The Vendors of My Vendor’s Vendor … What? … Wait? … I’m Confused?!

It is no secret that vendor management is one of the top security challenges we face today. But what compounds the challenge is not knowing the relationships beyond our direct vendors. What are the vendors of my vendor doing?

I don’t know what I don’t know
The scenario: A recent project was initiated by the business group that would greatly improve our customers’ experience with us as well as streamline internal processes. Great! But, and I know this is common with any organization, the assigned managers involved on the project are not trained in project management and most certainly are not focused on security issues.

We have vendor management report into the risk department so we are fortunate to have security “eyes” on it but, in this case, the vendor did not disclose that additional relationships would be required. It turns out that the additional vendors would be involved in processing funds and documents containing sensitive data. Isn’t that interesting? Now the vendor’s vendor, the one processing funds, has a vendor for backups and is backing up the sensitive data. So, my data is three vendors away and the PMs are shrugging their shoulders.

We were fortunate because we did have time to do our due diligence on those additional third-parties, but we might not be so lucky the next time and could find ourselves in damage control.

Here are three actions that will help with the vendor management security struggle:

  1. Stay close to home. What I mean is focus and hold your direct vendor accountable for the other, now required, vendors. They most likely will resist and say, “You need to do your own due diligence.” I would suggest you respond that part of your due diligence is understanding how they selected that company to partner with and what vetting and security reviews were performed. If they didn’t review the vendor’s security controls, how confident are you in their controls?
  2. Tie due diligence to the money. Require that due diligence be complete before issuing the P.O. If you don’t have ownership over vendor management, this might be a challenge. But write in your vendor management policy the requirement that all due diligence be completed prior to finance issuing the P.O. Project managers will be more motivated to dot the Is and cross the Ts if they know that the project could be delayed.
  3. Follow the guidance. Whether or not you’re in a regulated industry, modeling your vendor management program off guidance from large agencies with a breadth of experience will make for a stronger structure. At the core of this guidance is governance. And make sure that whatever risk you assign to your vendors, you communicate it to management and the board.

Brian Nesgoda, CISSP, SVP Risk Management/CIO

[ISACA Now Blog]

Data Loss Threatens M&A Deals

One of the most popular breakout sessions at Evolution17 featured a great merger and acquisition (M&A) scenario: Midway through the deal, critical information leaks, devastating the value of the deal. How can you figure out how much info leaked—by whom and to whom?

Here’s why that storyline was so riveting: 2016 saw more than $3.5 trillion in M&A deals. And the vast majority of those deals revolved around valuations of intellectual property (IP), which today makes up about 80 percent of a typical company’s value. If you’re a buyer organization, consider these questions:

  • Are you aware of all the IP within the target company?
  • Can you be sure all this IP will come with the deal?
  • Can you be certain it won’t leak to a competitor?

Data loss is a growing M&A problem
For most buyers, the answers to the questions above are no, no and no. This lack of visibility and security for the very assets a company is buying is startling, and it’s increasingly impeding the success of M&A deals. A 2016 survey of dealmakers found that about three in four M&A deals end up getting delayed—sometimes indefinitely—by data loss. Those that eventually get back on track often end up hobbled by missing data. Experts say this is a big part of the reason that 80 percent of M&As fail to achieve their potential or expected value.

M&A amps up the insider threat
Data loss is increasingly common in M&A for the same reason it’s increasingly common throughout the business world: More than half of all enterprise data now lives on endpoints, beyond traditional visibility and security tools centered on a network drive or central server. If the target company can’t see what its employees are doing with data on their laptops and desktops, then a potential buyer has near zero visibility. Couple that with the unique circumstances of an M&A deal and you’ve got a much higher risk of insider data theft. Laid-off employees freely take their endpoint data—sometimes for personal gain, other times just to sabotage their former employer. Those that do stick around tend to feel little loyalty toward their new company, lowering their inhibitions toward selling or taking data for personal gain.

There’s a better way to protect IP during M&A deals
IP is what an acquiring company is buying—the info that is critical to the value and competitive advantage gained through a deal. To make the most of an M&A opportunity, buyers need a better way to collect, protect and secure all data living on a target company’s endpoints—before, during and after a deal. Fortunately, with the right tools, a buyer can gain complete visibility of all endpoint data, take control of valuable IP and drive a deal to its most successful outcome.

Don’t let data loss sink an M&A. Read our new white paper, Best Practices for Data Protection During Mergers and Acquisitions.

Jeremy Zoss, Managing Editor, Code42

[Cloud Security Alliance Blog]

Three Reasons Why Cybersecurity Certifications are Essential

Other than a college degree, how can you validate your knowledge and skills? Certifications represent a way for professionals to validate their knowledge and expertise, as well as a path for continued education and professional development.

But what about value? Why are cybersecurity certifications essential today? What is the value of a cybersecurity certification?

Proves Your Worth
According to the 2017 (ISC)² Global Information Security Workforce Study (GISWS), when respondents were asked for the reasons why their organization requires staff to have information security certifications, employee competence was the most common answer. You can spend years working to prove your knowledge, but a third-party validated measure of competence displays your expertise (i.e., your worth) to your employer, colleagues and peers in your network. Not only do certifications require the testing of one’s knowledge and skillsets, but many certifications also require continuing professional education credits to ensure that the learning process doesn’t stop once certification is obtained. Certification also proves a candidate’s commitment to their respective profession – if they are dedicated enough to study for a lengthy exam and go through the entire certification process, that exemplifies commitment.

Instant Street Cred
Certifications are often difficult to obtain. Many people spend hours, weeks, even months studying for certification exams. When your managers and colleagues know that you’ve been validated by a third-party organization as having certain knowledge and skills by passing a tough exam, you earn credibility. When hiring managers are making decisions for staffing, 70 percent of GISWS respondents said it was at least somewhat important that the candidate has information security certifications. When asked if their organization requires its IT staff to have information security certifications, 40 percent said yes.

Catapults Your Career
Once you’re hired, you’ll probably start to think about career advancement and how to get to the next level. As part of the GISWS survey, respondents who hold certifications were asked how relevant their current certifications are to their potential career advancement. An incredible 90 percent of respondents said they are at least somewhat relevant. Members of (ISC)² (certification holders) also make a higher average annual salary than those who are not members – $103,000 for members compared to $76,300 for nonmembers. With certain certifications being required to obtain cybersecurity positions, it’s no wonder that they can be the way in the door and up the ladder.

Attaining certifications can be a key component in planning for and building a successful, well-respected career in cybersecurity. Certifications will show your value as a cybersecurity professional by helping to prove your worth as an employee, show street cred as a team member, and catapult your career, setting you up for a lifetime of success.

Validate your expertise and show your boss you have what it takes to protect your organization with a globally recognized (ISC)² certification. Choose which certification is right for you and download The Ultimate Guide.

[(ISC)² Blog]

English
Exit mobile version