.Our IT has been outsourced, so this is with the supplier.

There's a big risk for me right now.

The execution can be with the supplier. The consequences of failure, data loss or a security incident are ultimately with your organisation.

Therefore, you don't just want to assess critical IT providers on price, service and satisfaction.

You want to know if you have enough certainty about security, continuity and recovery.

Step 1: first determine whether the supplier is really critical

Question:

  • a key process shall cease without this Party;
  • processes the supplier's sensitive data;
  • he/she has management rights;
  • is difficult to switch;
  • recovery depends heavily on this party;
  • use critical subcontractors.

The more .ja.ja. the more the assessment.

Step 2: Understand the service and the responsibility limit

This sounds simple, but it often goes wrong here.

Record:

  • the supplier's management;
  • the organisation itself;
  • who is responsible for accounts;
  • who's patching;
  • monitoring;
  • who takes care of backup;
  • who detects incidents;
  • who's doing recovery.

An unclear border almost always leads to delays during incidents.

Step 3: demand for concrete security measures

I wouldn't just ask:

.

Question also:

  • Our service falls within the scope;
  • how admin access is secured;
  • shall be required to do so;
  • how vulnerabilities are managed;
  • how logging is monitored;
  • how staff are screened where relevant;
  • how to separate our data;
  • how changes are controlled.

The answer ‘we follow best practices’ is too vague.

Step 4: request proof

Evidence may consist of:

  • ISO 27001 certification;
  • SOC/ISAE report;
  • audit report;
  • penetration test;
  • vulnerability reporting;
  • restore test;
  • SLA reporting;
  • incident statistics;
  • Control statement.

Do not judge only whether a document exists.

Look at:

  • Scope;
  • date;
  • exceptions;
  • relevant findings.

Step 5: assess continuity

Question:

  • what is the agreed availability;
  • which RTO and RPO apply;
  • when recovery has been tested;
  • which dependencies exist;
  • what happens to ransomware;
  • how quickly the service can be restored elsewhere;
  • which capacity is available in case of a major incident.

A 99.9% SLA says nothing about the quality of recovery after a complex cyber attack.

Step 6: Review incident management

Pre-capture:

  • the time limit for reporting incidents;
  • who is contact person;
  • what information you receive;
  • how often updates are made;
  • who conducts forensic research;
  • how data is secured;
  • who supports legal notifications.

Ask for a recent incident or exercise.

Not to settle the supplier, but to see how the process really works.

Step 7: look at admin access

External administrators often have very wide rights.

Check:

  • individual accounts;
  • MFA;
  • privileged access;
  • logging;
  • temporary rights;
  • periodic reviews;
  • offboarding;
  • subcontractors.

A shared administrator account would prompt me to ask for it.

Step 8: look at the supplier chain

Ask which subcontractors are essential.

Examples include:

  • Cloud Provider;
  • data centre;
  • support partner;
  • authentication service;
  • backup provider.

You want to know where concentration risk is and what changes are reported.

Step 9: assess contract and SLA content

I would like to see at least that agreements exist on:

  • security;
  • access;
  • incident reporting;
  • logging;
  • backup;
  • recovery;
  • right of audit;
  • Insurance;
  • subcontractors;
  • data ownership;
  • exit;
  • data deletion.

Contractual text is not a guarantee, but an important control tool.

Step 10: Test exit question

Let's say:

♪ If we have to leave in three months, what do we need? ♪

Look at:

  • export formats;
  • documentation;
  • configurations;
  • dates;
  • accounts;
  • transfer;
  • costs;
  • dependency on intellectual property;
  • escrow where relevant.

A difficult departure increases supplier risk.

How do you judge the answers?

I wouldn't just score on a subject.

Note:

  • risk;
  • evidence;
  • open uncertainty;
  • owner;
  • Follow-up.

Examples include:

Subject matter Status Evidence Open Point
MFA management accounts Green Configuration + audit report None
Restore Orange Backup reporting No recent full restore test
Incident Notification Orange Contract No clear first reporting period
Exit Red None Export and transfer not worked out

That gives a lot more grip than one supplier.

What questions does a CFO ask?

For finance, I would look at:

  • continuity impact;
  • concentration risk;
  • financial health;
  • exit costs;
  • liability limits;
  • insurance;
  • repair costs.

What questions does a CIO or IT manager ask?

This is the focus of the debate:

  • technical controls;
  • management rights;
  • integrations;
  • logging;
  • patching;
  • monitoring;
  • recovery;
  • change management.

What questions does governance or oversight ask?

They don't have to read every control report.

I'd like to know:

  • which suppliers are critical;
  • where there is no significant evidence;
  • where the main residual risks are;
  • which actions are lagging behind;
  • which party makes the organisation disproportionate.

That's controllable information.

My main supplier demand

If I had to choose one question, it's:

.

This will automatically ignore sales brochures and general certifications.

For a broader approach to supplier risk, read also:

Third-party risk management: How do you control digital supplier risks?

Sources and read on

Third-party risk management →Digital risk management for RvT and RvC →NIS2 and chain responsibility →