Vendor risk management is an incredibly complicated process. While some methods are much more efficient than others, there is no consensus on how all organizations accurately manage vendor risk. Every organization has a different maturity level in their third-party risk management program. We generally see that organizations measure vendor risk in five different levels, each with an increasing level of security:
Nothing at all
Contract verbiage only
Audit check only (SOC 2)
Spreadsheet Security Questionnaire
Vendor risk management platform
#1 Nothing at all
This group doesn’t measure vendor risk at all. Some are in the beginning phases of their security program and have not started thinking about their vendor risk. They’re still figuring out how to measure their own risk. Many do not have the in-house expertise to begin measuring vendor risk. There are a few in this group who incorrectly believe that by not knowing the actual risk of their vendors, they are not liable for any issues.
#2 Contract Verbiage Only
These organizations do not have time to measure the risk of their vendors, but they know something needs to be done. Instead of spending an incredible amount of time measuring vendor risk, they instead add verbiage to all vendor contracts to state that the vendor must add all necessary security measures to protect the customer data from unauthorized access. These organizations believe that they would at least be covered from a legal standpoint if a compromise were to occur at the vendor organization.
#3 Audit Check Only
In addition to adding security requirements within vendor contracts, some organizations also request completed audit reports from the vendors. These audit reports may be a SOC 2 Type 2, HITRUST, or countless other audits. The organization reviews the audit report for any glaring issues, puts a check in the “review box”, then archives the data.
#4 Spreadsheet Security Questionnaire
The infamous vendor spreadsheet security questionnaire. On the positive side, this is so easy to start. All an organization needs to do is open up their favorite spreadsheet application, put their company logo at the top, type out a list of security questions, and email it to all of their vendors. While this seems easy at first, everything afterwards gets complicated. After the vendor completes the questionnaire, the organization needs to determine risk level for the vendor. There are usually a number of internal meetings and then follow up questions for the vendor and additional requests for vendor documentation. Finally, after countless hours, a consensus is reached and the organization decides whether or not to use the vendor. Afterwards, sometimes the executive leadership within the organization will simply accept any risk level just to do business with the vendor. So many organizations have this spreadsheet process, that vendor are just used to this inefficient method of measuring risk and have teams dedicated to answering different questionnaires for every customer. After this entire process is complete, the customer knows the vendor risk for a single point in time and must decide whether to repeat this entire process a year later to get an up-to-date measurement of the vendor.
#5 Vendor Risk Management Platform
As the vendor risk management process begins consuming an immense number of internal resources, many organizations determine that it makes more financial sense to purchase a solution to manage vendor risk. These solutions vary greatly in cost, efficiency, and accuracy. At least the organization can now utilize their internal resources on other tasks.
Conclusion
There are five basic methods for measuring (or not measuring) vendor risk. The methods vary in efficiency and security. Even within these methods, the approaches and solutions vary in accuracy. At Stern Security, we have worked with companies at all stages and could not recommend any of these options or any existing vendor risk management platform to customers. That’s why we created Velocity – the world needed an efficient and accurate vendor risk management solution. The Velocity platform utilizes passive reconnaissance and precise questionnaires which are all verified by an actual human analyst for accuracy. When a vendor completes an assessment, they can share the results with any of their customers that utilize Velocity. Everyone gets time back in their day and security is increased with Velocity.
For a look at how Velocity helps companies manage their security posture and vendor risk:
Book a Demo of Velocity to Learn about Vendor Risk Management Accuracy
If you ask any company if they are secure, most would say “Yes, of course we are!” This is especially true of vendors. No vendor ever says, “No, we’re not secure, but trust us with your data.” Most vendors are not being dishonest, but instead are overly optimistic about their vendor risk management accuracy, security posture and many do not have security staff to increase cybersecurity maturity.
Companies will often look for products to help with their vendor risk management programs. Vendor Management products are generally divided into two categories:
Self-Assessment Questionnaires: A questionnaire that the vendor fills out and once complete, it gives an automated score of the vendor’s posture.
Automated Assessments: A solution tool that scans the internet for publicly available details on the vendor in order to determine the security posture.
