This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The Neighborhood Watch: Using Continuous Monitoring to Increase Visibility and Effectiveness of TPRM programs

Download resources

About this session

Jon Ehret, VP of strategy and risk at RiskRecon and a third-party risk practitioner since 2004, argues that continuous monitoring is the missing tool that turns a questionnaire-only vendor program into a mature one. He frames third-party risk as a tug-of-war between a business that keeps adding vendors and understaffed risk teams (a median of two people running around 249 reviews a year), and shows survey data that only 30% of practitioners trust questionnaire responses to reflect real control effectiveness. His central metaphor is the scalpel versus the Swiss Army knife: questionnaires alone are one sharp tool, but maturity comes from combining inherent-risk rating, evidence, pen-test data, a GRC platform, onsite assessments and continuous monitoring. Comparing continuous monitoring to a neighbourhood watch that looks in from the outside, he walks through use cases (triaging a portfolio, planning and validating assessments, detecting incidents between review cycles, and driving vendor remediation) with case studies from a pharmaceutical company, a retailer and an energy company. He stresses inherent-risk rating by data and record volume as the bedrock of any program.

Visibility into our vendors' security controls and the effectiveness with which they are operating have been and continue to be some of the major challenges in the world of third party risk. This discussion will cover those struggles, the inherent limitations of the security questionnaire as well as how continuous monitoring tools can be utilized to shed light on the effectiveness of a vendor's security controls. 

Key takeaways

  • Do not run a third-party risk program on questionnaires alone; combine inherent-risk rating, evidence, pen-test data, a GRC platform, onsite visits and continuous monitoring.
  • Rate inherent risk per engagement by the type and volume of data a vendor holds, not by a blanket 'any PHI is high risk' rule, so effort matches real exposure.
  • Use continuous monitoring to triage a large portfolio, prioritising vendors whose external security posture is trending down over those merely in a higher risk tier.
  • Compare a vendor's questionnaire answers against objective outside-in data (for example patching scores) and open a conversation wherever they diverge.
  • Reserve onsite assessments for the highest-risk vendors; they surface problems (like an unmanaged, easily-relocated operation) no questionnaire would reveal.

Speakers

Jonathan Ehret
Jonathan Ehret
Vice President, Strategy & Risk · RiskRecon
Jonathan has been a third-party risk practitioner since 2004. He is co-founder and former president of the Third-Party Risk Association. He has deep experience building and running third-party risk programs in finance and healthcare. He started with… Read moreRead less

Jonathan has been a third-party risk practitioner since 2004. He is co-founder and former president of the Third-Party Risk Association. He has deep experience building and running third-party risk programs in finance and healthcare. He started with RiskRecon in April, 2020.

Resources

Tags

More from GoSec 2020

Also from Jonathan Ehret

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.