Risk Management Blog and Articles

October 22, 2019

Global Resilience Federation and ThirdPartyTrust establish partnership allowing members to peer-source vendor risk assessments

Reston, VA USA – October 23, 2018 – Global Resilience Federation (GRF) and ThirdPartyTrust today announced a new partnership that provides GRF members the opportunity to peer-source vendor risk management using the ThirdPartyTrust community-oriented platform that advances awareness and minimizes the workload of evaluations.
September 10, 2019

LS-ISAO Annual Member Gathering: A collaborative approach to Vendor Risk

Last Monday, (9/30) at the LS-ISAO Annual Member Gathering, we had the privilege to help organize a panel about the importance of a legal specific set of controls to help manage your third-party risk management program.
October 10, 2018

Experts share important metrics for assessing vendor risk

Metrics drive the measure of progress and stand as benchmarks during any assessment, audit or review process. They are the life blood of reporting, but when it comes to vendor risk management, it is not as straight forward as you might think.
July 25, 2018

Shared Assessments and ThirdPartyTrust bring the SIG to the Masses

ThirdPartyTrust has announced that it has joined the Shared Assessments Program, the member-driven trusted source in third party risk assurance and management. In addition to its membership in the program, ThirdPartyTrust’s platform now supports the Shared Assessments Standard Information Gathering (SIG) questionnaire.
July 6, 2018

Data is the New Oil and Breaches are the New Spills; So Where is the Leak?

The former CEO of Intel, Brian Kzranich said last month, “Data, I look at it as the new oil. It’s going to change most industries across the board. Oil changed the world in the 1900s. It drove cars, it drove the whole chemical industry,” Krzanich explains.
May 23, 2018

Guest Blog: A GDPR Primer to Meet the Deadline Next Week

Discussions on privacy laws have taken front and center in recent weeks as GDPR (General Data Protection Regulation) begins to be enforced by European Union (EU) member states on May 25, 2018.  As we have been discussing for a while, there is confusion as data collectors try to figure out the impact of this legislation.  There is no question that large, multi-national corporations will have to comply and many of these corporations are already in compliance.  However, with this deadline just around the corner, smaller companies that do not actively target EU residents are struggling with how this legislation impacts them. Until […]
April 23, 2018

How is Cyber Shaping the Insurance Industry? Learn From Pros at Allstate, Trustmark and BCSF

We participated in a panel at the OnRamp Insurance Conference. Here's some insight into how cybersecurity is shaping the insurance industry.
March 27, 2018

ThirdPartyTrust Infosec Interviews: Rocio Baeza, CEO CyberSecurityBase

Hi, everyone. This is Jeff Spetter from ThirdPartyTrust and I had the great pleasure of speaking with Rocio Baeza, CEO of CyberSecurityBase. Here’s a recap and audio of the interview.  Rocio Baeza the CEO and Founder of CyberSecurityBase, helping rising tech companies get started with information security. The mission is to simplify security, teach that model, and empower tech leaders. Given her work, she understands the limitations of resources companies may have to invest in cybersecurity. She doesn’t necessarily recommend for smaller organizations to follow frameworks meant for large enterprises. Because of the limitations of resources , both time and capital, […]
March 5, 2018

OWASP Chicago February Meetup Summary and Presentations

The evening at the OWASP Chicago meetup was filled with really informative content in a couple of areas all tied to application security. Here's a recap.