Third Party Risk Management: Risks Lurk Everywhere
Thomas Neuwert, neto consulting
Awareness of information security, IT security, and data security is growing amid increasing IT attacks. That’s good news. However, guest author and security expert Thomas Neuwert from neto consulting finds it concerning that security measures often stop at the company’s front door. The biggest risks, however, lurk with third parties.
About two years ago, an incident in the Suez Canal illustrated how vulnerable supply chains – and thus the global economy – can be. At that time, the 400-meter-long, nearly 60-meter-wide, and over 32-meter-high container ship “Ever Given” blocked the crucial sea passage. Suddenly, supply chains worldwide collapsed over days, weeks, and months. Nothing moved on the familiar sea highway. Container ships backed up and had to take massive detours. The “Ever Given” example showed one thing clearly: Chains usually break where the weakest link is – in this case, the narrow canal. And they break when no one expects it. The consequences in an increasingly interconnected and complex economy are immense.
What the Ship Incident Has in Common with IT Risks
The “Ever Given” incident is a singular event. But it can be applied to other areas – especially the secure handling of data and IT infrastructure. The best protection and the best concept for logistics processes or IT security are useless if business partners do not exercise due diligence. In the case of the “Ever Given,” many German mid-sized companies were the victims because their supplies were delayed. In the case of IT violations by third parties, the main companies are also dragged into the negative vortex.
Room for Improvement in Third Party Risk Management
To put it bluntly: The state of Third Party Risk Management in the German economy is not good. The highest security levels are useless if data risks are handled carelessly, especially with service partners in the cloud. No company can afford to isolate itself from the world like perhaps the regime in North Korea. It must allow data paths into and out of companies – for customers, employees, or the numerous suppliers and business partners. And it must be possible, for efficiency and cost reasons, to share data and services with third parties or, especially in the cloud, to store them with them.
However, this also increases the attack points. When third-party providers come into play, companies cannot rely on the self-assessment of these providers. Any violation by third parties can lead to significant financial losses and reputational damage.
Managing and Monitoring Partnerships with Third-Party Providers
Partnerships with third-party providers must be continuously managed. They are associated with significant business risks and shift control aspects beyond a company’s borders.
According to the Global Cybersecurity Outlook 2022 (PDF) by the World Economic Forum in Davos, indirect cyberattacks – successful breaches into corporate networks via third-party providers – have increased from 44 to 61 percent in recent years. Companies are increasingly not attacked directly but via third parties whose IT services, software, or hardware are compromised. In Germany, major names like Audi, Volkswagen, or Mercedes-Benz have already been affected – and more mid-sized companies will follow. In addition to IT partners in the cloud, companies should, in their own security interest, closely examine data security with their suppliers and partners. And in case of an incident, it must be ensured that a third party immediately informs the others in the network about the attack and any measures taken. This should be contractually secured in advance. Nevertheless, every company should ensure and monitor these critical IT interfaces themselves and verify them.
TL;DR
- Indirect cyberattacks via third-party providers have increased from 44 to 61 percent – your own firewall is not enough
- Even corporations like Audi, VW, and Mercedes-Benz have already been compromised via third parties
- Third Party Risk Management requires continuous monitoring, contractual safeguards, and independent controls
Key Facts
Increase in Indirect Attacks: From 44 to 61 percent according to WEF Global Cybersecurity Outlook 2022
Affected Companies: Audi, Volkswagen, Mercedes-Benz – and increasingly the mid-sized sector
Core Problem: Own security standards are useless if third-party providers and cloud partners have gaps
Solution: Contractual reporting obligations in case of security incidents and regular independent audits of partners
Fact: The number of newly discovered malware variants daily is over 450,000, according to AV-TEST.
Fact: The number of newly discovered malware variants daily is over 450,000, according to AV-TEST.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What is Third Party Risk Management?
Third Party Risk Management encompasses all measures for identifying, assessing, and controlling risks that arise from business relationships with third-party providers. These include cloud service providers, IT partners, suppliers, and all external organizations with access to company data.
Why are third-party providers such a significant security risk?
No company can completely isolate itself. It must have data paths to customers, employees, suppliers, and cloud services. Each of these interfaces is a potential entry point. Attackers deliberately target the weakest link in the chain.
What does the Suez Canal incident have to do with IT security?
The blockade by the Ever Given exemplarily showed how vulnerable interconnected systems are: Chains break at the weakest link, and the consequences affect all parties involved. This principle also applies to IT supply chains and data flows.
How can companies reduce third-party provider risks?
Companies should contractually anchor security requirements, conduct regular audits of partners, and independently monitor critical IT interfaces. Immediate reporting obligations in case of incidents must be agreed upon in advance.
Does Third Party Risk Management only affect large corporations?
No. Especially mid-sized companies are affected because they often rely on external IT service providers and cloud services without being able to verify their security level themselves.
Further Reading in the Network
Cloud Security and Provider Management on cloudmagazin.com
Supply Chain Risks and Digitalization on mybusinessfuture.com
Risk Management at the C-Level on digital-chiefs.de
Titel-Bild: Freepik
–
About the Author
Thomas Neuwert is managing director of neto consulting in Rosenheim. The firm delivers integrated Governance, Risk, and Compliance consulting. For automated solutions, neto consulting uses “embedded GRC” by GORISCON as its core product: It enables companies to implement efficient, resource-conscious workflows across domains – from information security and data protection to enterprise risk management.
Related Articles
- NIS2 and Supply-Chain Security: How Supply Chains Become Compliance Risks
- Dangers for Companies – How Cybercriminals Exploit ChatGPT
- secIT by Heise 2026: The Security Roadshow for Admins and IT Responsibles
Header Image Source: Pexels