Hi, I'm Tom Field senior vice president of editorial with information security media group. I'm talking today I'm on maturing your third party cyber risk management program It's my pleasure to be speaking with Dave Stapleton. He's a CISO with cyber GRX. Dave.
Thank you so much for taking time to speak with me today It's my pleasure So if anything has come out of the past year is that everybody recognizes that third-party cyber risk management is a must Yet there are organizations that still struggle to get their arms around the problem. Why is that? Well, y'all want to avoid spending too much time rehashing these issues because frankly they've kind of attached to death However, some of the most common challenges that we hear about at cyber GRX are one It's too much effort on one hand you have organizations with thousands of third parties who are desperately trying to distribute questionnaires You know usually in the form of spreadsheets and they're how many those third parties until they get those questionnaires completed back to them And then they're trying to make some sense of the data before starting the whole thing over in the next year Also, if you're a vendor or third party that has a very large customer population I think of an example like ADP for example And you can expect to get just inundated with these kinds of questionnaires and each year and all of them are just different enough to Make it impossible to reuse your answers. So there's a lot of effort there as well.
And it also just takes too long I mean if you think about the scenarios I just described this isn't the kind of thing You can just knock out in a couple of weeks during a year There's organizations, you know Both kind of one that the customer if you will side and a third-party side that have staff to go to this process year round Another issue that we hear quite a bit about is it's hard to gain just meaningful actionable insights This is you know, it's a massive process with it's usually far too manual as well And so imagine if you will you're a third-party risk analyst and you've got 1500 spreadsheets saved in a folder somewhere in your So I come and I ask you to summarize all the most prominent themes so you can make some kind of proposal to the board It's not going to be able to ask and it's it's hard to just get that information out from that format And then I think the last thing funding It's you know, as you mentioned a lot of people recognize that it's a must But it's just not as sexy as some other cybersecurity issues And I think it can be difficult to convince, you know The executives or boards to provide the funding that's needed to implement a truly mature program Dave one of the trends I've seen over the past year or two is that many organizations now have turned to the third party risk-reading services What do you see as some of the benefits of this approach? Yeah, so risk-reading services that certainly speak to some of the challenges that I just mentioned for example, right? And they're fast without a doubt these services are based on an external scan And the organization's internet-facing environment So basically the scan starts with third parties on top level domain and then sort of spiders through all the sub-domains Looking for assets that belong to that third party and then trying to identify vulnerabilities in this asset So things like an expired encryption certificate for example, and so definitely quick I think you know because the core of the service is just based around an automated scan. They're also fairly cheap So affordability is a good piece of it and it's lastly I would say that given that the scans are based on frameworks like the CDE And the results can kind of be rolled up into a single overall score think of it like a psycho score or something like that And when you're dealing with potentially thousands or maybe even just hundreds of third parties a single score for those There are parties that I certainly can simplify the risk analysis process So flip side of that Dave, what do you see as some of the drawbacks of that approach?
The big one that people talk about the most is this issue with outside-in scanning and just frequently a lack of information that it provides to you There's an analogy that's been sort of making its way around forums and social media and that kind of thing and it compares these type of scans to let's say I got like a fire marshal who's evaluating the fire safety of the building but they're standing on the sidewalk across the street from that Building to do their evaluation. So they can see you know, there's a fire escape and there's a fire hydrant Not that far away, but the problem is they don't know anything about the egress within the building They don't know where on their smoke detectors or they have batteries and the sprinkler systems You know, do they have a process for evacuating the building all that kind of thing? So the service security terms and outside in scan doesn't really tell you much about things like patch levels for internal systems or The use of data loss prevention techniques and tools internally the encryption of data rest on a non-public database or Policies and standards and procedures or plans for identifying and responding to incidents, for example So I say the risk of using too many analogies The biggest weakness I think is akin to sort of measuring the size of iceberg by what you can see above the water And then I think another concern is something that I hear from a lot of organizations that are being scanned by these types of risk rating services And they talk a lot about the number of false positives that are returned by these scans So the customers are the companies that are offering these types of risk rating services Aren't given a fully vetted and curated list of assets by the third party of their scanning And so the result is that scanners are kind of prone to picking up on domains or hosts that actually don't have anything to do with the targeted organization And the obvious concern there being that you know inaccurate information might be provided back to the customers of these risk rating services So Dave weighing all these factors pro and con where would you say that third-party rankings fit within what you would call a mature third-party cyber risk management program Sure, yeah, so risk ratings definitely have a place and given the benefits that I mentioned earlier You know third-party risk practitioners just need to keep in mind that they're not seeing the full picture Just by using risk ratings So one of the areas for example that I think risk ratings can really play a helpful role is in the vendor approach tournament process It would be awesome if organizations, you know, always had months to fully evaluate, you know a number of potential third parties before deciding on which one to do business with Unfortunately the reality is that we often are given very little notes out of four decisions made So in some cases, you know, just days and in those types of scenarios I think the ability to run one of these scans with the click of a button and receive some type of cyber security risk data on which To base a decision could be a huge asset. So that's one area where I think that understanding is definitely fit in a mature program We spent a lot of time talking about ratings Dave.
