Risk Management Blog and Articles

January 28, 2021

Understanding Supply Chain Data Breaches in the Aftermath of SolarWinds

We take a look at the different sides of supply chain data breaches and provide 3 practical tips to secure the extended enterprise.
December 17, 2020

Third Party Security Breachings & The Cost of a Security Breach: Top 5 Breaches

Data breaches caused by third-parties cost millions of dollars every year to large companies and are devastating to small businesses.
September 18, 2020

Yet Another Ransomware Vendor Breach in the Health System – And What We Can Learn

Although the servers of a third-party were affected, it is the Healthcare organization that needs to notify the tens of thousands affected, including 56,000 donors. Today we’ll dive into third-party risk management and liability.
July 30, 2020

What We Learned from the Latest Third-Party Data Breach in the Financial Services Industry

A ransomware attack against a vendor of a fund administrator exposed data of investors. We analyze how a TPRM program can help prevent a Third-Party Data Breach like this.
July 23, 2020

Web Applications Continue to be a Top Breach Vector for Attackers

We look at the latest DBIR through the lens of third-party risk and how it relates to the 43% of breaches that involve web applications.
May 21, 2020

Why the OWASP Top 10 can be an ally to your organization

The OWASP Top 10 is a good starting point for detecting possible issues around third-party components. So how does it relate to TPRM?
April 9, 2020

4 Challenges of Moving Cyber Initiatives Forward

With growing executive demand for changes to cybersecurity processes and awareness comes inherent challenges to an organization.
March 10, 2020

Should Legal increase spending in third-party risk management technology?

Gartner predicts that by 2023, organizational spending on third-party risk management (TPRM) technologies within the Legal industry will increase by 50%. What can tech actually do for the industry?
January 28, 2020

Data Privacy Day: 3 ways to keep third-party data exposure under control

January 28 is Data Privacy Day, an international effort to empower users and encourage businesses to ‘respect privacy, safeguard data and enable trust.’ In an increasingly data-driven world, you need to make sure your company is going the extra mile to protect your customers and users. That means keeping an eye on your third-parties that might have access to Personal Identifiable Information (PII).