Managing third-party risk in cybersecurity often appears straightforward on paper: assess vendors, identify risks, report weaknesses, and transfer liabilities through contracts. However, translating this theoretical framework into practice reveals significant challenges.
Having worked extensively as a CISO, I’ve observed how teams typically occupy a pivotal, yet precarious position. They serve as the compliance and cybersecurity authority between end-user purchasers and their desired vendors, often seen as hindrances to business objectives. This perception creates pressure, particularly when security is involved late in the decision-making process.
Late Security Involvement: A Recipe for Friction
Frequently, business teams decide on a tool's necessity based on operational efficiency and financial backing, only to pause when cybersecurity considerations surface. When this moment arises, security is tasked with answering critical questions that should have been addressed much earlier: What data will the vendor access? Where will that data be stored? What existing protections are in place—and what additional ones are required? Does the vendor's security practice align with the organization's risk tolerance?
Holding the brakes at the last minute is an unenviable position for security teams. Yet, this scenario occurs repeatedly when there’s no formal process for intake and evaluation. Clients often approach vendors with excitement only to find the approval process drags on for weeks, dominated by endless rounds of documentation requests, compliance verification, and discussions laden with legal jargon. In organizations where mature processes aren't established, this can lead to painful delays that frustrate all parties. Business teams encounter bottlenecks, vendors encounter hurdles, and security teams grapple with unresolved risks.
To avoid this friction, it's essential to partner with legal and finance teams early. Engaging them right at the outset ensures that security assessments occur before any contracts are inked. From my experience, once a contract is signed, the ability to influence vendor actions diminishes significantly. Constructing assessments that are embedded within contract language helps address any weaknesses effectively and secures expected outcomes.
Creating a Consistent Review Framework
At its core, the goal is to build a structured vendor evaluation process that’s both repeatable and defensible, aligning tightly with business operations. This goes beyond simple product reviews; we aim to interpret security standards, compliance mandates, and operational necessities into a coherent framework for deployment decisions.
Many organizations lack the bandwidth to thoroughly probe solution providers on vital aspects such as technical controls or shared responsibilities. Acting as an intermediary, we undertake this essential legwork, asking the critical questions and helping interpret the responses. A polished sales pitch, while appealing, doesn’t equate to genuine assurance of compliance or security.
Clearly defined timelines for assessments are crucial. Purchasers must understand where a review stands—whether it's with their internal team or the vendor. Organizations typically prioritize action from internal budget holders, who often view security teams as obstacles rather than allies in making sales happen.
When executed effectively, third-party risk management can expedite client projects while minimizing unforeseen challenges and risks.
Integrating Business Value Beyond Security
Today, employees operating with budgets expect to onboard new technologies rapidly, but this rush can breed significant issues, the most prevalent being an ineffective solution to the underlying business problem. I've witnessed purchasers becoming enamored with aesthetics, specific functionalities, or even the salesperson, often neglecting to clearly define what problems they seek to solve beforehand.
Ideally, both business objectives and success criteria should be established prior to any purchase. Security factors can be included as part of these criteria, assuming the vendor can meet a predetermined security threshold.
This Is Where AI Complicates Matters
AI is influencing third-party risk in two concurrent ways. First, vendors are incorporating AI into their solutions at an accelerated pace. Concurrently, employees are introducing AI tools into the workplace without IT oversight, typically without informing security or compliance teams. This trend only exacerbates the longstanding issue of security teams being the last to know about significant changes.
The rapid adoption of AI tools raises alarm not only because of their novelty but also because users can quickly enter sensitive business information into unverified systems, risking privacy and retention compliance. This further underscores the necessity for proactive vendor governance. Without a structured intake process for assessing new tools, organizations often find themselves reacting rather than anticipating challenges.
Companies need to recalibrate their approach to third-party risk management. It's not merely a task relegated to procurement or security but an enterprise-wide process. Effective organizations establish workflows for onboarding vendors, promptly identify data exposure, allocate review responsibilities, and recognize exceptions before contracts are finalized.
Delayed responses lead to reliance on heroics. A late discovery of risk often triggers frantic efforts to gather documents across time zones while trying to assess the situation with minimal information. It's a tactic that might succeed occasionally, but it's unsustainable over time.
The solution is straightforward: enhance processes before the urgency arises. Know who is responsible for vendor intake. Clarify when security should engage. Determine what documentation is needed. Understand how AI applications will be evaluated before they infiltrate operational workflows.
Striking a balance between compliance, real-world operational needs, and the pace of technological advances empowers organizations to make well-informed decisions regarding the vendors they choose to rely on.
Crucially, while some vendors excel at securing data, others may overlook fundamental security practices. A well-structured process is necessary to differentiate between these types of vendors and hold them accountable for associated risks.
Another often overlooked aspect of a robust third-party risk program entails leveraging contracts to enforce vendor accountability. Programs lacking this critical component frequently fail to deliver the anticipated results as they lack enforceable requirements.
Ultimately, third-party risk management shouldn't focus on eliminating friction altogether but rather on redirecting it to where it can have a meaningful impact, organized around a framework that allows for effective management.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?