Re-thinking Third Party Risk Management

Re-thinking Third Party Risk Management

@Pankaj_Goyal
@Pankaj_Goyal
5 Followers
1 month ago 348

Re-thinking Third Party Risk Management

@Pankaj_Goyal1 month ago

Re-thinking
Third Party Risk Management
Pankaj Goyal
Director Research at FAIR Institute
Octobe…
1/24
Do you believe that 
TPRM is working?
2
2/24
2024 has been a bad 
year for Supply 
chain risk…
3
3/24
https://howmaterialisthathack.org/
Supply chain attacks / incidents have become the 
#1 threat ve…
4/24
TPRM is not in a good shape… or Noseblind…
5
5/24
Third-party 
risk is not a 
high priority…
6
6/24
60-70% organizations are covering <49% third parties
7
7/24
8
The familiar problems still persist… manual, ad-hoc, labor intensive…
8/24
9
TPRM Challenges We Hear
Don’t Know 
Which 3rd 
Party to 
Focus on
No 
Automation 
& Scale…
9/24
So how can we make 
it better?
10
10/24
We asked the CISOs…
What are my top 
third party risks?
What can I do to 
reduce my risk 
expo…
11/24
Remember:
Third Party Risk IS
First Party Risk
12
12/24
The FAIR-TAM™ Framework to manage third party risk
Risk 
based prioritization
Comprehensive 
co…
13/24
The FAIR-TAM™ Framework to manage third party risk
Risk 
based prioritization
Comprehensive 
co…
14/24
15
We published more research through the FAIR TPRM 
Research Working Group
15/24
Research Objective: Identify the Top 10 controls for third 
parties to reduce first-party risk.
P…
16/24
Could FAIR-TAM™ 
have helped make 
2024 better?
17
17/24
Top Tier vendor due to high 
Business interruption exposure; 
concentration risk
Inside-out tele…
18/24
Top Tier vendor due to high 
Business interruption exposure
Your own redundancy?
CrowdStrike con…
19/24
Risk 
based prioritization
Comprehensive 
continuous monitoring
Actionable 
risk 
mitigations…
20/24
90% focus on 10% most critical 
third parties Automate inside-out telemetry Focus on yourself, rat…
21/24
Compliance Based Approach
Focus on managing tools & 
process
Chase third parties to 
remediate …
22/24
Remember:
Third Party Risk IS
First Party Risk
23
23/24
We can fix this…
24
Reach out at
pankaj@fairinstitute.org
24/24


  • Previous
  • Next
  • f Fullscreen
  • esc Exit Fullscreen
@Pankaj_Goyal

Share

Re-thinking Third Party Risk Management

Embed code


Swipe LEFT
to view Related

Scroll DOWN
to read doc

This website uses cookies to improve your experience. By using this site, you consent to the use of cookies.

Login

OR

Forgot password?

Don't have an account? Sign Up