Third-Party Cyber Risk Assessment
Understand the Cyber Risks Introduced by Suppliers, Service Providers and Connected Partners
Knowledge Kraft helps organizations evaluate whether third parties have appropriate controls for protecting information, systems and services.
Our assessments support onboarding, contracting, monitoring and reassessment decisions according to the supplier’s actual level of risk.
Related Services
- ISO 27001 Implementation
- Cyber Security Risk Assessment
- Vulnerability Assessment, Penetration Testing and Technical Remediation
- Endpoint Security Hardening
- Network, Server and Cloud Security Assessment
- Firewall, SIEM, EDR and IAM Advisory
- Incident Response and Cyber Crisis Management
- Phishing Simulation and Awareness Programmes
- Secure Coding and Application Review
- Data Privacy Compliance Support
Third-Party Cyber Risk Assessment at a Glance
Service objective: To identify and manage cybersecurity risks created by third-party access, technology, information processing and service dependencies.
Suitable For
- Organizations using cloud services
- Businesses outsourcing critical processes
- Companies sharing sensitive information
- Organizations using managed IT providers
- Manufacturers with connected suppliers
- Companies using software vendors
- Businesses managing large supplier bases
- Organizations responding to customer requirements
- Companies reviewing critical service providers
- Multi-location organizations
Knowledge Kraft Can Support
- Supplier-risk classification
- Security due diligence
- Supplier questionnaires
- Evidence review
- Contract requirement development
- Access and connectivity review
- Cloud-provider assessment
- Critical-service assessment
- Supplier audit
- Corrective-action tracking
- Periodic reassessment
- Exit and termination controls
- Programme governance
What Is Third-Party Cyber Risk Assessment?
Third-party cyber risk assessment evaluates the security risks created by external organizations that:
- Access company systems
- Process or store information
- Supply software
- Provide cloud services
- Manage infrastructure
- Connect to company networks
- Support critical business activities
- Use subcontractors
NIST cybersecurity supply-chain guidance addresses identifying, assessing and mitigating risks throughout the supply chain. Updated guidance highlights the reduced visibility organizations may have into how acquired technology and services are developed, integrated and operated.
A risk-based programme should not require every supplier to complete the same assessment.
Third parties may be categorized according to:
- Information sensitivity
- System access
- Connectivity
- Service criticality
- Subcontracting
- Geographic exposure
- Recovery dependency
- Regulatory or customer requirements
Challenges We Help Customers Address
- Every supplier receives the same questionnaire
- Critical suppliers have not been identified
- Supplier answers are accepted without evidence
- Security review occurs after the contract is signed
- Contract terms do not address cybersecurity
- Supplier access is broader than necessary
- Cloud-service responsibilities are unclear
- Subcontractors are not considered
- Findings are not tracked
- Suppliers are assessed once and never reviewed again
- Security incidents are not contractually reportable
- Service termination does not include access removal
- Business owners assume procurement owns all third-party risk
- Supplier questionnaires are excessively long
- Management lacks visibility of unresolved supplier risk
What Knowledge Kraft Delivers
Knowledge Kraft helps organizations establish a proportionate third-party security programme.
- Defining supplier-risk criteria
- Categorizing suppliers
- Identifying critical third parties
- Developing due-diligence questionnaires
- Defining evidence requirements
- Reviewing supplier security documentation
- Evaluating certifications and assessment reports
- Reviewing access and connectivity
- Reviewing information-sharing arrangements
- Assessing cloud and hosted services
- Reviewing business-continuity capability
- Evaluating incident-notification arrangements
- Developing contractual security requirements
- Conducting supplier interviews
- Conducting onsite or remote assessments
- Rating supplier risks
- Developing corrective-action plans
- Establishing risk-acceptance processes
- Tracking supplier actions
- Defining reassessment frequencies
- Developing termination and access-removal controls
- Preparing supplier-risk dashboards
- Training procurement and business owners
Legal and contractual language should be reviewed by appropriately qualified legal professionals before execution.
Frequently Asked Questions
Priority should be based on data access, connectivity, service criticality and potential business impact.
Not always. Higher-risk suppliers may require evidence review, interviews, audit reports or onsite assessment.
No. Certification can provide useful assurance, but the organization should still evaluate the specific service, scope and risk.
Yes. Assessments may review service responsibilities, security evidence, access, data location, resilience and incident processes.
Yes. Requirements can be proposed, subject to legal review.
Responsibility is normally shared among business owners, procurement, legal, IT and cybersecurity.
Frequency depends on risk, service changes, incidents, contract requirements and previous findings.
Yes. Remote or onsite audits can be performed against agreed criteria.