Half of the cybersecurity incidents affecting organisations are related to vendors. With proper supervision, you can ensure the security and continuity of your own business.
The security of the technology of your providers can impact your business.
Suppliers can be categorized into three types:
Suppliers that are “connected” to your information systems
Providers that are “not connected” but who have information about the organization or its customers
Suppliers whose activity impacts the operations of the organization.
Rank the criticality of your suppliers by levels, ideally it can be four (very low/low, medium, high and critical).
Factors to consider:
Economic, operational, legal, reputational, personnel safety risks.
The same methodology will not be applicable to everyone. Those providers/services with higher risk should be subject to stricter monitoring than those with lower risk levels.
Structure monitoring along two axes:
Required Security Level
Monitor Assurance
European regulator guidelines require you to supervise outsourced services. That is why, in partnership with Interbank Cooperation Center, we have participated in the creation of the Center for Interbank Cooperation, we have participated in the creation of the Pinakes platform, which makes it easy for them to comply to these guidelines with maximum efficiency and advantages.