The majority of significant security incidents now involve a third party – a supplier, a software vendor, a cloud provider, or a professional services firm with access to your systems. Attackers target the organisations around you precisely because they are less well defended.
Your clients are asking you the same questions about your suppliers that your insurers and regulators are. Without a managed third-party risk programme, you cannot answer them confidently.
