Agencies have typically treated vendor relationships as financial ones, with contract review focused on cost, not cybersecurity. But as third-party applications take on essential functions, data becomes the concern: payroll contractors handle employee data; document-sharing platforms hold confidential files. Each supplier relationship expands the potential attack surface, and agencies often manage hundreds, or even thousands, of them.
Annual vendor security questionnaires aren’t enough to control the risk. Agencies need continuous, automated and scalable third-party risk monitoring to keep pace with the threat environment, tracking changes in vendor vulnerabilities and helping stretched IT teams manage a growing number of suppliers without adding headcount.
It’s not an issue agencies can afford to ignore. “More and more data breaches are the result of data held by third parties,” said Greg Pollock, Director of Research and Insights at UpGuard. “All of those third-party relationships are now also an information security problem. And, in fact, this problem has become so acute that in the last year, 48% of data breaches involved a third party in one way or another.”
In this video interview, Pollock explains how agencies can get a handle on their third-party risk and secure their data when it’s in external hands.
Topics include:
- How procurement and cybersecurity can work together to vet suppliers
- Simple steps agencies can take to begin controlling third-party risk
- Why continuous monitoring solves problems of changing risk and scale