Both of these vendor management products prioritize getting as many vendors in their system as possible. They then claim they are the best solution because they have the most vendors. Unfortunately, this is meaningless because the results are inaccurate. There is the old adage, “Garbage in, garbage out.”
Vendors are unrealistically optimistic about their own security posture, so vendor management products utilizing self-assessment questionnaires give unrealistically optimistic conclusions. Not only are these vendors overly optimistic about their security, but many do not understand the security questions. You hear responses such as “Yes, we have a SOC 2 Audit. Here is the audit from AWS (Amazon Web Services), our cloud provider.” Unfortunately, the referenced SOC 2 Audit only applies to AWS’s own environment, not the application that the vendor may host in AWS. Instead, the vendor actually needs their own SOC 2 Audit for their own application. Another typical vendor response is “Yes, we’re secure because we host our application at AWS.” However, AWS claims zero responsibility for the security of the vendor’s application, as they only provide the platform to host it.
A vulnerability scan is not the same as a penetration test. Often vendors are asked if they have penetration tests performed on their solution and many will say “Yes, we have penetration tests performed every week!” However, they are referring to automated vulnerability scans, not comprehensive penetration testing that encompasses a very detailed manual and automated examination of the solution. If a vendor is filling out a questionnaire that asks them if they do penetration testing on their application, many will incorrectly say “Yes” even if they only do vulnerability scans.
Vendors will often say “Yes, we have a Security Officer” and will designate the most technically savvy person in the organization as their “Security Officer.” However, this person may not be a security professional at all. Sometimes this “Security Officer” is simply an IT support person or a project manager for the company. While this may vaguely provide a “check in the box” for compliance, it is not accurate and does not help the overall security posture of the organization.
Thus the vendor management solutions that rely on these self-assessment questionnaires often have inaccurate results that give their customers a false sense of security.
Automated Assessments are fast and give almost immediate scores that supposedly represent the security posture of the assessed organization. These products rely on scanning the internet for publicly available information in order to give a risk rating for a company. While these are very quick, professionals know that they are highly inaccurate. It is like looking at a house on Google maps and determining how secure it is. Sure, you may see a broken window in a grainy picture or a bad neighborhood from a crime map, but you don’t really know how secure the building is.
These products have numerous pitfalls. For example, consider a vendor offering visitors a public wireless network which is completely segmented on an air-gapped network separate from the corporate network. Automated products may see that network and say that it looks like an insecure network which reduces the security posture of the vendor even though this network has nothing to do with the company or its security. Another example is that some of these automated products will look at a company’s public website, find an issue on the site such as a weak SSL certificate, and claim that the vendor has a low security posture. However, the corporate website may have nothing to do with the product/device that the vendor sells.
The standard vendor management accuracy solution options are clearly broken. On one side of the spectrum, you have automated assessments that give fast results that prioritize speed and volume. On the other side of the spectrum, you have self-assessment questionnaires that prioritize convenience and volume. Both of these options produce highly inaccurate results because the data is not verified.
Velocity was created to fix this broken system. Velocity prioritizes Accuracy and Efficiency over volume. A team of security professionals verifies all vendor data in the system before we provide a verified security score and vendor report. Our system utilizes questionnaires and public reconnaissance in order to gather the data, but everything requires verification and supporting documentation before it gets a stamp of approval.
While the inaccurate vendor risk management products may provide a quick check in the box for compliance, they are not providing security and instead are giving customers a false sense of security with regard to their vendors. If we are going to flatten the breach curve and reduce the amount of vendor breaches, we need to accurately measure risk. The time has come to choose accuracy, security, and efficiency over volume and bare minimum compliance.
For a look at how Velocity helps companies manage their security posture and vendor risk:
Book a Demo of Velocity to Learn about Vendor Risk Management Accuracy
The Triangle Net has a vision to build a better world and provide opportunities to those striving to join the cyber security field. This amazing organization interviewed Stern Security’s Founder and CEO, Jon Sternstein, to discuss his security career. View the full interview here: https://www.thetrianglenet.com/episode-2-jon-sternstein/
Imagine building a strong, stable fortress around your most important assets. All of your focus is on stopping the intruder that will directly target your organization. However, there is an indirect way to breach the gates – through your third parties. Your organization relies on third parties (vendors) for necessary services and you have given them all keys to the castle so they can freely walk in and out like one of your employees. In many cases, you trust them to hold and manage your critical assets for you. Do you believe that they have created a fortress around your data that is as strong as the fortress that you created?
