
Autor: Nermin Sefić
Nermin Sefić analyses third-party cyber resilience, key controls, and practical consequences for suppliers.
The weakest point in a system is often an external service whose capacity, security, and recovery plan haven't been verified.
A company can secure its own network well and still lose a key function because of an incident at a supplier, platform, or data centre.
Third-party assessment must link security controls to business consequence: which process stops, how long it can stay down, and whether an alternative way of working exists.
The contract must include incident notification, evidence availability, recovery deadlines, data ownership, and an executable exit plan.
A backup supplier isn't a real backup until it's technically tested and contractually activated.
This publication is an original analysis; the sources cited serve as reference documentation.
#ThirdPartyRisk #CyberResilience #Suppliers #BusinessContinuity #NerminSefic #GNKASG #GNKDINAMOLtd
Cjelovit tekst i izvor: https://gnk-asg.hr/en/publications/cyber-resilience-and-third-party-suppliers/
Autor i urednička odgovornost: Nermin Sefić. Izdavač: GNK ASG d.o.o..
#GNKASG #GNKDINAMOLtd #NerminSefic #BusinessIntelligence #NerminSefić #GNKASGdoo #Zagreb