Security News

Cybersecurity news aggregator

INFO News Dark Reading

Manage Vendor Risk in a Few Practical Steps

Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Cyber Risk Manage Vendor Risk in a Few Practical Steps Manage Vendor Risk in a Few Practical Steps by Daniel Nutkis Jul 14, 2026 4 Min Read Application Security Cursor IDE Auto-Executes Malicious Code in Poisoned Repos Cursor IDE Auto-Executes Malicious Code in Poisoned Repos by Alexander Culafi Jul 14, 2026 3 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America Recent in World See All Cybersecurity Operations State IDs for AI Agents: Will Estonia Set a Precedent? State IDs for AI Agents: Will Estonia Set a Precedent? by Nate Nelson Jul 8, 2026 5 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyber Risk Vulnerabilities & Threats Application Security Commentary Manage Vendor Risk in a Few Practical Steps Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance. Daniel Nutkis , Founder and Executive Chairman , HITRUST July 14, 2026 4 Min Read Source: Dilok Klaistataporn via Getty Images OPINION Third-party information risk reaches beyond cybersecurity. A third-party failure can create operational disruption, privacy impact, regulatory exposure, contractual loss, business interruption, reputational harm, customer impact, uninsured financial loss, and continuity failure . The issue for boards and senior management is exposure: what risk the enterprise carries because information, systems, processes, and dependencies sit outside their control. Most organizations have responded by building third-party risk management programs. These programs review vendors, collect assurance reports, request and analyze questionnaires, evaluate contracts, require insurance, manage remediation, and route exceptions for approval. These activities matter. Effective governance also requires a clear view of the exposure those vendors create. The critical questions: What third-party information risk exposure are we carrying, how much of it has been effectively reviewed, is it within risk tolerance, how does it compare to peers, and what financial exposure remains? Related: More Countries Jump on the Social Media 'Ban Wagon' Effective third-party information risk governance follows a simple sequence: Measure → Validate Coverage and Confidence → Compare → Explain → Aggregate → Benchmark → Treat and Transfer → Govern. First, organizations need to measure residual exposure after considering inherent risk, data sensitivity, business criticality, assurance quality, control effectiveness, remediation, contractual protections, insurance, and compensating controls. Second, they need to validate coverage and confidence. Management should be able to explain how much of the vendor universe has been risk-tiered, how much has been reviewed, how much exposure those reviews represent, whether review depth was appropriate, and where uncertainty remains because evidence is stale, incomplete, narrow, self-attested, or otherwise low-confidence. Third, measured exposure should be compared with defined appetite and tolerance. Governance depends on thresholds, and thresholds require a stable, standardized measurement approach. Weak measurements push decisions toward reviewer judgment, business urgency, negotiation leverage, available documentation, or local interpretation. Fourth, management should explain deviations from norms. Business urgency may justify proceeding with a vendor outside normal tolerance. Those decisions should be explicit, measured, owned, time-bound, and visible. Exception reporting should identify the exposure driver, business rationale, alternatives considered, accepted exposure, expected duration, accountable owner, mitigation plan, and transfer plan. Related: Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure Fifth, exposure must be aggregated. A single vendor exception may be manageable. A cluster of similar exceptions can create material portfolio risk. Individually tolerable decisions can become collectively significant when they involve the same critical process, data type, cloud provider, software platform, geography, control weakness, subcontractor dependency, insurance limitation, or contractual gap. Sixth, benchmarking provides context. Boards should assess whether internal norms and thresholds align with those of comparable organizations. Some organizations accept more exposure than their peers do. Others operate with a more conservative posture, which may affect cost, speed, and competitiveness. Peer context helps leadership determine whether deviations reflect deliberate strategy or unmanaged drift. Seventh, risk treatment and risk transfer should be evaluated as governance decisions. Management should know what risk is being remediated, reduced, accepted, ensured, insured, indemnified, pooled, or otherwise transferred, along with the financial exposure that remains. Risk Transfer Deserves Careful Treatment Risk transfer becomes useful for governance when the organization can describe, in business terms, the residual exposure, plausible financial impact, retained portion, transferred portion, reliability of the transfer mechanism, and remaining exposure to the enterprise. This matters because insurance certificates, indemnity, completed reviews, approved exceptions, and activity reports can coexist with material exposure on the enterprise balance sheet. Related: AI Gateways Offer Attackers the Keys to the Kingdom Board and management responsibilities should also be clear. Management operates the governance model. That means maintaining the measurement approach, applying thresholds, evaluating vendors and contracts, identifying concentrations, recommending treatment, documenting exceptions, evaluating transfer options, assessing review coverage and confidence, and reporting material exposure. The board oversees whether management has a credible model for measuring and governing third-party information risk. That oversight includes approving or challenging risk appetite, understanding material exposure, reviewing significant deviations from tolerance, evaluating retained and transferred risk, assessing coverage and review effectiveness, and determining whether posture aligns with strategy, resilience expectations, and peer norms. A board-level report should be concise, quantitative, trend-based, and decision-oriented. It should function as an exposure-governance report, with operational vendor-review metrics handled separately. A practical report should include the following: an exposure overview, tolerance alignment, financial exposure and transfer, exceptions, benchmarking, and actions. This reporting structure gives boards the governance view they need. It shows the exposure that the enterprise carries, the strength of the evidence behind that view, the areas outside tolerance, the concentrations that could become material, the financial impact that remains, and the actions management is taking. Third-party information risk governance requires exposure visibility. Vendor reviews, questionnaires, certifications, contracts, insurance, and exception approvals all support the process. Board oversight also requires a measured view of residual exposure, coverage, confidence, tolerance alignment, concentration, peer context, retained financial exposure, transferred financial exposure, and required action. Organizations that build this capability can govern third-party information risk as an enterprise exposure. They can move faster when risk is understood and acceptable, escalate the relationships that require attention, avoid false comfort from activity metrics, and give boards and senior management the information needed to oversee the risk with discipline. Read more about: Opinion About the Author Daniel Nutkis Founder and Executive Chairman, HITRUST Since founding HITRUST in 2007, Dan has set a clear strategic vision as CEO that established HITRUST as the vanguard standard in managing information risk and meeting regulatory compliance for healthcare organizations seeking security and privacy certifications. He is now focused on bringing HITRUST’s services to a global, industry-agnostic audience. Dan has been recognized as a top information security influencer by several publications and industry organizations. See more from Daniel Nutkis Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the

Share this article