Skip to Content
Cybersecurity and Third-Party Risk
book

Cybersecurity and Third-Party Risk

by Gregory C. Rasner
July 2021
Intermediate to advanced
480 pages
9h 38m
English
Wiley
Content preview from Cybersecurity and Third-Party Risk

Chapter 15Transform to Predictive

The statistics on the number of firms who do not perform adequate third‐party due diligence are astounding. Surveys on this subject by such groups as Ponemon Institute routinely find that fewer than 55 percent of businesses have a vendor risk management program and an even fewer percentage of them perform any cybersecurity risk assessments. These programs are shown to be in desperate need, given the level of security incidents and breaches detailed in the Chapter 1. Those businesses with robust programs that view cybersecurity as a key risk domain have the ability to change the timing of some of their risk reduction.

All the due diligence activities described in the previous chapters have focused on either point‐in‐time assessments or Continuous Monitoring (CM). The steps outlined in those chapters articulate and describe the actions needed to start programs or improve upon existing ones. Engaging vendors in conversations and building relationships with them increase transparency and enable both businesses and their vendors to collectively work on reducing risk Such activities produce a lot of data, which is often just sitting there unused, unless it is needed for another due diligence or due care activity. This valuable information, however, can provide instructions on where risk really is located when a business is able to look at such data in an aggregate and holistic way.

In addition, engagements with the vendors are largely reactive as ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Cybersecurity Risk Management

Cybersecurity Risk Management

Cynthia Brumfield, Brian Haugli
Building a Cyber Risk Management Program

Building a Cyber Risk Management Program

Brian Allen, Brandon Bapst, Terry Allan Hicks

Publisher Resources

ISBN: 9781119809555Purchase Link