---
title: The challenges of third-party risk management
description: The challenges of third-party risk management
---

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/head-logo-2.svg "TowerWall")](https://towerwall.com/)

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/towerwall-logo-white-test.svg "TowerWall")](https://towerwall.com/)

- [Our Partners](https://towerwall.com/how-we-protect-you/our-technology-partners/)
- Our Solutions 
    - - Our Cybersecurity Solutions 
                  - We operationalize infosec,  
                     building security solutions that  
                     safeguard your most critical assets.
          - - [Solutions Overview](https://towerwall.com/cybersecurity-solutions/)
                  - [Risk Assessments & Security Reviews](https://towerwall.com/cybersecurity-solutions/risk-assessments-security-reviews/)
                  - [Program & Policy Development](https://towerwall.com/cybersecurity-solutions/program-policy-development/)
                  - [Incident Response & Remediation](https://towerwall.com/cybersecurity-solutions/incident-response-remediation/)
                  - [Managed Detection & Response](https://towerwall.com/cybersecurity-solutions/managed-detection-response/)
          - - [Compliance & Privacy](https://towerwall.com/cybersecurity-solutions/compliance-privacy/)
                  - [Comprehensive Security Training](https://towerwall.com/cybersecurity-solutions/comprehensive-security-training/)
                  - [Vulnerability Protection](https://towerwall.com/cybersecurity-solutions/vulnerability-protection/)
                  - [Penetration Testing](https://towerwall.com/cybersecurity-solutions/penetration-testing/)
- Virtual Security Officers 
    - - Virtual Security Officer 
                  - Leverage the experience and  
                     security acumen of Towerwall’s  
                     on-demand security experts.
          - - [Virtual Chief Information Security Officer (VCISO)](https://towerwall.com/virtual-security-officers/virtual-chief-information-security-officer-vciso/)
                  - [Virtual Data Protection Officer (vDPO)](https://towerwall.com/virtual-security-officers/virtual-data-protection-officer-vdpo/)
                  - [Virtual Chief Privacy Officer (vCPO)](https://towerwall.com/virtual-security-officers/virtual-chief-privacy-officer-vcpo/)
- We Advise 
    - - We Advise 
                  - One-size security solutions only  
                     lead to failure.
          - Industries 
                  - [Higher Education](https://towerwall.com/industries/higher-education/)
                  - [Financial Services & Banking](https://towerwall.com/industries/financial-services-banking/)
                  - [Healthcare](https://towerwall.com/industries/healthcare/)
                  - [BioPharma & Bio-Therapeutics](https://towerwall.com/industries/biopharma-bio-therapeutics/)
                  - [Retail](https://towerwall.com/industries/retail/)
                  - [Government](https://towerwall.com/industries/government/)
                  - [Catholic Diocese](https://towerwall.com/industries/catholic-diocese-cybersecurity/)
                  - [Cannabis](https://towerwall.com/industries/cannabis/)
                  - [Small Business](https://towerwall.com/industries/small-business/)
                  - [Enterprise](https://towerwall.com/industries/enterprise/)
          - Trends & Threats 
                  - [Remote Workforce](https://towerwall.com/trends-threats/remote-workforce/)
                  - [Vendor Questionnaire](https://towerwall.com/trends-threats/vendor-questionnaire/)
                  - [HIPAA](https://towerwall.com/trends-threats/hipaa/)
                  - [Ransomware](https://towerwall.com/trends-threats/ransomware/)
                  - [GDPR](https://towerwall.com/trends-threats/gdpr/)
                  - [Cloud Security](https://towerwall.com/trends-threats/cloud-security/)
                  - [Phishing](https://towerwall.com/trends-threats/phishing/)
                  - [Cybersecurity Insurance](https://towerwall.com/trends-threats/cybersecurity-insurance/)
- [Resources](https://towerwall.com/resources/) 
    - - Resources 
                  - Our latest insights, events,  
                     and tools to keep you safe.
          - - [Insights](https://towerwall.com/resources/?resources_category=MTU%3D&focusarea=0&industries=0&search=)
                  - [Webinars](https://towerwall.com/resources/?resources_category=MTg%3D&focusarea=0&industries=0&search=)
                  - [Whitepapers](https://towerwall.com/resources/?resources_category=MTY%3D&focusarea=0&industries=0&search=)
                  - [View All](https://towerwall.com/resources/)
- [Company](https://towerwall.com/company/) 
    - - Our Company 
                  - We are the industry’s leading cybersecurity preparedness partner.
          - - [Who We Are](https://towerwall.com/company/)
                  - [Our Team](https://towerwall.com/company/our-team/)
                  - [Our Approach](https://towerwall.com/our-approach/)
                  - [Our Values](https://towerwall.com/company/our-values/)
          - - [Awards & Recognition](https://towerwall.com/company/awards-recognition/)
                  - [Certifications & Affiliations](https://towerwall.com/company/certifications-affiliations/)
                  - [Community Involvement](https://towerwall.com/company/community-involvement/)
                  - [Careers](https://towerwall.com/company/careers/)
                  - [Contact Us](https://towerwall.com/company/contact-us/)

