Skip to main content

Third-Party Cyber Security Vendor Management

Typing on a laptop which is infected by a virus.

Many companies outsource the management and control of all or some of its information systems, networks or data storage to service providers and cloud-based services including ISP providers, hardware, software and firmware vendors and others who perform services on behalf of their company and may have access to sensitive data or systems.

From a business risk standpoint, third-party services may always be considered vulnerable. As a result, it is a best practice to develop a formal written process for selecting and managing third-party contractors and services. Some risk control considerations and best practices include:

General considerations for selecting contractors or service providers

  • Conduct and obtain enough background information, e.g., independent reviews, surveys and reports, to get a better understanding of their advertised services/operations.
  • Obtain references from other customers or organizations, for example, from the Better Business Bureau.
  • Evaluate their financial stability.  
    • Is this an established company or a start-up?
    • Do they have adequate financial solvency to provide long-term support?
    • Are they knowledgeable about your general and industry-specific security and compliance requirements?
    • Do they have any industry or security certifications?
  • Assess their capabilities and policies for protecting your data (both physically and procedurally).
  • Evaluate the credentials and qualifications of the personnel specifically assigned to your contract.
    • Do they have the technical expertise to complete the project or service?
  • Determine what security background checks are conducted of the personnel who will have access to your information and how often.
  • Confirm they can provide an acceptable level of customer technical support.
    • If required, can they provide 24/7 support 365 days a year?
  • Determine if they will handle all portions of your contract or if they intend to sub-contract with other companies.
    • Describe any services they will sub-contract.
    • If they sub-contract to others, verify they are assuming responsibility for ensuring their sub-contractors comply with all of your security requirements.
  • Confirm they are knowledgeable of, and in compliance with, all legal and regulatory requirements.
  • Ask them to describe their cyber incident response plan.
    • In the event they experience a breach, what is their process for investigating, responding to and notifying your company?
    • Ask them to describe their history of cyber security incidents, how they were handled and improvements they made to minimize reoccurrence.
  • Ask them to describe their business continuity capabilities.
    • Do they have a written plan? Is it updated and practiced at least once a year? Do they have redundant systems and/or data storage sites?
    • How quickly can they resume normal operations in the event of a failure at one location?  

Contract management and risk transfer

Some risk control considerations and best practices include:

  • Specify the individuals within your company who have the authority to make or approve changes to contract provisions and insurance requirements.
  • Review of all contracts s by your legal counsel including hold harmless, indemnification, and defense clauses to help protect your company’s interests.
  • Use written contracts when outsourcing the management and control of all or some of company information systems, networks or data storage to service providers, contractors or cloud-based services. All contracts should be agreed to and signed before beginning the work or service.
  • Specify requirements for insurance coverages to help confirm the contractor or service provider is financial able to pay for damages resulting from a cyber breach for which they are responsible, including limits, additional insured status, written notice of cancellation clause, etc. Your insurance agent may be able to provide assistance.
  • Obtain Certificates of Insurance (COIs) annually from the contractors or service providers and to help confirm that they continue to match the insurance specifications specified in your contracts.  

 Data security requirements

Data security requirements, which can be incorporated in contract provisions, can include acceptable use agreements that limit how the third party may access or use sensitive data and systems, and disciplinary consequences for noncompliance. Some data security requirements to consider include:

  • Minimum qualifications and certifications of personnel who are working on the project or service, including security background checks for any personnel having access to sensitive data or critical systems.
  • A current list of individuals authorized to access your system or data and a requirement that the contractor is responsible for properly protecting and controlling their administrative privileges. The list should be promptly updated if changes are made.
  • Strong password controls. Require individuals with access to use a password that is unique to your company and not shared with any third-parties.
  • Secure channels using strong encryption for all remote administration of your network and similar equipment.
  • Specifications on the required timelines of the release for contracted services that include upgrades, patches, etc., as well as how it is handled and who is responsible.
  • Contractors responsibility for its subcontractor’s compliance with all security requirements and all legal and regulatory requirements.
  • Company ownership and intellectual property rights for work produced by contractors in support of your business. Consult with legal counsel to determine appropriate, steps to preserve these rights.
  • Restrictions on access to types of information or systems by the contractor and its subcontractors.
  • Protecting the confidentiality and integrity of the data in their care and custody by contractors. Confidentiality clauses and nondisclosure agreements (NDAs) may be required. Consult with your counsel for advice on the use of confidentiality clauses and NDAs if concerned with protection of sensitive and/or proprietary information.
  • Restrictions on copying, storing or transmission of data.
  • The return or destruction of information and assets at the end of the contract or job.
  • Physical security and access controls for the contractor or service provider to restrict access to authorized users only on their site.  

Business continuity requirements

Some business continuity requirements to consider, include:

  • Acceptable level of customer technical support they must be able to provide, such as response time, time period available per day or days open per week.
  • The maximum amount of response time allowed to replace or restore your critical equipment, applications, software or services in the event of physical damage or cyber breach.

Incident response requirements

Some incident response requirements to consider include:

  • Notification to your company within an agreed timeframe of any security incidents that may impact the security of your information, systems or services.
  • Promptly response and assistance as needed in support of your incident investigation and recovery efforts in the event of a security incident.  

Cloud-based services

Cloud-based services may be advantageous due to their scale and in-house expertise.  They may be able to provide a larger storage capacity and higher level of security than the companies they are providing services for.  Also, cloud-based storage systems can serve as a remote backup site, which may be more secure than an onsite storage solution in the event of a fire, water intrusion or natural disaster.

Cloud storage can also experience data breaches and accordingly, it is best to specify your security requirements for all sensitive data transmitted to or being stored in cloud storage, for example, requirements for encryption. Also, verify how the provider achieves isolation and avoids access or commingling of your information with other information being stored.

 Audits

The right to conduct audits can help you to ensure that your contractors are diligent in the services they provide to protect your data. Consider:

  • Specifying the frequency and level of security audits to be conducted, including self-audits or certified third-party audits, and the audit report details required.
  • Including a requirement for third parties that store your sensitive data that they record all authorized access to the data and any unauthorized attempts to access the data. Information such as the date, timestamp, source address, etc., should be logged and provided to you in scheduled reports. See the Travelers Risk Control article Network Logging and Monitoring for more information.

Open source software – a caution

Open-source software or proprietary programs that contain open-source software components can potentially present significant risk because, contrary to common misconceptions, most open source software is still subject to licensing agreements, imposing specific obligations on anyone who uses, modifies or distributes the code. If the open-source software developers disclaim responsibility associated with the software, the user may be responsible for any claims that the software violated third-party copyrights, patents or other intellectual property rights.

Related resources

Cyber Risk Management - Getting Started - Establishing a Security Baseline

This article discusses the importance of management commitment as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

The Cyber Security Team

Learn about the importance of a security team as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Cyber Security Policies

This article discusses the importance of security policies as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.