to fully shoulder the responsibility of de-risking a third-party vendor. The&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.sec.gov\/news\/press-release\/2023-227\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">SEC&#8217;s charges against SolarWinds<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> set a concerning precedent \u2014 a CISO can take the fall, even if the problem stems from organizationwide dysfunction. If the IT and business teams support the CISO in vetting third-party vendors, it sets the stage for future cross-team collaborations, boosts the organization&#8217;s buy in, and produces better results when it comes to security.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/mitigating-third-party-risk-requires-collaborative-approach\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Mitigating third-party risk may seem daunting when considering the<\/p>\n","protected":false},"author":12,"featured_media":2787,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2786","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=1816%2C1070&ssl=1",1816,1070,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=300%2C177&ssl=1",300,177,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=640%2C378&ssl=1",640,378,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=640%2C377&ssl=1",640,377,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=1536%2C905&ssl=1",1536,905,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=1816%2C1070&ssl=1",1816,1070,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=1024%2C603&ssl=1",1024,603,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/mitigating-third-party-risk-requires-a-collaborative-thorough-approach.jpg?fit=1816%2C1070&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2786","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2786"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2786\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2787"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}