Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Ariel Evans, Ajay Singh, Alex Golbin

Rating No ratings yet

The book is essential reading for CISOs, DPOs, CPOs, Sourcing Managers, Vendor Risk Managers, Chief Procurement Officers, Cyber Risk Managers, Compliance Managers, and other cyber stakeholders, as well as students in cyber security.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Navigating Supply Chain Cyber Risk: A Comprehensive Guide to Managing Third Party Cyber Risk ## 【One-Line Pitch】 A practical, executive-level playbook for building and running a third-party cyber risk management (TPRM) program, grounded in real breach case studies and regulatory requirements. Essential reading for CISOs, vendor risk managers, compliance officers, procurement leaders, and anyone accountable for supply chain security. ## 【Book Arc】 - **Opening (~0%–10%)**: Establishes why third-party cyber risk is now a board-level crisis—digital assets have grown from 10% to over 85% of business assets since 2001, and third-party breaches cost roughly three times more than on-premise incidents. Sets up the core questions every organization must answer: how much exposure exists, which vendors pose the greatest financial risk, and how to prioritize remediation. - **Early (~10%–32%)**: Classifies vendor types (SaaS, PaaS, IaaS, service providers) and walks through landmark supply chain attacks—Target, Home Depot, NotPetya, CCleaner, SolarWinds, Colonial Pipeline, GitHub, and Airbus—to extract lessons about attack vectors and the "perfect storm" conditions that enable them. Introduces the challenges of vendor risk management, including automated scanning tools and IT asset scanners. - **Middle (~32%–48%)**: Dives into the regulatory landscape: HIPAA, PCI DSS, NAIC, CCPA, NYDFS Part 500, and DFARS. Explains who is covered, what compliance requires, and how penalties accumulate—including the sobering detail that a single lost laptop with 500 records counts as 500 separate HIPAA violations. - **Late (~48%–75%)**: Moves to building the actual TPRM program: preparation, due diligence, risk assessments, vendor risk quantification, policy and procedure development, and internal versus third-party audits. Emphasizes that vendor selection must not be left to the business alone—cyber must have a seat at the contracting table. - **Ending (~75%–100%)**: Looks forward to the future of vendor cyber risk management, including the autonomous economy, and includes an appendix with interagency guidance on third-party relationships. ## 【Key Takeaways】 - **Third-party breaches are disproportionately costly** (Early): A vendor-related data breach costs roughly three times more than an on-premise breach, making supply chain risk a financial issue, not just a technical one. This justifies investment in TPRM programs. - **Vendor classification drives risk strategy** (Early): Cloud service providers (SaaS, PaaS, IaaS) differ fundamentally from consultants or attorneys—each type carries different risk profiles and requires different assessment depth. A one-size-fits-all approach fails. - **Real-world breaches reveal recurring patterns** (Early): From NotPetya's software update compromise to SolarWinds' months-long undetected access, attackers consistently exploit the trust between organizations and their vendors. These case studies are the best argument for proactive vendor oversight. - **Automated scanning closes the questionnaire gap** (Early): Security questionnaires can be answered using automated scanning software with self-service portals for evidence upload. IT asset scanners reveal concrete gaps—missing EDR, outdated systems, unmapped PII, absent MFA—that self-reported answers often miss. - **Regulatory penalties escalate quickly** (Middle): HIPAA violations multiply per record and per day of non-compliance, with state attorneys general able to add $25,000 per violation plus legal fees. The same pattern of compounding liability appears across CCPA, NYDFS, and other regulations. - **Contracts are a critical control point** (Middle): The book recounts a vendor contract that disclaimed all breach responsibility—and the company signed it. Contractual language must mandate 72-hour breach notification, incident response plans, and clear liability allocation. - **Vendor inventory is the foundation** (Middle): Knowing who your vendors are is not enough—you must know what type of vendor each is and what functions they serve. Salesforce, for example, is both a cloud service and a system vendor, requiring different risk lenses. - **Frameworks provide structure but require interpretation** (Middle): NIST and ISO assessments should be reviewed in depth, but all frameworks ultimately aim at the same triad—administrative, technical, and physical safeguards supporting confidentiality, integrity, and availability. ## 【Reading Tips】 - **Skim the case study chapter** (Early) for the narrative arc of each breach—the technical details matter less than the pattern: attackers exploit vendor trust, and the damage is often out of proportion to the initial entry point. - **Deep-read the regulatory chapters** (Middle) if you operate in healthcare, financial services, or defense—the penalty structures and coverage definitions are the most actionable content in the book. - **Pay special attention to the contract language discussion** (Middle): The anecdote about the vendor contract that disclaimed all responsibility is a cautionary tale that every procurement and legal stakeholder should internalize. - **The program-building chapters** (Late) are where practitioners will find the most value—preparation, due diligence, and audit sections translate directly into operational checklists. - **If you are new to TPRM**, start with the opening chapters to build the business case, then jump to the program-building section; return to regulations as needed for your specific industry. ## 【Coverage Limits】 The excerpts cover the book's structure and key themes but do not include full detail on the later program-building chapters (risk quantification, internal audit, third-party vendor audit) or the future perspectives section. Specific regulatory penalty charts and framework comparisons are referenced but not fully reproduced in the source material. ##
Page 13
Companies, including global systemically important banks. In one of his prior roles Alex led a Vendor Risk Assessments business (as part of a joint venture...
View in text
Excerpt 2
ers – A third‑party organization that provides services to the company. Examples include lawyers, accountants, doctors, IT compa‑ nies, management consultan...
View in text
Excerpt 3
to support information that needs to be provided manually. IT Asset Scanners can provide a view of cybersecurity readiness. Gaps are identified based upon t...
View in text
Excerpt 4
olation; they did not act with willful neglect the breach. and could not reasonably have known about the breach. $120-$60,226 per violation $1,205-$60,226 ...
View in text
Excerpt 5
eria: • Has a gross annual revenue greater than $25 million • Trades or receives personal information of at least fifty thousand California consumers, house...
View in text
Excerpt 6
ompanies working with the DoD and other federal government agencies as defense contractors are privy to confidential information. DOI: 10.4324/978100358132...
View in text
Excerpt 7
to financial applications and financial data aggregators.6 The standard was backed by some of the largest financial data aggregators, numerous banks, and t...
View in text
Excerpt 8
gram needs to be formed and what are the key objectives? 2. Does my manager’s overall responsibility align with the key objectives of the program? 3. Who a...
View in text
Tags
AI categories
CybersecurityBackendCloud Native
Publisher: Routledge
Publish Year: 2023
Language: English
File Format: PDF
File Size: 5.2 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…