Vendor / third-party risk management
In one sentence
Knowing which outside companies can reach your systems or data, and holding them to security expectations.
Vendor risk management means keeping an inventory of third parties with access, doing proportionate diligence (do they enforce MFA? encrypt your data?), and putting breach-notification terms in contracts.
Why it's on your cyber insurance application
A named and growing application area; a one-page vendor inventory answers most of it at SMB scale.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Vendor & third-party risk
Do you review the security of vendors who access your systems or data?
Why carriers ask: Third-party breaches account for a large share of incidents. Applications increasingly ask how you vet vendors with access to your data.
If the answer is no: Start with the inventory: every vendor with system or data access, what they touch, and whether they have MFA. Ten vendors, one page, one hour.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
Guides that cover this
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.