#vendormanagement — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vendormanagement, aggregated by home.social.
-
Every environment has components nobody has revisited since they went in. Once a year, per system. Is the decision that put this here still valid. Are we using it well. If it is a renewal year, is there something better. Everything has a shelf life.
#SystemsThinking #ITLeadership #VendorManagement #Architecture #Operations
-
Every environment has components nobody has revisited since they went in. Once a year, per system. Is the decision that put this here still valid. Are we using it well. If it is a renewal year, is there something better. Everything has a shelf life.
#SystemsThinking #ITLeadership #VendorManagement #Architecture #Operations
-
FYI: Explaining master services agreement: Master services agreement: the umbrella contract governing advertiser, agency and vendor relationships. What it contains, who audits it, and where it breaks. https://ppc.land/master-services-agreement/ #MasterServicesAgreement #ContractLaw #AdvertisingAgency #VendorManagement #BusinessRelationships
-
I moved my infrastructure to a Swiss provider for jurisdiction, not features. It does not remove the ability to access my data. It changes what has to happen first. Legal security is where providers actually differ, and it is the axis nobody scores.
#DataSovereignty #Privacy #InfoSec #VendorManagement #Compliance
-
I moved my infrastructure to a Swiss provider for jurisdiction, not features. It does not remove the ability to access my data. It changes what has to happen first. Legal security is where providers actually differ, and it is the axis nobody scores.
#DataSovereignty #Privacy #InfoSec #VendorManagement #Compliance
-
ICYMI: Explaining master services agreement: Master services agreement: the umbrella contract governing advertiser, agency and vendor relationships. What it contains, who audits it, and where it breaks. https://ppc.land/master-services-agreement/ #MasterServicesAgreement #ContractLaw #Advertising #AgencyRelationships #VendorManagement
-
Explaining master services agreement: Master services agreement: the umbrella contract governing advertiser, agency and vendor relationships. What it contains, who audits it, and where it breaks. https://ppc.land/master-services-agreement/ #MasterServicesAgreement #ContractLaw #Advertising #AgencyRelationships #VendorManagement
-
FYI: Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. https://ppc.land/six-identity-questions-vab-says-every-ad-buyer-must-ask-their-vendor/ #AdTech #IdentityMarketing #DigitalAdvertising #VendorManagement #MatchRate
-
FYI: Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. https://ppc.land/six-identity-questions-vab-says-every-ad-buyer-must-ask-their-vendor/ #AdTech #IdentityMarketing #DigitalAdvertising #VendorManagement #MatchRate
-
ICYMI: Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. https://ppc.land/six-identity-questions-vab-says-every-ad-buyer-must-ask-their-vendor/ #AdBuyers #IdentityQuestions #VendorManagement #DigitalMarketing #UID2
-
Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. https://ppc.land/six-identity-questions-vab-says-every-ad-buyer-must-ask-their-vendor/ #AdBuying #IdentityQuestions #VendorManagement #UID2 #OpenID
-
Pentagon CTO Pushes Faster Tech Buying Process for Vendors
The Pentagon's CTO is shaking up the tech buying process, aiming for faster decisions for vendors - think "fast yeses and fast nos" to get small companies in and out quickly, avoiding years of uncertainty. This streamlined approach will create a single, efficient entry point for companies to showcase their tech.
#DefenseProcurement #GovernmentTechnology #EmergingThreats #SupplyChain #VendorManagement
-
AI Vendors Downplay Role in Security Vulnerabilities
AI vendors are caught in a contradictory spin cycle, urging companies to rely on AI to combat threats while downplaying security flaws, leaving customers wondering who's truly responsible for safeguarding their systems. When vulnerabilities arise, these vendors often claim it's simply their AI working as intended - a…
#AiSecurity #ArtificialIntelligence #VendorManagement #SecurityVulnerabilities #EmergingThreats
-
Disputing with vendors doesn’t have to be a headache. Start by fostering open, transparent communication. Document conversations and treat disputes as collaborative problem-solving opportunities. How have these approaches worked for you in the past? Share your thoughts and strategies. #VendorManagement
-
Relying on a single cybersecurity vendor? 😬 That's a risk! Learn why a multi-vendor approach is smarter & what to watch out for with product limitations. New video explores this crucial topic. Check it out! #VendorManagement #Cybersecurity #Shorts
-
Relying on a single cybersecurity vendor? 😬 That's a risk! Learn why a multi-vendor approach is smarter & what to watch out for with product limitations. New video explores this crucial topic. Check it out! #VendorManagement #Cybersecurity #Shorts
-
In cybersecurity, your 𝘴𝘶𝘱𝘱𝘭𝘪𝘦𝘳’𝘴 𝘸𝘦𝘢𝘬𝘯𝘦𝘴𝘴 is your 𝐬𝐡𝐚𝐫𝐞𝐝 𝐬𝐞𝐜𝐫𝐞𝐭 🤐
#cybersecurity #infosec #cybersecurityawareness #databreach
#supplychain #vendormanagement -
Ledger has disclosed a customer data exposure related to a third-party payment processor, Global-e, involving personal contact information.