A company’s own internal cybersecurity posture should be the initial focus for protecting any organization. However, vendor risk is close behind. In today’s world, no organization operates in isolation. Every organization relies on third parties to conduct business whether it is for a customer platform, email service, banking, patient portal, infrastructure, deliveries, and more. These third parties are truly an extension of your own organization and they can either increase or decrease your security posture.
Problem
The vendor risk management problem is well known as we’ve seen major organizations announce breaches that originated through their third parties. In industries that publicly list their breach data, we can clearly see how serious and extensive this problem really is. Take the healthcare industry as an example – From 2009 to 2019, between 20% and 24% of data breaches were attributed to third parties or business associates. However, in 2020, breaches by business associates spiked to 40.2%!! There are similar examples in every industry in which organizations rely of third parties. The recent SolarWinds breach is a prime example of this as government entities and major corporations were impacted.
Third Party breaches in the healthcare industry in 2019 (Source: HealthcareBreaches.com)
Third Party breaches in the healthcare industry in 2020 (Source: HealthcareBreaches.com)
Regulations
Regulations have tried to stay ahead of third party security, but for many, if not most, organizations, the 3rd party security review is still not a mature process.
FFIEC and Gramm-Leach-Bliley Act (GLBA)
Over 20 years ago, GLBA (also called the Financial Modernization Act of 1999) tried to address the issue of internal and third party vendor risk to customer data for financial institutions. Buried deep inside this regulation is SEC. 501. PROTECTION OF NONPUBLIC PERSONAL INFORMATION. SEC 501(b), labeled, “Financial Institutions Safeguards” in essence states that each financial institution has an obligation to protect the security and confidentiality of customer data (106th Congress, 1999).
The FFIEC (Federal Financial Institutions Examination Council) IT Examination Handbook further states that financial organizations should ensure that service providers, or third parties, which have access to customer data adhere to GLBA SEC. 501(b) regulations (FFIEC, n.d.).
NCUA
Credit Union auditors are becoming more experienced when it comes to 3rd party security. The National Credit Union Administration (NCUA) examiners review third party due diligence procedures as part of their audits (Young LaBerge, 2019). This should not come as a surprise to credit unions as a 2007 NCUA Supervisory Letter detailed evaluating third party relationships. Specifically, this letter stated that examiners should review the following with respect to credit union third party relationships commensurate with the risk profile: Risk Assessment and Planning, Due Diligence, Risk Measurement, Monitoring and Control (NCUA, 2007).
23 NYCRR 500
New York State has also attempted to manage the cybersecurity issues in the financial industry including those posed by third parties. The New York State Department of Financial Services enacted “Cybersecurity Requirements for Financial Services Companies” also known as 23 NYCRR 500, which went into effect on March 1st, 2017 (NEW YORK STATE DEPARTMENT OF FINANCIAL SERVICES, 1). The regulation states that each covered entity (Financial Services Organizations) must assess the risks that their Third Party Service Providers poses to their data. It goes on to state that Covered Entities had until March 1st, 2019 to complete a thorough due diligence process on all Third Party Service Providers (NY Dept of Financial Services, 2020). In addition to the initial review of the third parties, section 500.11 “Third Party Service Provider Security Policy” states that Covered Entities are required to perform periodic assessments of Third Party Service Providers based on “the risk they present and the continued adequacy of their cybersecurity practices” (NEW YORK STATE DEPARTMENT OF FINANCIAL SERVICES, 1).
HIPAA & HITECH
The Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996, laid the groundwork necessary for healthcare organizations to secure Protected Health Information (PHI) through the HIPAA Security Rule. However, for third parties (Business Associates), HIPAA Compliance was not strong, criminal enforcement was not in place, and breach notification rules were not in scope. It wasn’t until 2009 when the Health Information Technology for Economic and Clinical Health Act (HITECH) was enacted which fully brought Business Associates into the security requirements and notifications within HIPAA Compliance (HIPAA Journal, n.d.).
