home.social

#vendormanagement — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vendormanagement, aggregated by home.social.

fetched live
  1. Every environment has components nobody has revisited since they went in. Once a year, per system. Is the decision that put this here still valid. Are we using it well. If it is a renewal year, is there something better. Everything has a shelf life.

    #SystemsThinking #ITLeadership #VendorManagement #Architecture #Operations

  2. Every environment has components nobody has revisited since they went in. Once a year, per system. Is the decision that put this here still valid. Are we using it well. If it is a renewal year, is there something better. Everything has a shelf life.

    #SystemsThinking #ITLeadership #VendorManagement #Architecture #Operations

  3. FYI: Explaining master services agreement: Master services agreement: the umbrella contract governing advertiser, agency and vendor relationships. What it contains, who audits it, and where it breaks. ppc.land/master-services-agree #MasterServicesAgreement #ContractLaw #AdvertisingAgency #VendorManagement #BusinessRelationships

  4. I moved my infrastructure to a Swiss provider for jurisdiction, not features. It does not remove the ability to access my data. It changes what has to happen first. Legal security is where providers actually differ, and it is the axis nobody scores.

    #DataSovereignty #Privacy #InfoSec #VendorManagement #Compliance

  5. I moved my infrastructure to a Swiss provider for jurisdiction, not features. It does not remove the ability to access my data. It changes what has to happen first. Legal security is where providers actually differ, and it is the axis nobody scores.

    #DataSovereignty #Privacy #InfoSec #VendorManagement #Compliance

  6. ICYMI: Explaining master services agreement: Master services agreement: the umbrella contract governing advertiser, agency and vendor relationships. What it contains, who audits it, and where it breaks. ppc.land/master-services-agree #MasterServicesAgreement #ContractLaw #Advertising #AgencyRelationships #VendorManagement

  7. Explaining master services agreement: Master services agreement: the umbrella contract governing advertiser, agency and vendor relationships. What it contains, who audits it, and where it breaks. ppc.land/master-services-agree #MasterServicesAgreement #ContractLaw #Advertising #AgencyRelationships #VendorManagement

  8. FYI: Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. ppc.land/six-identity-question #AdTech #IdentityMarketing #DigitalAdvertising #VendorManagement #MatchRate

  9. FYI: Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. ppc.land/six-identity-question #AdTech #IdentityMarketing #DigitalAdvertising #VendorManagement #MatchRate

  10. ICYMI: Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. ppc.land/six-identity-question #AdBuyers #IdentityQuestions #VendorManagement #DigitalMarketing #UID2

  11. Six identity questions VAB says every ad buyer must ask their vendor: Published today, the 15-page guide names UID2, OpenID and RampID as identifier options and urges buyers to audit vendor match-rate accuracy before signing on. ppc.land/six-identity-question #AdBuying #IdentityQuestions #VendorManagement #UID2 #OpenID

  12. Pentagon CTO Pushes Faster Tech Buying Process for Vendors

    The Pentagon's CTO is shaking up the tech buying process, aiming for faster decisions for vendors - think "fast yeses and fast nos" to get small companies in and out quickly, avoiding years of uncertainty. This streamlined approach will create a single, efficient entry point for companies to showcase their tech.

    osintsights.com/pentagon-cto-p

    #DefenseProcurement #GovernmentTechnology #EmergingThreats #SupplyChain #VendorManagement

  13. AI Vendors Downplay Role in Security Vulnerabilities

    AI vendors are caught in a contradictory spin cycle, urging companies to rely on AI to combat threats while downplaying security flaws, leaving customers wondering who's truly responsible for safeguarding their systems. When vulnerabilities arise, these vendors often claim it's simply their AI working as intended - a…

    osintsights.com/ai-vendors-dow

    #AiSecurity #ArtificialIntelligence #VendorManagement #SecurityVulnerabilities #EmergingThreats

  14. Disputing with vendors doesn’t have to be a headache. Start by fostering open, transparent communication. Document conversations and treat disputes as collaborative problem-solving opportunities. How have these approaches worked for you in the past? Share your thoughts and strategies. #VendorManagement

