Share E-Book

AuthorAriel Evans, Ajay Singh, Alex Golbin

The book is essential reading for CISOs, DPOs, CPOs, Sourcing Managers, Vendor Risk Managers, Chief Procurement Officers, Cyber Risk Managers, Compliance Managers, and other cyber stakeholders, as well as students in cyber security.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

Passage locations
Tags
No tags
Publisher: Routledge
Publish Year: 2023
Language: 英文
File Format: PDF
File Size: 5.2 MB
Support Statistics
¥.00 · 0times
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

(This page has no text content)
“In a world where cyber risks are ever‑evolving, Navigating Supply Chain Cyber Risk by Ariel Evans, Ajay Singh and Alex Golbin emerges as a vital resource. This book provides a clear and comprehensive roadmap for understanding, mitigating, and responding to third party cyber risks. Whether you’re a seasoned security professional or just starting out, Evans, Singh and Golbin’s insightful guidance empowers you to navigate the complex digital landscape. Here’s what particularly impressed me: • Practical and actionable: Navigating Supply Chain Cyber Risk goes beyond theory, offering practical steps and real‑world examples to fortify your defenses. • Accessible and engaging: The writing style is clear and engaging, making complex topics understandable for a broad audience. • Comprehensive coverage: This book delves into a wide range of third party cyber risks, from data breaches to malware attacks, providing a holistic view of the threat landscape. If you’re looking to build a resilient and secure digital environment, Navigating Supply Chain Cyber Risk is a must‑read.” Dr. Yoav Intrator, Chief Product Officer, RiskQ “In an era where digital threats loom large over the intricate web of global supply chains, Navigating Supply Chain Cyber Risk emerges as a beacon of insight and practical wisdom. This book makes essential reading for anyone looking to navigate the complex intersection of supply chain management and cybersecurity. With its clear explanations, real‑world examples, and actionable strategies, it equips professionals with requisite tools to protect their critical operations against cyber threats. A timely and valuable contribution to the field.” Nagendra Aswatha, Asst. Professor, Operations & Supply Chain Management
(This page has no text content)
NAVIGATING SUPPLY CHAIN CYBER RISK Cybersecurity is typically viewed as the boogeyman, and vendors are responsible for 63% of reported data breaches in organisations. And as businesses grow, they will use more and more third parties to provide specialty services. Typical cybersecurity training programs focus on phishing awareness and email hygiene. This is not enough. Navigating Supply Chain Cyber Risk: A Comprehensive Guide to Managing Third Party Cyber Risk helps companies establish cyber vendor risk management programs and understand cybersecurity in its true context from a business perspective. The concept of cybersecurity until recently has revolved around protecting the perimeter. Today we know that the concept of the perimeter is dead. The corporate perimeter in cyber terms is no longer limited to the enterprise alone, but extends to its business partners, associates, and third parties that connect to its IT systems. This book, written by leaders and cyber risk experts in business, is based on three years of research with the Fortune 1000 and cyber insurance industry carriers, reinsurers, and brokers and the collective wisdom and experience of the authors in Third Party Risk Management, and serves as a ready reference for developing policies, procedures, guidelines, and addressing evolving compliance requirements related to vendor cyber risk management. It is unique since it provides strategies and learnings that have shown to lower risk and demystify cyber risk when dealing with third and fourth parties. The book is essential reading for CISOs, DPOs, CPOs, Sourcing Managers, Vendor Risk Managers, Chief Procurement Officers, Cyber Risk Managers, Compliance Managers, and other cyber stakeholders, as well as students in cyber security. Ariel Evans is a senior cybersecurity expert, serial entrepreneur, and award‑winning author. She is the chairperson of the cybersecurity continuing education programs at Seton Hall University and Pace University and has been on the front lines of cybersecurity as a former CISO, and Cyber Risk Manager. Ajay Singh is a Professor of Practice, corporate advisor, Fellow at the Institute of Directors, Former CEO, and award‑winning author.
Alex Golbin is a Senior Financial Services Executive with over two decades of leading Risk Management, Enterprise Resiliency, Operations and Technology Transformation, Global Technology, Business Process Improvement, and leveraging state‑of‑the‑art technology.