The incident underscores persistent third-party risk challenges, particularly where external services process or store customer data. Vendor security posture and contractual controls remain critical components of overall risk management.
From an infosec standpoint, what controls best reduce downstream exposure from partners?
Share insights and follow @technadu for objective infosec coverage.
#ThirdPartyRisk #DataProtection #CryptoSecurity #Infosec #PrivacyEngineering #VendorManagement
-
Ledger has disclosed a customer data exposure related to a third-party payment processor, Global-e, involving personal contact information.
The incident underscores persistent third-party risk challenges, particularly where external services process or store customer data. Vendor security posture and contractual controls remain critical components of overall risk management.
From an infosec standpoint, what controls best reduce downstream exposure from partners?
Share insights and follow @technadu for objective infosec coverage.
#ThirdPartyRisk #DataProtection #CryptoSecurity #Infosec #PrivacyEngineering #VendorManagement
-
When trade collapsed, buyers paid the price alongside sellers.
The smartest buyers didn’t chase the cheapest offer.
They chose reliability, compliance, and clarity.
History proves one thing clearly:
In global trade, informed buyers always outperform aggressive ones.#Procurement #StrategicSourcing #B2B #Purchasing #GlobalSourcing #SupplyChainManagement #Vendormanagement
-
Selling to the CISO: An open letter to the cybersecurity industry https://www.csoonline.com/article/4089738/selling-to-the-ciso-an-open-letter-to-the-cybersecurity-industry.html #DataandInformationSecurity #ApplicationSecurity #TechnologyIndustry #VendorManagement #NetworkSecurity #CSOandCISO #Security
-
Wie CISOs schlechte Produkte enttarnen https://www.csoonline.com/article/4063809/wie-cisos-schlechte-produkte-enttarnen.html #VendorManagement #CSOandCISO
-
What the Salesloft Drift breaches reveal about 4th-party risk – Source: www.csoonline.com https://ciso2ciso.com/what-the-salesloft-drift-breaches-reveal-about-4th-party-risk-source-www-csoonline-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #vendormanagement #cyberattacks #Cybercrime #DataBreach #CSOonline #CSOOnline
-
What the Salesloft Drift breaches reveal about 4th-party risk https://www.csoonline.com/article/4053891/what-the-salesloft-drift-breaches-reveal-about-4th-party-risk.html #VendorManagement #Cyberattacks #Cybercrime #DataBreach
-
71% of CISOs hit with third-party security incident this year https://www.csoonline.com/article/4051668/71-of-cisos-hit-with-third-party-security-incident-this-year.html #VendorManagement #RiskManagement #SupplyChain #DataBreach
-
Chess.com just faced a major data breach affecting 800K users—not from their own systems but through a vulnerable third-party app. How safe is your data when vendors can open the door?
https://thedefendopsdiaries.com/chesscom-data-breach-lessons-in-cybersecurity-and-vendor-management/
#chesscombreach
#cybersecurity
#dataprotection
#vendormanagement
#infosec -
Chess.com just faced a major data breach affecting 800K users—not from their own systems but through a vulnerable third-party app. How safe is your data when vendors can open the door?
https://thedefendopsdiaries.com/chesscom-data-breach-lessons-in-cybersecurity-and-vendor-management/
#chesscombreach
#cybersecurity
#dataprotection
#vendormanagement
#infosec -
How Gainesville Regional Utilities is locking down vendor risk https://www.csoonline.com/article/4047811/how-gainesville-regional-utilities-is-locking-down-vendor-risk.html #VendorManagement #RiskManagement #CSO50
-
Makes you wonder if #McDonalds even has a #VendorManagement program or hell an #InfoSec program for that matter.
Do they even conduct #SecurityAudits of their vendors? Do they have an #ArchitectureReviewBoard for new projects and initiatives?
Why aren't baseline/ minimum #SecurityStandards spelled out in their SOWs?
None of this is rocket-science, or even that costly, but you have to be willing to put forth the effort.
https://yro.slashdot.org/story/25/07/09/2014234/mcdonalds-ai-hiring-bot-exposed-millions-of-applicants-data-to-hackers -
Makes you wonder if #McDonalds even has a #VendorManagement program or hell an #InfoSec program for that matter.
Do they even conduct #SecurityAudits of their vendors? Do they have an #ArchitectureReviewBoard for new projects and initiatives?
Why aren't baseline/ minimum #SecurityStandards spelled out in their SOWs?
None of this is rocket-science, or even that costly, but you have to be willing to put forth the effort.
https://yro.slashdot.org/story/25/07/09/2014234/mcdonalds-ai-hiring-bot-exposed-millions-of-applicants-data-to-hackers -
Oh dear…
The BD person (WHO I KNOW AND HAVE WORKED WITH BEFORE) just said rainbowed a logo sheet in front of me and said if all these guys trust us you can too!
Bro I don’t trust my mom, I sure as hell don’t trust that a SaaS company did a decent review of your site.
This is why we see so many damn third parties making mistakes, the implied trust someone bigger did it right so you don’t have to.