CMMC
The Cybersecurity Maturity Model Certification (CMMC) is one of the latest additions to the cybersecurity third party risk arena. This certification is based on both NIST 800-171 and DFARS 252.204-7012. CMMC was developed by the Department of Defense (DoD) to strengthen the cybersecurity posture of defense contractors. All defense contractors must at least have CMMC Level 1 certification, but the levels increase depending on the sensitivity of data involved.
CMMC Levels (Carnegie Mellon University and The Johs Hopkins University Applied Physics Laboratory LLC, 2020)
Current Review Process
Many organizations do not review the security posture of their third parties. Covered Entities often rely on contractual language asserting that their vendors must “protect” the data involved. However, looking into whether the vendor is actually protecting the data requires both time and security expertise. If a covered entity does review their third party controls, it usually only involves asking for a SOC 2 Type 2 or similar report. Some organizations take it a step further by sending self-created security questionnaires in PDF or Excel formats to their third parties during contract negotiations. This data is then reviewed and discussed in numerous meetings which result in a final report that may be created months after the initial discussions.
Solutions
There are various solutions in place that offer vendor security assessments services, but few are accurate. Our team at Stern Security created a game changing cloud application called Velocity (https://www.velocitysec.com) to address this issue head-on and make the entire vendor review process simple for customers. Our cloud-based solution is both efficient and accurate. Additionally, our team verifies vendor supplied data in the system which goes well beyond commonly used self-assessment questionnaires.
Take a look at how Velocity helps companies manage their security posture and third party vendor risk
Conclusion
Regulatory bodies and auditors are catching onto the risk of third parties. Organizations are also beginning to ask the right questions before handing the keys to the castle to vendors. Cutting edge solutions like Velocity make the vendor review process straightforward, rigorous, thorough, and trustworthy. We still have a long road ahead to ensure that vendors create fortresses that are as strong as or even stronger than the ones their customers build to protect the most valuable assets.
Book a Demo of Velocity
Works Cited
106th Congress. (1999, November 12). GRAMM–LEACH–BLILEY ACT. Retrieved from Congress.gov: https://www.congress.gov/106/plaws/publ102/PLAW-106publ102.pdf
Carnegie Mellon University and The Johs Hopkins University Applied Physics Laboratory LLC. (2020, 30 1). Cybersecurity Maturity Model Certification (CMMC). Retrieved from Office of the Under Secretary of Defense for Acquisition & Sustainment: https://www.acq.osd.mil/cmmc/docs/CMMC_Model_Main_20200203.pdf
FFIEC. (n.d.). Vendor and Third-Party Management . Retrieved from FFIEC IT Examination Handbook Infobase: https://ithandbook.ffiec.gov/it-booklets/retail-payment-systems/retail-payment-systems-risk-management/operational-risk/vendor-and-third-party-management.aspx
HIPAA Journal. (n.d.). HIPAA and HITECH . Retrieved from HIPAA Journal: https://www.hipaajournal.com/hipaa-and-hitech/
NCUA. (2007, October). Supervisory Letter No 07-01: Evaluating Third Party Relationships. Retrieved from National Credit Union Administration: https://www.ncua.gov/files/letters-credit-unions/LCU2007-13ENC.pdf
NEW YORK STATE DEPARTMENT OF FINANCIAL SERVICES. (1, March 2017). CYBERSECURITY REQUIREMENTS FOR FINANCIAL SERVICES COMPANIES. Retrieved from governor.ny.gov: https://www.governor.ny.gov/sites/governor.ny.gov/files/atoms/files/Cybersecurity_Requirements_Financial_Services_23NYCRR500.pdf
NY Dept of Financial Services. (2020, 12 10). FAQs: 23 NYCRR Part 500 – Cybersecurity . Retrieved from New York State Department of Financial Services: https://www.dfs.ny.gov/industry_guidance/cyber_faqs
Young LaBerge, E. M. (2019, April 12). Rumor Has It: NCUA Digging Deeper on Vendor Management. Retrieved from National Association of Federally-Insured Credit Unions (NAFCU): https://www.nafcu.org/compliance-blog/rumor-has-it-ncua-digging-deeper-vendor-management