logo

A common sense approach for assessing third-party risk

ID: faa9b0bb-124e-5b5d-af74-feb3899f870f

STIX ID: report--faa9b0bb-124e-5b5d-af74-feb3899f870f

Feed Name: Expel Blog

Date Published: 2018-07-26

Date Updated: 2026-04-27

Author: Bruce Potter

...
...

Expel provides a pragmatic how‑to for third‑party vendor security assessments: design a short, clear questionnaire, implement a concise multi-step process to collect and evaluate vendor responses, integrate reviews into procurement and contract workflows, and store results securely. The guide recommends the "50 at 50" approach to balance assurance and effort, advises escalation paths for higher‑risk suppliers, and warns against common mistakes such as overloading questionnaires, trusting answers unquestioningly, and inadvertently performing or funding deeper assessments like penetration tests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.