Topics  Compliance & Privacy, Enterprise

# The challenges of third-party risk management

[By Michelle Drolet](https://blog.towerwall.com/author/towerwall2020)

[Read More](https://blog.towerwall.com/author/towerwall2020)

 3 Minute Read

November 17, 2015

## Vendors and other third parties should be treated with the same level of intense scrutiny as your own in-house risk compliance mandates.

How seriously is your company treating the risk of a data breach? Have you done due diligence on all of your vendors and third-party partners? Cyberattacks can have a devastating impact in terms of reputation and customer trust. It takes time and resources to deal with the fall out. The true cost of a serious data breach is hard to calculate.

According to Verizon's [2015 Data Breach Investigations Report](https://blog.towerwall.com/Users/vcruz_000/AppData/Local/Microsoft/Windows/INetCache/Content.Outlook/79OH6MF9/the%20end%20of%20casual%20relationships), the estimated financial loss for 70 organizations in various industries around the world from 700 million compromised records was $400 million. No business can afford to ignore a threat like this.

### Redirecting resources

There's plenty of evidence that the enterprise takes the threat seriously. [Gartner](http://www.gartner.com/newsroom/id/2828722)estimates that global information security spending will hit $76.9 million this year, up 8.2% on 2014. But are companies spending that money in the right places? No matter how much internal systems are tightened and improved, companies can still be exposed by third-party vendors.  
 It's not enough to ensure that your own house is in order, you have to assess every business relationship. After all, a chain is only as strong as its weakest link, and cybercriminals are adept at finding weak spots. The superintendent of the New York State Department of Financial Services, Benjamin M. Lawsky, summed it up nicely in his[February speech](http://www.dfs.ny.gov/about/speeches_testimony/sp150225.htm):

> "In many ways, a company's cyber security is only as strong as the cyber security of its third-party vendors."

 

### Learning from the OCC

For many industries, third-party risk management is not optional. Regulators in the U.S. and Europe are starting to bring more pressure to bear. For example, the Office of the Comptroller of the Currency (OCC) extended regulatory responsibility to senior management in financial institutions with Bulletin 2013-29.  
 You don't have to be in the finance industry to learn from the main issues it highlighted:

- Failure to properly assess, understand, and document the risk and cost of outsourcing services.
- Failure to perform proper due diligence and ongoing monitoring.
- Entering into contracts without a proper assessment of the third-party's risk controls.
- Entering into contracts that could incentivize a third party to take risks in order to maximize profit, even if those risks could be detrimental to the bank or its customers.
- Engaging in third-party relationships without a formal contract, or with inadequate contracts.