-
Oh dear…
The BD person (WHO I KNOW AND HAVE WORKED WITH BEFORE) just said rainbowed a logo sheet in front of me and said if all these guys trust us you can too!
Bro I don’t trust my mom, I sure as hell don’t trust that a SaaS company did a decent review of your site.
This is why we see so many damn third parties making mistakes, the implied trust someone bigger did it right so you don’t have to.
-
Report: Silent breaches in supply chains are wreaking havoc on industries. Learn how to protect your organization from these hidden threats. https://jpmellojr.blogspot.com/2025/02/silent-breaches-and-supply-chain.html #SilentBreaches #SupplyChainSecurity #CyberSecurity #3rdPartyBreaches #BlackKite #CyberRisk #VendorManagement
-
Recent reports reveal a surge in supply chain attacks targeting critical infrastructure. Cybercriminals are increasingly exploiting vulnerabilities within third-party vendors, leading to massive breaches that can impact countless organizations. This trend underscores the need for a robust cybersecurity framework that goes beyond traditional perimeter defenses.
Key takeaways from these developments include:
1. Vulnerability Awareness: Organizations must regularly assess and inventory their suppliers, understanding the risks each poses to their operations.
2. Collaborative Defense: It's essential to foster communication and collaboration between companies and their vendors, ensuring everyone is equally committed to cybersecurity best practices.
3. Incident Response Planning: Having a well-defined incident response plan that includes third-party risks is crucial. Preparation can dramatically reduce response time and potential damage.One unique perspective often overlooked is the importance of cultivating a culture of cybersecurity awareness among all employees, not just the IT department. A company-wide understanding can act as a force multiplier in mitigating risks.
As we reflect on these evolving threats, how prepared is your organization to handle a third-party incident? Share your thoughts or strategies in the comments!
#Cybersecurity #SupplyChainSecurity #IncidentResponse #VendorManagement #ThreatIntelligence
Read more: https://steelefortress.com #InfoSec -
$1500 is cheap if you stop adding AI to every tool you have making the need for more vendor reviews and creating a never ending cycle of pain management for your vendor manager.
#smallbusiness #RiskManagement #tprm #supplychain #vendormanagement -
New line of business- “$1500 Vendor Review”
I will do a proper Vendor Review using human intelligence (HI) based on your company’s Vendor and Risk Management policies.
My average vendor review is 10 hours per vendor with both BizOps and InfoSec reviews, using standard TPRM methods, and will contain relevant documentation and attachments to make risk based decisions on vendors.
Yes - $1500 gets you 1 vendor review. Not a vendor program, not a vendor manager, just a single vendor review.
Seems like a lot of cash huh. Yep, but since you need it and don’t want to do it, pay me, I will do it for you.
#smallbusiness #RiskManagement #tprm #supplychain #vendormanagement
-
New line of business- “$1500 Vendor Review”
I will do a proper Vendor Review using human intelligence (HI) based on your company’s Vendor and Risk Management policies.
My average vendor review is 10 hours per vendor with both BizOps and InfoSec reviews, using standard TPRM methods, and will contain relevant documentation and attachments to make risk based decisions on vendors.
Yes - $1500 gets you 1 vendor review. Not a vendor program, not a vendor manager, just a single vendor review.
Seems like a lot of cash huh. Yep, but since you need it and don’t want to do it, pay me, I will do it for you.
#smallbusiness #RiskManagement #tprm #supplychain #vendormanagement
-
HIRING: Director of Information Security / Sacramento, CA, US
💰 USD 140K+👉 https://isecjobs.com/J453229/
#CISM #CISSP #Compliance #ComputerScience #FFIEC #ISACA #Monitoring #Riskassessment #Riskmanagement #Vendormanagement
-
Ensuring Compliance: CFO Perspectives on Third-Party Risk Management https://thecyberexpress.com/cfo-perspective-on-third-party-risk-management/ #ThirdPartyRiskManagement #TheCyberExpressNews #CybersecurityNews #VendorManagement #CyberEssentials #Vulnerabilities #TheCyberExpress #RiskAssessment #RiskManagement #FirewallDaily #cybersecurity #FinancialRisk #BusinessNews #DataSecurity #Compliance #CFO
-
4️⃣ Implement & manage AI tools safely & responsibly. #AIEthics
5️⃣ Be diligent in vetting third-party vendors. #VendorManagement -
Nothing better than finally convincing your 3rd party consultants that you do know what you're doing, and that you've been catching them in their shit for months and months. Take that! #SEO #vendormanagement
-
Someone I am mentoring asked me a profound question, and @SecureOwl had the best way to teach.
"do you have a best practice on how do a very basic risk assessment of third party applications / software?"
MSPs rely on services, and risk assessments for SaaS are always something that has to be done both for clients and internally.
Mike's methods do not change the need for detailed vendor reviews, but it can help a security practitioner do qualitative research quickly in small, move-fast environments.
https://mike-sheward.medium.com/the-60-second-saas-vendor-assessment-eb7179beaedd
-
Vendor management is operations for security architects.
-
And sometimes while doing due diligence on companies you just get really happy they've got their stuff seemingly under control and take the time and effort to properly answer your questions.
Yay!