Cybersec Tips

Third-Party Risk Management: How to Assess Your Vendors and Help Protect Your Business

  • saraSara Velásquez in Dec 4, 2025Growth Lead
Third-Party Risk Management: How to Assess Your Vendors and Help Protect Your Business

Third-party risk management (TPRM) has become a critical function in today’s business environment. It is no longer an IT-only concern—it is now a central business issue, especially across the supply chain. According to the Verizon Data Breach Investigations Report 2024, more than 30% of data breaches are attributable to third parties, highlighting the need for rigorous, ongoing vendor assessments.

The average cost of a breach, according to the IBM Cost of a Data Breach Report 2024, exceeds USD $4.35 million—excluding loss of trust, legal exposure, and reputational impact.

Today, most incidents no longer originate from a compromised firewall—they come from a vendor with weak controls, an unknown subcontractor in the chain, or a SaaS application that was never evaluated. Signing an NDA and a security appendix is no longer enough to ensure protection. TPRM is now a requirement for true business resilience.

To date, third-party risk has surged due to four key factors:

1. Rising supply chain attacks

Cyber attackers increasingly target vendors as “backdoors” into larger organizations. ENISA reported that 53% of supply chain attacks in 2024 exploited software or service providers.

2. Massive reliance on the digital ecosystem

Core SaaS platforms, MSP/MSSPs, consulting firms, payment platforms, logistics providers, remote support, OT integrators, etc. Many companies now depend more on their ecosystem than on their internal systems.

3. New global standards and regulations

Regulatory and market pressure has increased significantly.
Examples include:

  • NIST Cybersecurity Framework (CSF) 2.0, which emphasizes governance and supply chain security

  • NIST SP 800-161, now a key reference for cybersecurity supply chain risk management

  • ISO/IEC 27036, which provides guidelines on how to manage supplier relationships

Regulations such as NIS2 and DORA, while European, set expectations that influence multinational operations worldwide. This affects not only IT but also Procurement and Supply Management, which must adapt to these new requirements.

4. Procurement becomes central to the risk model

Procurement teams no longer just “purchase services”—they are directly involved in managing risk. Today, security heavily depends on:

  • how vendors are classified,

  • what is required in RFPs,

  • how risks are documented,

  • which controls are mandated before signing.

Key recommendations to assess vendors securely

1. Vendor classification by criticality

Key factors to evaluate per vendor:

  • access to sensitive data

  • impact on core operations

  • connectivity to internal networks or OT/ICS environments

  • dependency level or single points of failure

This helps differentiate an OT support provider, a financial SaaS platform, and a catering service.

2. Minimum security requirements per category

For critical vendors:

  • vulnerability management

  • encryption at rest and in transit

  • strong MFA and IAM

  • backups + continuity

  • monitoring and logging

  • documented security programs

For non-critical vendors: lighter but proportional controls.

3. Essential contractual clauses

Depending on vendor type and risk level, we recommend including:

  • incident notification requirements

  • encryption and data protection obligations

  • clearly defined shared responsibilities

  • compliance with applicable frameworks (NIST, ISO, regulatory)

4. Continuous monitoring

Continuous oversight is essential. Critical vendors should comply with stricter controls such as:

  • security SLA reviews

  • monitoring of public breach disclosures

  • selective audits

Common mistakes we see

Our experience supporting organizations across industries has revealed recurring gaps in most third-party risk programs. Identifying them early is key to reducing operational, legal, and cybersecurity risks:

  • Evaluating all vendors the same way: Risk levels vary widely; a uniform approach drives unnecessary costs and insufficient controls where they matter most.

  • Not involving Security, Legal, and Risk teams: Without multidisciplinary input, key contractual, technical, and regulatory requirements may be overlooked.

  • Not documenting risk decisions: The lack of traceability hinders incident analysis, exception justification, and audit readiness.

  • Ignoring subcontractors: Many incidents originate from indirect third parties—often the most overlooked part of the chain.

How Seccuri can help

At Seccuri, we help organizations of all sizes strengthen their cybersecurity maturity and third-party risk management using frameworks such as NIST CSF 2.0. Our team—experienced globally in risk, OT, governance, and compliance—partners with you to design a practical and comprehensive 18-month work plan focused on closing real gaps and prioritizing critical capabilities.

We also double-click on talent: with AI-powered evaluations, we assess your team’s skills and capabilities, identify gaps, career paths, and the roles required to sustain a robust cybersecurity program over time.

The question is no longer if you will be attacked, but when. Preparation makes all the difference.

If you want to understand your current level and the concrete steps you should take next, schedule an introductory call with us here:
👉 https://calendly.com/seccuri-contact/30min?back=1&month=2025-06

 

Sources:

IBM. (2024). Cost of a Data Breach Report 2024. IBM Security & Ponemon Institute. https://www.ibm.com/reports/data-breach

Verizon. (2024). Data Breach Investigations Report 2024. Verizon Enterprise. https://www.verizon.com/business/resources/reports/dbir/

ENISA. (2023). Threat Landscape for Supply Chain Attacks. European Union Agency for Cybersecurity. https://www.enisa.europa.eu/publications/threat-landscape-for-supply-chain-attacks

Gartner. (2023). Third-Party Risk Management Trends and Findings. Gartner Research.

National Institute of Standards and Technology. (2024). NIST Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce. https://www.nist.gov/cyberframework

National Institute of Standards and Technology. (2022). NIST Special Publication 800-161 Rev. 1: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. https://doi.org/10.6028/NIST.SP.800-161r1

National Institute of Standards and Technology. (2021). NIST Special Publication 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. https://doi.org/10.6028/NIST.SP.800-171r2

International Organization for Standardization. (2022). ISO/IEC 27001:2022 — Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems. ISO.

International Organization for Standardization. (2020). ISO/IEC 27036-1:2020 — Information Security for Supplier Relationships. ISO.

European Union. (2023). NIS2 Directive: Directive (EU) 2022/2555 on Measures for a High Common Level of Cybersecurity Across the Union. Official Journal of the European Union.

European Union. (2022). DORA — Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector. Official Journal of the European Union.

SecurityScorecard. (2024). Global Third-Party Cyber Risk Report. SecurityScorecard.

Ponemon Institute. (2023). The State of Third-Party Risk Management. Ponemon Institute.