These issues should resonate with any industry, not just financial services. We've seen data breaches in healthcare, hospitality, retail, entertainment, manufacturing, technology, and the list goes on. We find the same root causes every time – a failure to identify and manage third-party risk.

### Tackling third-party risk management

There are lots of different ways you might begin to identify and address risks associated with vendors. Firstly, it's important to plan properly. There's no one-size-fits-all answer for third-party risk management, but you should always be asking certain questions:

- Why are these services being outsourced in the first place?
- Is there any possibility the third-party will subcontract?
- Do they have data centers based overseas?
- What data is being shared?
- What is the plan in the event of a third-party failure or breach?
- How often are vendors assessed?

The planning phase should produce solid documentation, including a comprehensive due diligence report, a map of third-party relationships, risk assessments, performance reports, audits, and reviews. There's no room for trust. If you don't ensure compliance with service-level agreements, for example, then you could be exposing your company, not just to the risk of data breach, but also to legal liability.

### Re-imagining vendor assessments

We need a fresh approach to vendor assessment and an understanding that issues must be addressed in a timely manner. Remediation efforts need to be audited, and there must be room for companies to terminate when third parties cannot or will not comply. There are two major failings with traditional vendor assessments:

- **Rating system**: Reports can produce an arbitrary score or ranking. All too often that ranking doesn't take the bigger picture into account. The risk isn't just about the systems that any given vendor has in place, it's about the nature of the relationship your business has with that vendor. What is your potential exposure in the event of an incident?
- **Regular reviews**: an annual snapshot of your vendor's security is rarely enough to provide peace of mind. Where serious risks are identified, it may be necessary to institute real-time, continuous monitoring. There also needs to be follow up to confirm that action is being taken to tighten security when required.

In the modern climate, with cyber security growing in importance, there's simply no room for casual business relationships based on blind trust. It's time to take third-party risk management seriously and work out a solution that delivers the oversight your business really needs.

This article was recently published in [Network World.](http://www.networkworld.com/article/3005320/application-security/the-challenges-of-third-party-risk-management.html)  
*Imagery credit Thinkstock.*

#### The challenges of third-party risk management

Back to Top

## Related Insights

### [Bugs for cash: Bounty hunters in the new wild west of security](https://blog.towerwall.com/bugs-cash-bounty-hunters-new-wild-west-security)

 Compliance & Privacy, Enterprise

### [Positive signs for the future of cybersecurity](https://blog.towerwall.com/positive-signs-for-the-future-of-cybersecurity)

 Compliance & Privacy, Enterprise

[View All Insights](https://blog.towerwall.com)

×

## Talk with us now about:

#### Your security needs.

- ![Phone](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/phone-icon.svg "Phone")
  
  [Call 774.204.0700](tel:774.204.0700)
- ![Mail](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/mail-icon.svg "Mail")
  
  [Email Us](mailto:info@towerwall.com)

### The front line of cybersecurity.™

For over 23 years, Towerwall, a woman-owned business, has helped scores of companies safeguard their data and leverage their investment in IT with advanced information security technology solutions and services. Our experience in all facets of information security coupled with serving in the CIO/CISO/ISO roles provides a unique first-hand understanding of the security challenges organizations face daily.

### Connect

- <https://blog.towerwall.com/info@towerwall.com>
- <https://www.linkedin.com/company/towerwall-inc.?trk=pro_other_cmpy>
- <https://twitter.com/Towerwall>
- <https://www.facebook.com/Towerwall>

- [Career Opportunities](https://towerwall.com/company/careers/)
- [Contact Us](https://towerwall.com/company/contact-us/)

© Towerwall, Inc. and its licensees. All rights reserved [Privacy Policy](http://towerwall.com/privacy-policy/) Sitemap [Created by Howbridge](https://meethowbridge.com/)

[![Towerwall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/footer-logo.svg "Towerwall")](https://towerwall.com/)