Marketplace / Third-Party Risk Management Basics
Fundamentals

Third-Party Risk Management Basics

Your security is only as strong as the vendors you depend on — here's the basic framework for managing that risk, without needing an enterprise-scale program on day one.

Key Takeaways
  • Vendors with access to your data or systems extend your attack surface, regardless of your own controls.
  • A basic framework covers four steps: inventory, assess, monitor, and respond.
  • Prioritizing your highest-risk vendors first is more practical than trying to cover everyone at once.
  • Even a lightweight program is worth having, regardless of company size.

Why It Matters

A breach doesn't need to originate inside your own systems to hurt you. Vendors with access to your data or systems extend your effective attack surface, whether or not you directly control their specific security practices.

High-profile incidents caused by a compromised third party rather than a direct attack are common enough that this isn't a theoretical risk — it's a well-established attack pattern that specifically targets the weaker link in a chain of trusted relationships.

The Basic Framework

A workable framework has four core steps: inventory (know which vendors have access to what), assess (evaluate risk before onboarding and periodically after), monitor (recognize that risk isn't static — a vendor's posture can change after onboarding), and respond (have a plan for what happens if a vendor is compromised).

Each step builds on the last. Skipping straight to assessment without a clear inventory, for instance, means you're likely missing vendors you don't even realize have meaningful access to your environment.

  • Inventory: know which vendors have access to what
  • Assess: evaluate risk before onboarding, and periodically after
  • Monitor: risk isn't static — a vendor's posture can change after onboarding
  • Respond: have a plan for what happens if a vendor is compromised

Where to Start If You Have Nothing

Start with your highest-risk vendors — the ones with access to sensitive data or critical systems — rather than trying to build a comprehensive program covering every vendor relationship at once, which tends to stall out before producing any real value.

A simple spreadsheet tracking vendor access and last-reviewed date is a legitimate starting point; the program can mature over time as you build capacity, and doesn't need to launch fully formed.

Questions
Do small businesses really need a formal vendor risk program?

Even a lightweight version — a simple inventory and basic risk questions before onboarding new vendors — is worth having, regardless of company size. The goal is awareness and a basic process, not enterprise-scale formality.

How often should vendor risk be reassessed after onboarding?

Annually is a common baseline for most vendors, with more frequent review for your highest-risk relationships or after any notable security incident affecting that vendor.

Related Reading

Have a Question We Didn’t Cover?

Email Our Team