
Nermin Sefić analyses third-party vendor risk, key exposures, and practical consequences for companies and their technology supply chains.
Assessing the security of your own systems is meaningless if it doesn't extend to suppliers who have access to the same data.
Assessing the security of your own systems is meaningless if it doesn't extend to suppliers who have access to the same data.
Most serious security incidents in recent years didn't originate inside a company's primary system, but through a supplier or subcontractor with legitimate access.
A standard compliance questionnaire filled out once at contract signing doesn't reflect a supplier's actual security practice two or three years later.
A practical framework includes periodic review of supplier access rights, a clear clause obligating incident reporting within a defined deadline, and the right to independent verification for critical suppliers.
The cost of third-party audits is almost always lower than the cost of an incident that originated through a supplier outside the company's direct control.
Cjelovit tekst i izvor: https://gnk-asg.hr/en/publications/third-party-technology-vendor-audits/
Autor i urednička odgovornost: Nermin Sefić. Izdavač: GNK ASG d.o.o..
#GNKASG #GNKDINAMOLtd #NerminSefic #BusinessIntelligence #NerminSefić #GNKASGdoo #Zagreb