NAVIGATING SUPPLY CHAIN CYBER RISK A Comprehensive Guide to Managing Third Party Cyber Risk Ariel Evans, Ajay Singh and Alex Golbin
Designed cover image: Suphanat Khumsap / iStock / Getty Images Plus First published 2025 by Routledge 4 Park Square, Milton Park, Abingdon, Oxon OX14 4RN and by Routledge 605 Third Avenue, New York, NY 10158 Routledge is an imprint of the Taylor & Francis Group, an informa business © 2025 Ariel Evans, Ajay Singh and Alex Golbin The right of Ariel Evans, Ajay Singh and Alex Golbin to be identified as authors of this work has been asserted in accordance with sections 77 and 78 of the Copyright, Designs and Patents Act 1988. All rights reserved. No part of this book may be reprinted or reproduced or utilised in any form or by any electronic, mechanical, or other means, now known or hereafter invented, including photocopying and recording, or in any information storage or retrieval system, without permission in writing from the publishers. Trademark notice: Product or corporate names may be trademarks or registered trademarks, and are used only for identification and explanation without intent to infringe. British Library Cataloguing‑in‑Publication Data A catalogue record for this book is available from the British Library ISBN: 978‑1‑032‑94762‑4 (hbk) ISBN: 978‑1‑032‑94761‑7 (pbk) ISBN: 978‑1‑003‑58132‑1 (ebk) DOI: 10.4324/9781003581321 Typeset in Joanna by codeMantra
About the Authors ix Preface xiii Acknowledgments xv Part I The Case for Supply Chain Cyber Risk Management 1 1 The Extended Enterprise 3 2 Know Your Supply Chain 9 3 Notable Supply Chain Cyber Events 16 4 Challenges in Vendor Cyber Risk Management 32 Part II Vendor Cyber Risk Management – Regulations and Compliance 39 5 Vendor Cybersecurity Regulations 41 6 HIPAA and Vendor Cyber Risk Management 58 7 General Data Protection Regulation (GDPR) 65 CONTENTS
Contentsv i i i 8 California Consumer Privacy Act (CCPA) 70 9 New York State Department of Financial Services (NYDFS) Part 500 78 10 Defense Federal Acquisition Regulation Supplement (DFARS) 86 11 Frameworks and Certifications 92 12 Attestations and Assessment Utilities 106 13 SOC 2 Report 115 Part III Building the Vendor Cyber Risk Management Program 123 14 Preparation 125 15 Due Diligence 133 16 Risk Assessments 142 17 Vendor Risk Quantification 149 18 The Role of Policy and Procedure 153 19 Internal Audit 167 20 Third‑Party Vendor Audit 174 Part IV Future Perspectives in Vendor Cyber Risk Management 183 21 The Way Forward 185 Appendix: third‑Party Relationships: Interagency Guidance on Risk Management 203 Index 209
ABOUT THE AUTHORS Ariel Evans  is a senior cybersecurity expert, serial entrepreneur, and award‑winning author. Ariel is a professor at Pace University and leads an advisory board of over 170 CISOs, CTOs, CIOs, DPOs, Cyber Attorneys, and Insurance Firms in research into Cyber Risk Management. Her books and courses are based upon seven years of research with the Fortune 1000 and cyber insurance industry. Ariel is the pioneer of the digital asset approach to cyber risk. Her most recent product company, RiskQ has patented the digital asset approach and created a cyber risk quantification platform called ValuRisQ for or‑ ganizations, InsurQ for insurance companies, and RadarQ for IT asset management. She also founded in 2018, Cyber Intelligence 4U (CIU). CIU is a cyber education services company that provides leading courses for universities, organizations, and individuals focused on filling the gaps in traditional ed‑ ucation that are needed to meet the challenges of the digital age. CIU works with Pace University, Seton Hall University, Rutgers University, ISACA, and others. Over 4000 students have gone through the programs in 2018. Cli‑ ents include Verizon, AM Best, Citibank, and a host of others. She has won numerous awards including the EU Commission award for Innovation in cyber risk and Gartner Cool Vendor in Privacy Management. Formerly, she was a founder of two software companies in the United States that were spun and sold to BMC and elance.com, a Kleiner Perkins
