• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Management Leadership

COVID-19 raises alarm over third-party cybersecurity risk

FutureCIO Editors by FutureCIO Editors
May 4, 2020
Photo by Junior Teixeira from Pexels

Photo by Junior Teixeira from Pexels

A Gartner survey of 145 legal and compliance leaders on 14 April 2020 revealed that since the onset of COVID-19, more than half of respondents believe that cybersecurity and data breach is the most-increased third-party risk their organizations face.

“Remote working has been hastily adopted by suppliers to keep their business running, so it’s unlikely every organization or employee is following best practices. Legal and compliance leaders are concerned about the new risks this highly disruptive environment has created for their organizations,” said Vidhya Balasubramanian, managing vice president in the Gartner Legal and Compliance practice.

Bribery and corruption, privacy, fraud, and ethical conduct were all noted as the most-increased third-party risks (10% of respondents for each) for a signification number of respondents (see Figure below).

Balasubramanian advised legal and compliance leaders to act now to mitigate third-party risk while still enabling their supply chain partners to flex to the current pressures on the system

“This will likely mean managing the contractual risks and opportunities of current relationships, mitigating emerging issues, and streamlining due diligence for new third-parties. Legal and compliance leaders will also be looking at other ways to reduce the compliance burden on third parties,” she continued.

Navigate the contractual relationship

Legal and compliance leaders are managing the contractual risks of disrupted supply chains by:

  • Working with procurement or supply chain leaders to identify which critical suppliers have manufacturing facilities, or a portion of the workforce, located in high risk areas
  • Contacting high-risk, critical suppliers to understand their preparedness for COVID-19, and the likelihood that they will meet contractual obligations.
  • Anticipating ongoing financial or business disruption by conducting a review of existing contracts with high-risk suppliers to identify those with force majeure and other relevant clauses

Mitigate amplified third-party risks

Gartner identified several emerging practices from the survey respondents:

  • Reviewing third-party compliance activities, including third-party work from home policies, as well as privacy and security training plans
  • Updating contracts to include clauses intended to mitigate cybersecurity & data privacy risks (e.g., clauses on VPN use, data use)
  • Reducing the compliance burden on suppliers by:
  • Entering into temporary “workaround agreements” by amending contracts to maintain services in a remote environment
  • Postponing supplier audits until later in the year
  • Modifying payment structures to those suppliers needing to boost cash flow
  • Streamline Third-Party Due Diligence

Emerging practices in this area include:

  • Talking to functional partners about working with new third parties if needed to alleviate supply chain issues.
  • Identifying critical, zero tolerance risks and revising due diligence processes to flag these.
  • Identifying and prioritizing critical third parties and helping them manage risk throughout the pandemic.
  • Conducting remote audits.
  • Decreasing the amount of information requested from potential suppliers about general risks.

Balasubramanian explained that legal and compliance leaders have had to pivot quickly to support their supply chain and other business partners as part of this rapidly shifting third-party risk landscape. “The most progressive companies have approached this crisis as an opportunity to clarify and streamline compliance obligations, strengthen current relationships, and focus their risk management efforts on the most critical, urgent risks,” she concluded.

Related:  2FA not enough to save online gamers, but its a start
Tags: GartnerLegal and Compliance
FutureCIO Editors

FutureCIO Editors

No Result
View All Result

Recent Posts

  • APAC CIOs rethink cybersecurity investments amid expanding threat landscape
  • Study finds almost half of businesses bank on AI-enabled cybersecurity for EDR and XDR
  • AI drives cloud market growth in Q1
  • ARTHALAND chooses OutSystems to advance real estate sustainability
  • Experts warn against AI-powered deepfake impersonation scams

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe