CISO Inquiry Community Write-up
Management and Leadership
Conducting Fourth-Party Breach Due Diligence
IANS
A CISO in the lending and brokerage industry asks: We received a breach notification from a vendor regarding a compromise of one of their suppliers (fourth party to us). Even though the party is a non-critical supplier to our vendor, our vendor states it engaged an independent forensic security firm to determine precisely what was accessed in the supplier's environment.
- Who else goes to this extent in their standard protocols?
- Do you believe you have contractual provisions to support that course of action?
Complete the form and we'll send the summary to your email.
Find similar resources
Ask-An-Expert Call Summary
Infrastructure
Developing a Practical, Scalable Security Road Map for OT and ICS
A practitioner's guide to prioritizing segmentation and resilience in ICS environments—for security leaders who need a roadmap the operations team will actually support.
IANS
Ask-An-Expert Call Summary
Management and Leadership
Presenting Impactful IAM and PAM Metrics to Executive Leadership and the Board
How to translate identity and access data into production downtime risk and financial impact—so executives see the cost of stopped, not a security dashboard.
IANS
We use cookies to deliver you the best experience on our website. By continuing to use our website, you consent to our cookie usage and revised Privacy Policy.