Vendor management spans a wide variety of topics: from contracts, to metrics, to relationships, and beyond. But one of the most critical aspects of vendor management—particularly for a CISO—is how to manage the risk your vendors bring to the table.
We’ve outlined how to select your vendors, onboard them, and manage them continuously below—but before that, there are a few things you need to keep in mind:
There are risks associated with every vendor relationship—so the question becomes how important those potential risks are to you. In other words, what are the risks you’ll accept and which are just going to be too, well...risky?

Most CISOs don’t have enough team members in place to facilitate a dream vendor management process, which makes selecting the risks that they’ll address more critical. But it is important that you have a team with enough bandwidth to assess your vendor relationships during the selection and onboarding process—and most of all, on a continuous basis. Maximizing your team’s efficiency and making the most of the resources you have available will play a critical role in your vendor management and security.
Often, an organization may narrow a list of potential vendors down to the top 3-5 and pass it along. As the CISO, you are then responsible for helping your team assess the information security risks your organization may be subjected to with particular vendors.
In order to have an effective vendor selection process, you need to have a clear understanding of the kind of information that will be exchanged between your organization and the vendor’s organization.
What amount of access they have and what type of data will be shared are extremely important to know ahead of time. With all of this information in mind, you should have a better idea of how deep you’ll need to go with your vendor risk assessment. Different organizations present different levels of risk; some require an on-site assessment and penetration test (among other things), and others might be conducted from your desk. Once you have these answers, you’ll have a pretty good idea of whether or not you’ll want to move forward to the onboarding of a particular vendor.
Once you’ve assessed the risk associated with a particular category of vendor, you’ll want to look at the vendors and see how they compare. If there are any risks you’re not comfortable with, you need to look to the vendor to address those risks before they’re onboarded.
Once you’ve selected a vendor, it’s time to manage the onboarding process. That will likely involve some of the following:
When your vendor is onboarded, they should be assigned to a vendor manager or someone on your staff who can manage the working relationship going forward. This includes monitoring important KPIs and metrics, as well as conducting annual reviews of the vendor.
But remember that cyber risks are evolving every day—so once-a year-assessments are simply inadequate in terms of managing vendor risk. You need to know what is going on with your vendors on a day-to-day, hour-to-hour, and minute-to-minute basis. This is where continuous vendor risk monitoring comes into play. You don’t just see a snapshot in time of your vendor’s performance—you see a real-time view. This helps you become aware of any new risks so you can manage them quickly and appropriately.
You can’t manage every single risk that your vendors present. It’s simply not possible in today’s threat landscape. What’s more is every vendor is different, and they simply cannot all be lumped together as far as risk is concerned.
Therefore, being able to identify the risks that are most relevant to your business—and focus on those that can have the biggest impact to your organization if they’re not correctly managed—is a skill every CISO needs to have.
Data breaches that originate through third parties are more commonplace than organizations are used to. The SolarWinds hack and Kaseya ransomware attack are two recent examples of threat actors exploiting the security practices of...
Organizations rely on third-parties to keep competitive in the marketplace. The EY global third-party risk management survey highlights that in 2019–20, over 33% of the 246 global companies surveyed were managing and monitoring third-party...
Third parties are essential to helping your business grow and stay competitive. But if you’re not careful, your trusted partnerships can introduce unwanted cyber risk and overhead into your organization.
© 2026 BitSight Technologies. All Rights Reserved. | Privacy Policy | Security | For Suppliers
Contact Us | BitSight Technologies | 111 Huntington Ave, Suite 2010, Boston, MA 02199 | +1-617-245-0469