How to Build a Third-Party Cyber Risk Program
Most third-party cyber risk programmes are questionnaire factories: enormous effort spent collecting documents that nobody reads, on a cycle too slow to catch anything. A programme that actually reduces risk looks different — it spends its scarce human attention on a small number of relationships and automates everything else.
Why programmes fail
The failure is almost always structural rather than technical. Assessment effort is distributed evenly across a vendor population where risk is distributed extremely unevenly; assessments happen at onboarding and then never again; and the output is a filed document rather than a decision. Meanwhile a substantial share of breaches continue to arrive through third parties, a pattern the Verizon DBIR has tracked as a growing share of incidents.[3]
NIST's supply chain guidance is unambiguous that third-party risk management must be a continuous, risk-tiered programme integrated with procurement — not a onboarding gate.[1] The six stages below are how that principle turns into an operating model.
Stage 1: Inventory
You cannot manage what you have not enumerated, and almost every organization underestimates its vendor count by a wide margin — because procurement records, expense claims and shadow SaaS are three different populations.
- Sources to reconcile — accounts payable, procurement contracts, SSO and OAuth grant logs, expense reports, and DNS/certificate records showing third-party services on your domains.
- Minimum record — legal entity, service provided, business owner, data accessed, systems integrated, contract renewal date.
- The critical field — what would break, and for how long, if this vendor went dark tomorrow. This is the field that drives everything downstream.
Stage 2: Tiering
Tiering allocates attention. It must be driven by consequence — what the vendor could cost you — not by contract value, which correlates poorly with risk. A $9,000 monitoring tool with privileged production access outranks a $3M facilities contract.
| Tier | Definition | Assessment approach |
|---|---|---|
| Tier 1 — Critical | Privileged access, or business stops without them | Deep assessment, contractual audit rights, continuous monitoring, annual review |
| Tier 2 — Significant | Sensitive data at volume, or important process dependency | Targeted assessment on relevant domains, continuous monitoring |
| Tier 3 — Limited | Limited data, replaceable service | External score baseline; monitoring alerts only |
| Tier 4 — Minimal | No data access, no dependency | Register entry, periodic score refresh |
Stage 3: Assessment depth by tier
The purpose of tiering is that Tier 3 and 4 vendors — usually the large majority — never consume analyst time unless evidence says they should. For them, an externally measured score is the assessment.
For Tier 1 and 2, layer methods deliberately: start from external evidence to know where to look, then use questionnaires and document review only for controls external observation genuinely cannot see — backup testing, segmentation, joiner-mover-leaver process, subprocessor management. Asking a Tier 1 vendor 300 generic questions produces less insight than asking twelve pointed ones informed by what you already observed. Why the questionnaire cannot carry the load alone is examined in the limits of vendor security questionnaires.
Stage 4: Contractual controls
Contracts are where a programme gets its enforcement power, and the clauses must be negotiated before signature — leverage disappears afterwards. ISO/IEC 27036 provides the reference structure for security in supplier relationships.[5]
- Incident notification — a defined maximum notification window in hours, not "promptly", with a named contact and required content.
- Right to assess — the right to reassess on a defined cadence and upon material change, including after the vendor's own incidents.
- Subprocessor disclosure and approval — the entry point to fourth-party visibility — see supply chain risk.
- Minimum control commitments — specific and testable (MFA on all administrative access, encryption at rest, defined recovery objectives) rather than "industry standard practices".
- Remediation obligations — timelines for critical findings, with escalation and termination rights if missed.
- Return and destruction of data — verified, on a deadline, at termination.
Stage 5: Continuous monitoring
This is the stage that separates a programme from a paperwork exercise. Vendor posture changes constantly; an annual review is blind for 51 weeks. Continuous external monitoring closes that window, and its value is entirely in the alerting logic: a stream of score fluctuations nobody triages is noise.
| Trigger | Applies to | Response |
|---|---|---|
| Score drop ≥ 40 points in 30 days | Tiers 1–2 | Contact vendor for explanation and remediation plan |
| Known-exploited vulnerability exposed | All tiers | Immediate notification; track to closure |
| Score crosses below tier threshold | Tiers 1–3 | Formal review; consider contractual escalation |
| Credential leak involving vendor domain | Tiers 1–2 | Verify containment; assess your own exposure |
| Public incident disclosure | All tiers | Impact assessment on your data and dependency |
| New subprocessor detected | Tiers 1–2 | Assess the fourth party; check contractual approval |
CISA's known-exploited catalogue is the practical benchmark for the second row: exposure to a catalogued vulnerability is a materially different signal from a generic CVE.[4]
Stage 6: Offboarding
Terminated vendors remain a risk while they retain access or data, and offboarding is the most commonly skipped stage. A minimum checklist: revoke SSO, OAuth grants and VPN access; rotate any shared credentials and API keys; confirm data return or destruction in writing; remove network allowlist entries and DNS delegations; and close the register entry with a date. Dormant integrations from vendors nobody has paid in three years are a recurring finding in real incidents.
What to automate
- Automate — discovery reconciliation, external scoring of the entire population, monitoring and alert triage, evidence collection reminders, and register hygiene.
- Keep human — tiering decisions, interpretation of Tier 1 findings, negotiation, exception approval and termination judgements.
The economics only work with this split. Scoring every vendor externally — no questionnaires, no vendor cooperation required, under the patented Xcigence method[6] — is what frees analyst capacity for the twenty relationships that carry most of the risk. See third-party cyber risk scoring for how that baseline is produced and maintained.
Metrics that matter
Report outcomes, not activity. Questionnaires completed is activity; the metrics below are outcomes, and they map to the governance expectations of NIST CSF 2.0.[2]
- Coverage — percentage of the reconciled vendor population under active monitoring.
- Concentration — percentage of Tier 1 vendors below your sector threshold, and the largest shared dependency across your book.
- Time to remediation — median days from critical vendor finding to verified closure.
- Ecosystem exposure — aggregate quantified loss exposure attributable to third parties, trended quarterly.
Scoring vendors, suppliers, and downstream providers on one methodology.
References
- [1]NIST. SP 800-161r1 — Cybersecurity Supply Chain Risk Management Practices
- [2]NIST. Cybersecurity Framework (CSF) 2.0
- [3]Verizon. Data Breach Investigations Report (DBIR)
- [4]CISA. Known Exploited Vulnerabilities (KEV) Catalog
- [5]ISO. ISO/IEC 27036 — Information security for supplier relationships
- [6]USPTO. Patent application US 16/822,691 — Global Dossier record
Continue reading
Questionnaires are self-attested, point-in-time, and unverified. They still matter — but only for the questions external evidence genuinely cannot answer.
Your vendors have vendors. Concentration risk in shared cloud, identity and file-transfer providers is now the dominant mode of systemic cyber failure.
A cybersecurity risk score turns observable security evidence into a standardized number decision-makers can compare, price, and act on. Here is what goes into one and what makes it defensible.
See your own cyber risk score
Xcigence computes a standardized 300–850 cyber risk score for your organization and every vendor in your ecosystem — no agents, no questionnaires.