  15. Relying on a single cybersecurity vendor? 😬 That's a risk! Learn why a multi-vendor approach is smarter & what to watch out for with product limitations. New video explores this crucial topic. Check it out! #VendorManagement #Cybersecurity #Shorts

    youtube.com/watch?v=Bms-FCNCy_Q

  16. Relying on a single cybersecurity vendor? 😬 That's a risk! Learn why a multi-vendor approach is smarter & what to watch out for with product limitations. New video explores this crucial topic. Check it out! #VendorManagement #Cybersecurity #Shorts

    youtube.com/watch?v=Bms-FCNCy_Q

  17. In cybersecurity, your 𝘴𝘶𝘱𝘱𝘭𝘪𝘦𝘳’𝘴 𝘸𝘦𝘢𝘬𝘯𝘦𝘴𝘴 is your 𝐬𝐡𝐚𝐫𝐞𝐝 𝐬𝐞𝐜𝐫𝐞𝐭 🤐

    #cybersecurity #infosec #cybersecurityawareness #databreach
    #supplychain #vendormanagement

  18. Ledger has disclosed a customer data exposure related to a third-party payment processor, Global-e, involving personal contact information.

    The incident underscores persistent third-party risk challenges, particularly where external services process or store customer data. Vendor security posture and contractual controls remain critical components of overall risk management.

    From an infosec standpoint, what controls best reduce downstream exposure from partners?

    Source: linkedin.com/posts/hackmanac_c

    Share insights and follow @technadu for objective infosec coverage.

    #ThirdPartyRisk #DataProtection #CryptoSecurity #Infosec #PrivacyEngineering #VendorManagement

  19. Ledger has disclosed a customer data exposure related to a third-party payment processor, Global-e, involving personal contact information.

    The incident underscores persistent third-party risk challenges, particularly where external services process or store customer data. Vendor security posture and contractual controls remain critical components of overall risk management.

    From an infosec standpoint, what controls best reduce downstream exposure from partners?

    Source: linkedin.com/posts/hackmanac_c

    Share insights and follow @technadu for objective infosec coverage.

    #ThirdPartyRisk #DataProtection #CryptoSecurity #Infosec #PrivacyEngineering #VendorManagement

  20. When trade collapsed, buyers paid the price alongside sellers.

    The smartest buyers didn’t chase the cheapest offer.

    They chose reliability, compliance, and clarity.

    History proves one thing clearly:
    In global trade, informed buyers always outperform aggressive ones.

    ​#Procurement #StrategicSourcing #B2B #Purchasing #GlobalSourcing #SupplyChainManagement #Vendormanagement

  21. Makes you wonder if #McDonalds even has a #VendorManagement program or hell an #InfoSec program for that matter.

    Do they even conduct
    #SecurityAudits of their vendors? Do they have an #ArchitectureReviewBoard for new projects and initiatives?

    Why aren't baseline/ minimum
    #SecurityStandards spelled out in their SOWs?

    None of this is rocket-science, or even that costly, but you have to be willing to put forth the effort.

    https://yro.slashdot.org/story/25/07/09/2014234/mcdonalds-ai-hiring-bot-exposed-millions-of-applicants-data-to-hackers

  22. Makes you wonder if #McDonalds even has a #VendorManagement program or hell an #InfoSec program for that matter.

    Do they even conduct
    #SecurityAudits of their vendors? Do they have an #ArchitectureReviewBoard for new projects and initiatives?

    Why aren't baseline/ minimum
    #SecurityStandards spelled out in their SOWs?

    None of this is rocket-science, or even that costly, but you have to be willing to put forth the effort.

    https://yro.slashdot.org/story/25/07/09/2014234/mcdonalds-ai-hiring-bot-exposed-millions-of-applicants-data-to-hackers

  23. Oh dear…

    The BD person (WHO I KNOW AND HAVE WORKED WITH BEFORE) just said rainbowed a logo sheet in front of me and said if all these guys trust us you can too!

