Third-party risk refers to the potential security risks to an organization stemming from the use of third-party vendors, including those vendors in the supply chain as well as groups that may not typically perform security investigations such as law firms, building infrastructure maintenance and services, accounting firms, or even catering. Third-party risk is also posed by business partners and subsidiaries as well as the vendors that they work with.
While these third parties may be outside of the typical security and IT purview for an organization, they frequently have digital access or connectivity to an organization’s resources that are vulnerable to attack. Even in cases where the intended resource poses little risk, access to it can be used to establish a beachhead from which attackers can move laterally to discover more valuable assets (as happened in the Target breach). Third-party risk management involves continuously identifying, analyzing, and controlling all associated risks over the duration of the relationship.
See Also
Warning: simplexml_load_file(): /var/www/html/shared/learning-center/guides.xml:463: parser error : Extra content at the end of the document in /var/www/html/shared/learning-center/listing-path.php on line 3
Warning: simplexml_load_file(): <guide id="active-vs-passive-reconnaissance"> in /var/www/html/shared/learning-center/listing-path.php on line 3
Warning: simplexml_load_file(): ^ in /var/www/html/shared/learning-center/listing-path.php on line 3
Warning: Attempt to read property "guide" on false in /var/www/html/shared/learning-center/listing-path.php on line 6
Warning: Trying to access array offset on null in /var/www/html/shared/learning-center/listing-path.php on line 6
Warning: Attempt to read property "cluster" on null in /var/www/html/shared/learning-center/listing-path.php on line 6
Learning Center >
Warning: Attempt to read property "guide" on false in /var/www/html/shared/learning-center/listing-path.php on line 7
Warning: Trying to access array offset on null in /var/www/html/shared/learning-center/listing-path.php on line 7
Warning: Attempt to read property "url" on null in /var/www/html/shared/learning-center/listing-path.php on line 7
Warning: Attempt to read property "guide" on false in /var/www/html/shared/learning-center/listing-path.php on line 7
Warning: Trying to access array offset on null in /var/www/html/shared/learning-center/listing-path.php on line 7
Warning: Attempt to read property "title" on null in /var/www/html/shared/learning-center/listing-path.php on line 7
Warning: Attempt to read property "guide" on false in /var/www/html/shared/learning-center/listing-path.php on line 8
Warning: Trying to access array offset on null in /var/www/html/shared/learning-center/listing-path.php on line 8
Warning: Attempt to read property "description_short" on null in /var/www/html/shared/learning-center/listing-path.php on line 8
Resources > Reports
Download this study to learn how to protect your most critical assets from being easily exploited by attackers as your enterprise expands to include more subsidiary brands and web applications.
Resources > Reports
Download the IDC EASM buyers guide and understand the key capabilities to look for when selecting an External Attack Surface Management solution with expert guidance and selection criteria from analyst firm IDC.
Use Cases
The CyCognito platform provides immediate visibility of your subsidiaries' security posture and attack surface with no deployment or configuration.