ABOuT ThE AuThORSx company. Additionally, she was the Acting Chief Information Security Of‑ ficer for a Telco subsidiary in the United States and was responsible for the establishment of the Information Security division, from the very ini‑ tial stage of defining the security and compliance requirements to the as‑ similation of IT security and compliance programs across the firm. She was accountable for IT security policies and procedures, governance and standardization of all security and compliance‑related IT activities and risk management. Ariel has sat on the board as a cyber expert for several companies. Her insight into regulation, governance, and business connectivity technol‑ ogy allows Ariel to provide expert guidance to the Department of Home‑ land Security, the Payment Card Industry and other governing bodies that are accountable for reducing risk and ensuring secure financial, medical and personal data. Ariel is the primary author of the PCI Security Council e‑commerce guidelines issued in January of 2013. Ariel has her undergraduate degree in Nuclear Physics and her M.B.A. from New York University’s Stern School of Business. Books Managing Cyber Risk  –  A Cyber Risk Managers’ Handbook, ISBN‑13: 978‑0367177737. Bit.ly/ ArielEvans. Enterprise Cybersecurity in Digital Business;  –  Building a Resilient Organization. ISBN‑13: 978‑ 0367511494. https://amzn.to/39CvR7h. Awarded Top 30 Cybersecurity Books you should read in 2024. Cybersecurity and AI for Business: in development. Articles Contributor to the Cybersecurity Law Review. How CISOs Can Use Digital Asset Metrics to Tell a Coherent Cyber Story to the Board. How Much Cyber Insurance to Buy Based on How Claims Are Paid. Media Women in Cyber Interview: https://crri.us/international‑women‑in‑cyber‑ariel‑ evans/?fbclid=IwAR0OadPlBkZrKQ6M4oKV01kVz9gc1oRJB_d3Br22wiUgm Zfp0ZeBDRP8JjU.
ABOuT ThE AuThORS x i Task Force 7 Radio (Top 10 podcasts): https://www.voiceamerica.com/guest/44210/ ariel‑evans. The James Bohannon Show: http://www.jimbohannonshow.com/2018/03/15/ wednesday‑march‑14‑2018/. I24 News interview on GDPR and Cyber Risk: https://www.youtube.com/watch? v=LfctYo2Wyw4&t=34s. Memberships and Chairs Chairperson of the Pace Academic Advisory Board‑Pace University‑Seidenberg School of Computer Science and Information Systems, New York. Chairperson of the Seton Hall Academic Advisory Board‑Pace University‑Seidenberg School of Computer Science and Information Systems, New Jersey. Member of the International Association of Privacy Professionals (IAPP). Member of the Information Systems Audit and Control Association (ISACA). Member of the Cloud Security Alliance (CSA). Ajay Singh is Professor of Practice, corporate advisor, Fellow at the Institute of Directors, former CEO, and award‑winning author. Memberships Member of IEEE Committee on Cyber Security for Next Generation Connectivity Systems. Member of the Academic Advisory Board‑Pace University‑Seidenberg School of Computer Science and Information Systems, New York. Books Cyber Strong: A Primer on Cyber Risk Management for Business Managers (2020): This book was recognized as an Award‑Winning Finalist at the International Book Awards by the American Book Fest in 2022. An Entrepreneur’s IOD Handbook on Cyber Security (2021): A condensed guide tailored for corporate professionals and executive management. Cybersecurity‑Concepts, Principles, Technologies, and Practices (2023): This work has received the prestigious Golden Book Award in 2024. Cyber Strong: Cybersecurity and Risk Management (2023). Cyber Shock: Cyber‑Attacks that Shook the World (2024). An exploration of significant cyber incidents and the lessons we can learn from them.
ABOuT ThE AuThORSx i i Alex Golbin is a senior financial services executive with over two decades of leading Risk Management, Regulatory Remediation, Enterprise Resiliency, Operations and Technology Transformation, Global Technology, Risk and Control Functions, Data, Business Process Improvement, and leveraging state‑of‑the‑art technology. Alex’s current and prior roles included leadership responsibilities in numerous globally recognized Fortune 500 Companies, including global systemically important banks. In one of his prior roles Alex led a Vendor Risk Assessments business (as part of a joint venture with 16 Banks and Financial Services companies) to improve operational resilience, regulatory compliance, and cost. He has successfully led the enablement of multiple global industry consortiums, industry risk management & cybersecurity frameworks, and the establish‑ ment of strategic industry partnerships. Memberships Member of the Information Systems Audit and Control Association (ISACA). Member of the Project Management Institute (PMI). Member of the Academic Advisory Board‑Pace University‑Seidenberg School of Computer Science and Information Systems, New York. Certif ications Project Management Professional (PMP). Certified Data Privacy Solutions Engineer (CDPSE). Certified Information Security Manager (CISM). Alex has an MBA from NYU Stern in Finance and Management, BS in Computer Science. He serves on multiple advisory boards as an expert in cybersecurity, risk management, and technology.
