Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Cybersecurity NewsTransportation/Logistics/Supply Chain/Distribution/ Warehousing

6 Best Practices that Reduce Third-Party Cybersecurity Risk

By Steve Earley
digital-cyber
October 5, 2017

Cybersecurity threats are increasingly sophisticated and targeted. Hackers who want your information or want to disrupt your operations are looking for any way into your network. In an interconnected world, these hackers are increasingly looking to an organization’s supply chain partners, especially those with network access but without effective cybersecurity protection.

 

Third-party risk management (TPRM) platforms are emerging to guard against attacks that originate in an organization’s supply chain.  Ideally, these help an organization map its attack surface, and monitor changes to the companies that are part of that attack surface, with the result being risk insights that let security management anticipate problems and work with its vendors to remediate these risks.

 

Getting started with TPRM requires an organization to do a self-analysis that will form the foundation for its program. The following best practices can be used to set a foundation for successful TPRM:

 

Develop a list of high-impact vendors. You may interact with a large number of vendors, so the first step in TPRM is to consider which vendors would be of highest-impact to your organization if a breach occurred. When determining your high-impact vendors, consider the level of sensitivity and volume of data that a vendor is handling. It is important to also consider the type of data a vendor is handling, such as personally identifiable data (PII), cardholder data (related to PCI) or protected health information (PHI, related to HIPAA). Finally consider the transactions being handled – those involved in bill payment, payment processing or high-dollar transactions can be particularly impactful.

 

Identify assets exposed to vendors and vendor assets that store your data. Next, by scanning or spidering against a vendor’s domain, you can determine a great deal of information such as what services are running or which ports are open on firewalls. This scan, combined with human intelligence, can tell a lot about a vendor. You should also ask high-impact vendors for a data flow diagram to understand where your data is going and whether there’s a fourth party you may need to be concerned with, such as a backup storage vendor. In this step, you’re not just looking at the vendor, you’re looking at the vendor’s vendors as well.

 

Manage the relationship with your vendors. When working with a vendor, you need to be able to understand and monitor their cyber hygiene. Consider what you are doing to ensure your data is not commingling with other companies’ data. And then you need to ensure the risk of the data stored is in alignment with the content terms that you’ve put in place with the vendor.

 

Refine the vendor list for ongoing monitoring. It’s not enough to assess a vendor just once, but it’s also not realistic to assess all vendors all of the time. After your analysis of which vendors are of highest priority, make a plan for ongoing (continuous) assessment of these vendors to ensure your data remains safe.

 

Develop initial “threat scenarios.” Even with ongoing assessment, threats will still loom. Organizations with a more advanced TPRM program can “visualize” or map out what the impact would be of a particular risk. The threat scenario maps out how a hacker would pivot through your network in order to get to your most important data. This step requires both technology for scanning and human intelligence for analysis.

 

Ongoing risk mitigation. Understanding that attackers may still get through, how will you prepare for risk mitigation?

  • Assessment – Depending on the impact of a particular vendor to your business, you may want to do deeper assessment every year and may want to go onsite for the assessment.
  • Scanning – Continuously monitor your high-impact vendors, looking for trends and threat scenarios or changes in their security posture.
  • Verify critical assets – What data could be exposed via the targeted third parties? What is the security on that data?
  • Verify controls – What does the vendor control today? You may use a “trust but verify” model, and this should be done periodically.
  • Contract review – Evaluate contracts with these vendors to ensure that data security issues and expectations are formalized.

 

Any risk you can’t mitigate, you want to be able to manage. By using these TPRM best practices, your company and its data will be in the best possible position in the event that an attack occurs.

KEYWORDS: cyber risk mitigation security risk management supply chain management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Steve Earley, Director, Third Party Risk

Fortress Information Security

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

2026 Women in Security

Security’s 2026 Women in Security

Denise Platon. Image courtesy of Platon

Denise Platon — Women in Security 2026

Women in Security: Julia Stuyt

Julia Stuyt — Women in Security 2026

Glowing AI square

Security Experts Discuss the Hugging Face, OpenAI Incident

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • security

    6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

    See More
  • code

    6 best practices for cybersecurity programs

    See More
  • phishing

    4 Steps to Mitigating Third-Party Vendor Cybersecurity Threats

    See More

Related Products

See More Products
  • 9780367339456.jpg.jpg.jpg

    Cyber Strategy: Risk-Driven Security and Resiliency

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

See More Products

Events

View AllSubmit An Event
  • February 26, 2026

    Zero Incidents vs. Zero Tolerance – Workplace Violence Prevention Best Practices that Work

    ON DEMAND: Workplace violence remains one of the most complex challenges facing healthcare organizations today. Explore the real drivers of violence in healthcare and how proactive communication, de-escalation, access control, and documentation can reduce risk.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing