Tips and Techniques for Managing Vendor or Supply Chain Cybersecurity Risk

Posted on Feb 13, 2018

Ensuring everything is in place to protect cyber assets from those that wish to harm is a daunting task, even for the most seasoned cybersecurity team. The list of security controls that could be in implemented, or even more important should be in place, is extremely long. There are multiple cybersecurity frameworks and industry regulations that an organization can look to for guidance, but unfortunately, the documented security controls are often vague and lack clarity on where to begin. Some security frameworks are better than others in the quality of the documentation. Complicating matters for many businesses is that the IT footprint that should be secured is expanding nearly every day because of the rapid growth of outsourcing business functions to third-party companies (which in turn often outsource to other 3rd party companies, etc.). This article provides a few tips and techniques for managing cybersecurity risks in the supply chain or vendor network.

Significant Growth of Outsourced IT Poses Increased Risk

The Software as a Service (SaaS) model has seen a dramatic rise which has introduced new cybersecurity challenges for businesses. Gartner predicted that the worldwide public cloud services market would grow 18% between 2016 and 2017. Many businesses have already outsourced critical business services including human resources, billing, finance, customer relationship management (CRM), enterprise resource planning (ERP), among others. Although the use of these services may be convenient to businesses, they introduce complexity in how to manage cybersecurity risks on networks not owned by the business. Business executives now need to look at how to best drive programs that ensure proper protection of the company’s online data by their ecosystem of vendors or in their supply chain.

Lack of Experienced Cybersecurity Staff Poses Increased Business Risk

The depth and breadth of information security controls required by a business often require a significant team of qualified cybersecurity staff. Unfortunately, the supply of qualified people has not kept up with demand. A recent study by the Center for Strategic and International Studies and Intel Security reported: “82 percent [of the respondents] said they’re unable to fill open jobs with adequately trained and experienced [cybersecurity] people.” And reported further that “71 percent said the [cyber talent] shortage was already causing direct and measurable damage to their organizations.” The challenge of not being able to find enough qualified cybersecurity staff, joined with the complexities of influencing cybersecurity programs of third party partner companies can make a vendor risk managers job quite complex. Building an effective cybersecurity risk management program requires a commitment to the organization to ensure needed investment is made to implement appropriate security measures including legal contracts, cybersecurity assessment tools, partner collaboration, and training initiatives.   

Leverage Automated and Intelligent Solutions

Managing one’s cybersecurity posture is hard enough. Ensuring that effective security measures are in place across an ecosystem of vendor or supply chains was near impossible until the recent emergence of automated and intelligent cybersecurity VRM solutions.  

SecurityScorecard  helps businesses understand vendor or supply chain cybersecurity risk across ten important risk factor areas. The solution helps businesses understand which companies from their ecosystem of vendor or supply chain pose the most risk via a common and consistent cybersecurity rating system. When used in collaboration with vendor or supply chains, organizations can quickly close the gap on the potential cybersecurity risk a vendor might pose.

To learn more, claim your scorecard today.


Security Research in your Inbox

Thanks for siging up for the newsletter!

No waiting, 100% Free

Get your personalized scorecard today

Get your free scorecard and learn how you stack up across 10 risk categories. Answer a few simple questions and we'll instantly send your score to your business email.

Get Your Free Score

Get In Touch

Thank you for contacting us!

Request a Demo

Thank you for requesting a demo!