Third-Party Risk Management in Cybersecurity

4 Minute read
Qurash Ramlal
Customer Success Manager | Governance & Security Advisory
Third-Party Risk Management in Cybersecurity
In this article

Share this article

Supplier cybersecurity posture increasingly affects procurement qualification, cyber insurance reviews, operational resilience, and customer trust — particularly where suppliers process sensitive data or support critical operations.

Most organisations now depend on dozens or hundreds of third parties for business-critical services. Each one is a potential entry point — and the supply-chain breaches dominating recent headlines came through suppliers, most of which those organisations had reviewed at onboarding and never reassessed. Third-party risk has to be managed as a continuous programme, not a one-off procurement checkbox. This article sets out what that programme actually looks like.

The short answer

Credible third-party risk management in cybersecurity runs in six continuous phases: supplier inventory, tiered risk assessment, classification, ongoing monitoring, remediation, and governance reporting. It aligns to ISO/IEC 27036, NIST SP 800-161, and ISO 27001 Annex A.5.19–5.23 — and is the operational answer to POPIA Section 21 accountability for operators.

Start with an honest inventory — most organisations have more suppliers than they think

The first credible step in any TPRM programme is the inventory: every vendor, supplier, service provider, and partner with access to data, systems, or critical services. Most organisations underestimate this number by a factor of two or three. The inventory captures data access, service criticality, and contractual context for each relationship — the basis for everything that follows.

Tier suppliers by risk — most do not require the same level of scrutiny

Treating every supplier identically wastes effort and dilutes attention where it matters. A tiered model — typically high, medium, low — based on data sensitivity, service criticality, and regulatory exposure, focuses remediation and monitoring intensity on the suppliers that can actually hurt the business. High-tier suppliers receive in-depth assessment and continuous monitoring; low-tier suppliers receive lightweight controls and periodic review.

Assess against frameworks, not gut feel

Credible supplier assessments map to recognised supply-chain risk standards: ISO/IEC 27036 for supplier-relationship security, NIST SP 800-161 for cybersecurity supply chain risk management, and ISO 27001 Annex A.5.19 through A.5.23 for operational controls. Assessments cover security posture, patch and vulnerability management, application security, credential controls, incident response capability, and contractual obligations. Tooling like RiskRecon supplements internal review with external posture data.

Monitor continuously — point-in-time review is no longer enough

A supplier secure at onboarding may not be secure twelve months later. Continuous monitoring — external posture scoring, breach notifications, regulatory enforcement alerts, and certificate status changes — surfaces deterioration before it becomes an incident. The shift from annual questionnaires to continuous monitoring is the single biggest change in TPRM practice over the past five years.

Anchor TPRM in contracts and POPIA accountability

Section 21 of POPIA holds the responsible party accountable for personal information processed by operators. That means TPRM cannot stop at questionnaires — it must produce the assurance evidence (assessment, contractual mapping, ongoing monitoring) that supports your accountability. Contracts include defined security obligations, breach-notification timelines, right-to-audit clauses, and exit data-handling requirements.

Report TPRM to the audit committee, not just procurement

TPRM is now an audit-committee and board metric. Regular reporting covers the supplier portfolio by risk tier, status changes since the last review, open remediation actions on high-tier suppliers, and breach or near-miss events involving the supply chain. This is the evidence regulators and insurers increasingly expect when supply-chain exposure comes up.

Mature TPRM programmes also assess concentration risk — where multiple critical services depend on a single supplier or platform provider.

Key Takeaways

  • Most organisations underestimate their third-party footprint by two to three times — start with an honest inventory.
  • Tiered risk classification focuses scrutiny on the suppliers that can actually hurt the business.
  • Assessments align to ISO/IEC 27036, NIST SP 800-161, and ISO 27001 Annex A.5.19–5.23 — not informal questionnaires.
  • Continuous monitoring has replaced annual reviews as the credible operating model.
  • POPIA Section 21 makes the responsible party accountable for operator processing — contracts must reflect that.
  • TPRM is now an audit-committee metric, not a procurement administrative task.

How Cyber Resilience Can Help

Cyber Resilience helps organisations build defensible third-party risk programmes through supplier inventorying, tiered risk assessment, continuous monitoring, and governance reporting aligned to POPIA and international standards.

Speak to our team to arrange a TPRM scoping discussion.

Qurash Ramlal

Customer Success Manager | Governance & Security Advisory

Qurash Ramlal works closely with Cyber Resilience clients to support long-term cybersecurity maturity, governance alignment, and operational resilience improvement.

With experience across cybersecurity, telecommunications, and managed services environments, he focuses on helping organisations strengthen governance visibility, improve security awareness, and align operational security initiatives to evolving business risk.

Expertise

ISO 27001 • Managed Security Services • Governance • Client Success • Cybersecurity Advisory

Frequently asked questions

How often should we reassess our suppliers?

High-tier suppliers warrant continuous monitoring with formal reassessment at least annually. Medium-tier suppliers typically operate on an 18-month to 2-year cycle, with continuous external posture monitoring in between. Low-tier suppliers can sit on a three-year cycle if the contractual and monitoring posture is stable.

How does POPIA Section 21 apply to our suppliers?

Section 21 holds the responsible party accountable for personal information processed by operators (third-party processors). That accountability does not transfer with the data. TPRM produces the assurance evidence — assessment, contractual mapping, ongoing monitoring — that supports your Section 21 obligations and is increasingly expected when the Information Regulator engages.

What is RiskRecon, and how does it fit?

RiskRecon is a third-party security posture platform that continuously assesses the external attack surface of your suppliers and scores them against an objective rubric. It supplements — does not replace — structured assessment and contractual review. The combination produces evidence both regulators and audit committees can rely on.

What if a supplier refuses an assessment?

It is a procurement decision. For high-tier suppliers, refusal to support a reasonable assurance request is itself a risk signal. Many organisations now include right-to-audit clauses and consent for continuous posture monitoring in contracts at onboarding, eliminating the need for later negotiation. Where a supplier is critical and unwilling, the question is whether the concentration risk is acceptable.

Can we automate TPRM completely?

Partially. External posture monitoring, breach-feed correlation, and questionnaire workflow can be automated. The judgment work — interpreting findings, scoping remediation, contractual response, and reporting — remains human. Automation removes administrative drag; it does not remove the assessment discipline.

Related Insights

Cyber resilience insights grounded in operational reality.

Practical guidance, operational perspectives, regulatory insights, and forensic-led thinking across cybersecurity, governance, resilience, and digital risk.

Need Clarity on your CURRENT RESILIENCE POSTURE?

Whether you need a focused assessment, operational support, governance maturity, or incident response guid-ance, we will help you understand your current position and build a practical path forward.