What are some of the other program elements that need to be built around them? Yeah, so I mean, it's the rest of your third-party cyber risk management program So one of the things you definitely need a mechanism to That allows you to assess risk, you know, within a third party some of the things I was talking about before that you just can't scan for from the internet So this could take on all kinds of different formats some organizations in certain circumstances We'll just conduct full independent audits of the implementation and effectiveness of security controls with their third parties Some will contract out that kind of work and have an auditing firm. Maybe one of the big four conduct assessments or audits on their behalf You can use approaches that combine a self-assessment with maybe independent validation of the answers to kind of get hopefully best of both worlds As far as I'm expediency, but still that independent eyes or you just leverage self assessments Just let the third party tell you how they're implementing their cyber program I think the important thing there is to make sure you're applying the right level of inspection That's you know commensurate with the level of risk that's presented by your third party So that actually kind of leaves me to another part of a mature program, which is understanding of inherent risk So think of inherent risk as the level of risk that is known simply by evaluating the characteristics of a third party I mean their relationship to you as their customer So, you know, what type of information are they processed transmitting or storing what access do they have to your facilities or data or applications? If something were to go wrong, how quickly can you replace that third party?
So as an example, I got a printing shop that is used to print flyers for periodic company that's likely presents much lower inherent risk Then for example, I'll go back to AAP approval service that's processing transmitting and storing just massive amounts of employee PII So understanding inherent risk tells you how rigorous you need to be in your assessment process What type of processes do you need to use? But it also gives you an idea of the level of acceptable or unacceptable risk that may result in that assessment You know for any particular third party because that's gonna change depending on what sort of inherent risk that third party poses to in the first place And then in the last piece to sort of complete the puzzle that we've got these assessment results back We need to understand what that risk is and what to do about I mean there's very little point I'm doing any of this if you don't have a process in place and to address unacceptable identified risk So again, it's taking into consideration What kind of potential impact did this have on my organization and then What are the appropriate steps that you or your third party can take to reduce or mitigate that risk? So I think those are some of the standard pieces that would be included in any third party cyber risk program And then certainly with like your time on top of a risk rating service So you're talking a little bit more about cyber GRX. How are you helping customers to grow and mature their approaches to third party cyber risk?
Yeah, so you know cyber GRX was and is built by a cyber security risk practitioners So our goal is you know to provide or at least facilitate all the aspects of a mature third party cyber Risk Management program that I've kind of talked about already day So one of the key ways and this is the thing that excites me most about our organization is that we are leveraging an exchange model for risk assessment data Our assessment is standardized which means that what the third party has joined our exchange and completed an assessment that assessment can be shared with Multiple of their other customers. So and we're reducing that level of effort on both ends So this addresses kind of one of the core challenges with third party cyber risk management, which is really about the time it takes imagine logging onto an exchange and you enter in a hundred new third parties and you find out Oh, that 50% of these already have assessments completed. All I need to do is press a button to request access to that data So another thing that we're doing which is very exciting is combining the results of these kind of standardized assessments that we're connecting with advanced analytics So we're using a combination of cyber hygiene scanning near real-time threat intelligence feeds and separate field chain data to go beyond just a simple assessment of compliance You know check a box yes or no in order so we can demonstrate two third parties and their customers Why a particular assessment response presents real risk again, not just you said you don't do this so go do it It's not appropriate I don't think for organizations feel that I have to spend money and time trying to close just every gap in a third party cyber program So I'd say what we want to do is provide you know practical insights to help companies focus on what really matters Now Dave I know that you're producing an upcoming webinar on this very topic. What greater detail will you offer in that particular program?
Yeah, yeah So the format of the webinar will let me spend a little more time kind of digging into the details of how risk ratings work Which I think is something that people like to know more about and then of course how do you fit into an actual third party cyber risk management program? for example I'd like to talk more about the specifics of ingesting risk ratings data in an inappropriate way force and how to combine that information with Inside out assessment data to kind of capture the full picture of risk the other thing I like about our webinars I'm personally in the visual learner So I'll be able to illustrate some of those key points as well with hopefully some some informative diagrams and other illustrations Well, Dave, I look forward to it meanwhile. Thank you so much your time and insight today. Absolutely.
It's my pleasure. Thank you again We've been talking about maturing your third-party cyber risk management program and I've been speaking with Dave Stapleton He's the CISO with cyber GRX for information security media group. I'm Tom Field. Thank you very much