CISO Inquiry Community Write-up
Management and Leadership

Conducting Fourth-Party Breach Due Diligence

IANS

A CISO in the lending and brokerage industry asks: We received a breach notification from a vendor regarding a compromise of one of their suppliers (fourth party to us). Even though the party is a non-critical supplier to our vendor, our vendor states it engaged an independent forensic security firm to determine precisely what was accessed in the supplier's environment.

  • Who else goes to this extent in their standard protocols?
  • Do you believe you have contractual provisions to support that course of action?

Complete the form and we'll send the summary to your email.