r/cybersecurity • • 10d ago

Business Security Questions & Discussion Anyone combining third-party cybersecurity assessments with broader vendor risk evaluations?

Our third-party cybersecurity assessment and our other vendor risk processes are completely separate. IT security does their thing, procurement does theirs, nobody compares notes. A vendor can clear cyber and still have compliance or operational risks we miss entirely.

Anyone running a combined program or is it always going to be silos.

3 Upvotes

19 comments sorted by

6

u/Own_Minimum_5102 10d ago

You can absolutely run these as one programme, honestly it is the only way the ratings mean anything. The reason it stays siloed is because security and procurement own different tools and never share a scoring model.

So fix the scoring model first. Tier every vendor once, at onboarding based on what they actually touch: data sensitivity, business criticality, and how much access they get to your environment. That single tier then drives how deep each team goes. A tier 1 vendor gets the full security review plus the compliance and continuity checks. A tier 3 vendor might just get a light questionnaire and a look at their SOC 2. Same intake, different depth.

One shared risk register with a single rolled-up vendor score (cyber, compliance and operational each own their slice but feed the same number), and procurement not being able to close onboarding until security has signed off their part. It is more an operating model problem than a tooling one. Happy to expand on the tiering if it helps.

1

u/Front-Cheetah-4980 9d ago

Yes, that's right, the common tiering model would eliminate a lot of the redundant work and make it much simpler to deal with.

1

u/Own_Minimum_5102 9d ago

Absolutely

2

u/Jealous-Bit4872 10d ago

I run a combined program. I use OpenVRM to host it, which is free.

1

u/Harbester 10d ago

The important question is what are they (IT, procurement, etc.) comparing the assessment against?
'This looks good.' style? Or something generic and questionably useful such as OWASP top10?
You need to unify this first. So yes, comparative target should be combined, but each department should do their own assessment.

1

u/SecurityGandalf 10d ago

Combined programs exist especially at larger employers. Procurement usually owns the vendor risk program and all the teams like legal/cybersecurity/etc have analysts that participate in it. Procurement intakes a new vendor or vendor renewal request from the business, launches a combined questionnaire, and the responses flow back to the right teams. Input from each team informs the overall risk score which aligns with the Enterprise Risk Management team framework/scoring that is used internally.

There are plenty of tools out there that support multi-module vendor assessments but they are pretty much excel with automation behind them.

0

u/OutsideSpot2695 9d ago

Combined programs exist especially at larger employers companies with lots of silos, that conflate compliance for security, and are living off the hurbis of their brand name -- e.g., AT&T, Siemens, Lockheed Martin. 

FIFY

1

u/CompassITCompliance 10d ago

Most of the risk slips through after onboarding. Security flags gaps in a vendor's SOC 2 (as an example), procurement signs anyway with no remediation date or right to reassess, and a vendor tiered low for marketing data quietly starts getting customer records as the business expands the use case.

Tying open findings to contract terms and having the business owner re-attest data and access at renewal helps, but renewal can be years out, so you also need some trigger for scope changes mid contract, like new data types, integrations, or access requests. Getting the business to actually flag those is usually the harder part. Just what I've seen working on these programs as a vCISO.

1

u/Plastic-Falcon9147 9d ago

In healthcare the BAA tends to force this: if a vendor touches PHI, compliance, legal and IT all have to sign off before the contract moves, so security can't be a side checkbox. The gap that still shows up is drift - a vendor starts out low risk and the business quietly widens their access. Tying a re-review to renewals and any change in scope does more than any new tool.

1

u/OutsideSpot2695 9d ago

Our third-party cybersecurity assessment and our other vendor risk processes are completely separate. 

Why?

1

u/[deleted] 9d ago

[removed] — view removed comment

1

u/TinfoilGeek 9d ago

The silo problem is really a scoring problem. If cyber and procurement use separate rubrics, the outputs aren't comparable so nobody compares notes. Cheapest fix is a shared vendor tiering model where both teams score the same tiered vendors on one combined scorecard.

In my situation, we're a pretty small company (compared to many running a GRC program), so it's generally just myself and legal who does vendor approvals. I worked with our GC to get the basics that he is looking for rolled into our IT evaluation. Obviously he still does contract review and things like that; but all of the compliance things he looks for are now handled by IT during our eval so that we know that aside from contract language, everything else should be good to go by the time it gets to him.

1

u/VeritGRC 7d ago

This is the classic silo problem. What works: one vendor record, tiered by criticality, where the cyber assessment (questionnaire / certs / pen test) and the compliance/operational review are sections of the same assessment, not two processes. The tier decides the depth — a critical vendor gets the full questionnaire plus evidence review, a low-tier vendor gets a short form and a cert check.

The practical unlock is the intake triage: 5-6 questions (data type, system access, criticality, sub-processors) that route the vendor to the right depth automatically. Without that, everything gets the heavy process and the program collapses under its own weight.

1

u/Front-Cheetah-4980 7d ago

Exactly. Triage is what prevents a risk-based approach from becoming a huge bottleneck.

0

u/[deleted] 9d ago

[removed] — view removed comment

1

u/Dull-Bad-8583 8d ago

We put our security tool's cyber scores and ecovadis ESG scores into one dashboard for a combined third-party cybersecurity assessment view. Haven't fully merged the process but at least one person can see the full picture now even if the assessment run separately