Cybersecurity is the number one business risk according to Forbes. Seventy percent of data breaches are due to third parties. As a result of this interdependency between organizations and their vendors, we are writing this book to help organizations address this urgent need to evaluate their supply chain and understand the potential cyber consequences for each of their third parties. The security of a company is only as strong as its weakest link. Over the past five years there has been an emphasis on understanding the role that third parties play in cybersecurity. Not only what role they play, but also an increase in focus from regulatory bodies. Today, almost every cybersecurity, privacy, and industry regulation has language that addresses the requirements of the third party. This book is written as a comprehensive guide to understand, manage, and mitigate third‑party cyber risks. It will provide you with the knowledge and tools you need to protect your organization’s supply chain regardless of if you have an existing program or are you just starting from scratch. We begin the book, providing background research into the impacts, and  trends, using case studies and examples to embed your learning experience. We follow that up with regulatory data that is critical to understanding the requirements your company faces with third parties. We then begin the how‑to section that walks the reader through preparation, due diligence, policies, risk quantification, risk scoring, and audit. PREFACE
PREFACEx i v We summarize our thoughts on the future in the way forward focusing on AI. Cyber risk management is a journey without a destination. We will always have cyber risk. It is a journey of managing it with the best chances of success. May your journey be one of wonder, growth, and resilience.
ACKNOWLEDGMENTS No book writes itself and no author can share knowledge without standing on the shoulder of giants. We wish to express our heartfelt thanks and appreciation to our colleagues, friends, researchers, and mentors who have helped us to frame our thoughts and complete this book. A special thanks to all two hundred members of the Pace Seidenberg Cybersecurity Advisory Board, whose amazing collaboration has helped to make this book possible. There are too many of you to thank individually. A hearty thanks to Dean Jonathan Hill from Pace University’s Seidenberg School of Computer Science and Information Systems. From the team: We are all passionate about supply chain cyber risk, being on both sides of the equation and seeing the struggle over the past several years to have strong programs to understand the cyber risks, program requirements, and regulations. This book is meant to move people forward, faster based on our work in this area. From Ariel: I cannot forget to triple thank my husband again and again. Doctor Yoav Intrator who is bar none an expert in technology innovation, AI and in all things cyber and whose example propels me to excel, for his support, wisdom, and his unconditional belief in love in me. You are my rock. From Alex: It was an exciting journey to publish this book, to distill nuances and complexity of this most important and complex risk to the
ACKNOwLEDGMENTSx v i industry. As part of the creative experience, I appreciated the friendship and bond I formed with my two co‑authors, learning from each other, and making something that we can all be proud of. I want to especially thank my family Alice, Abigail, and Aaron for supporting me during this journey, the countless weekends of calls, writing, and blabbering about obscure topics around cybersecurity. From Ajay: Collaborating with Ariel and Alex on this book was incredibly rewarding. We brought diverse expertise to the table, and our brainstorming sessions sparked innovative ideas. The camaraderie and shared passion for our topic made the process enjoyable. A special thanks to my lovely wife, Sangeeta for her unwavering support. We hope you find this book useful.
Part I THE CASE FOR SUPPLY CHAIN CYBER RISK MANAGEMENT
(This page has no text content)
DOI: 10.4324/9781003581321-2 Introduction In 2018, Dr. Yoav Intrator, the former CEO of JPMorgan Chase Israel, pub‑ lished a paper titled “An Autonomous Economy: Coming Sooner Than You Think.”1 The paper focused on how responsibilities are shifting from human to machine and was the first to formally define autonomous econ‑ omy (AE) as an IT‑driven economy. In the AE paper, he identified four key barriers, Trust, Supply Chain, Regulation, and Platform to reach an autonomous state. He also referred to them as frictions, since on the surface they slow us down in moving from an IT‑enabled economy to an IT‑driven economy. However, at the same time, they are innovation triggers which drive innovation; social, technological, and economic frictions stimulate invention. This book will explore one of these frictions, supply chain, from a cyber risk perspective and the risk it poses as an extended enterprise. In the past few years, we have observed how the four identified frictions are being amplified. The increase in fake news erodes our trust, and the emerging 1 THE EXTENDED ENTERPRISE