CISO survey: 6 lessons to boost third-party cyber-risk management
ID: faec560e-8757-5608-b73c-18f72d041936
STIX ID: report--faec560e-8757-5608-b73c-18f72d041936
Feed Name: ReversingLabs Blog
Date Published: 2025-03-20
Date Updated: 2026-04-29
Author: [email protected] (John P. Mello Jr.)
A survey of 200 CISOs highlights a rise in third-party cybersecurity incidents in 2024 and widespread challenges in software supply chain visibility, resource constraints, and executive prioritization of third-party risk. The report notes growing adoption of AI automation for vendor assessments with significant time savings, while traditional GRC platforms often fail to capture TPCRM complexity. Experts emphasize proactive dependency management (including transitive dependencies), data-driven executive engagement, and sector-specific tooling. Gartner recommends improving risk communication, tracking contract decisions, conducting incident response planning with third parties, and collaborating with critical vendors to mature their security practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