    Bro I don’t trust my mom, I sure as hell don’t trust that a SaaS company did a decent review of your site.

    This is why we see so many damn third parties making mistakes, the implied trust someone bigger did it right so you don’t have to.

    #VendorManagement #InfoSec

  24. Oh dear…

    The BD person (WHO I KNOW AND HAVE WORKED WITH BEFORE) just said rainbowed a logo sheet in front of me and said if all these guys trust us you can too!

    Bro I don’t trust my mom, I sure as hell don’t trust that a SaaS company did a decent review of your site.

    This is why we see so many damn third parties making mistakes, the implied trust someone bigger did it right so you don’t have to.

    #VendorManagement #InfoSec

  25. Recent reports reveal a surge in supply chain attacks targeting critical infrastructure. Cybercriminals are increasingly exploiting vulnerabilities within third-party vendors, leading to massive breaches that can impact countless organizations. This trend underscores the need for a robust cybersecurity framework that goes beyond traditional perimeter defenses.

    Key takeaways from these developments include:

    1. Vulnerability Awareness: Organizations must regularly assess and inventory their suppliers, understanding the risks each poses to their operations.
    2. Collaborative Defense: It's essential to foster communication and collaboration between companies and their vendors, ensuring everyone is equally committed to cybersecurity best practices.
    3. Incident Response Planning: Having a well-defined incident response plan that includes third-party risks is crucial. Preparation can dramatically reduce response time and potential damage.

    One unique perspective often overlooked is the importance of cultivating a culture of cybersecurity awareness among all employees, not just the IT department. A company-wide understanding can act as a force multiplier in mitigating risks.

    As we reflect on these evolving threats, how prepared is your organization to handle a third-party incident? Share your thoughts or strategies in the comments!

    #Cybersecurity #SupplyChainSecurity #IncidentResponse #VendorManagement #ThreatIntelligence
    Read more: steelefortress.com #InfoSec

  26. $1500 is cheap if you stop adding AI to every tool you have making the need for more vendor reviews and creating a never ending cycle of pain management for your vendor manager.
    #smallbusiness #RiskManagement #tprm #supplychain #vendormanagement

  27. New line of business- “$1500 Vendor Review”

    I will do a proper Vendor Review using human intelligence (HI) based on your company’s Vendor and Risk Management policies.

    My average vendor review is 10 hours per vendor with both BizOps and InfoSec reviews, using standard TPRM methods, and will contain relevant documentation and attachments to make risk based decisions on vendors.

    Yes - $1500 gets you 1 vendor review. Not a vendor program, not a vendor manager, just a single vendor review.

    Seems like a lot of cash huh. Yep, but since you need it and don’t want to do it, pay me, I will do it for you.

    #smallbusiness #RiskManagement #tprm #supplychain #vendormanagement

  28. New line of business- “$1500 Vendor Review”

    I will do a proper Vendor Review using human intelligence (HI) based on your company’s Vendor and Risk Management policies.

    My average vendor review is 10 hours per vendor with both BizOps and InfoSec reviews, using standard TPRM methods, and will contain relevant documentation and attachments to make risk based decisions on vendors.

    Yes - $1500 gets you 1 vendor review. Not a vendor program, not a vendor manager, just a single vendor review.

    Seems like a lot of cash huh. Yep, but since you need it and don’t want to do it, pay me, I will do it for you.

    #smallbusiness #RiskManagement #tprm #supplychain #vendormanagement

  29. 4️⃣ Implement & manage AI tools safely & responsibly. #AIEthics
    5️⃣ Be diligent in vetting third-party vendors. #VendorManagement

  30. Nothing better than finally convincing your 3rd party consultants that you do know what you're doing, and that you've been catching them in their shit for months and months. Take that! #SEO #vendormanagement

  31. Someone I am mentoring asked me a profound question, and @SecureOwl had the best way to teach.

    "do you have a best practice on how do a very basic risk assessment of third party applications / software?"

    MSPs rely on services, and risk assessments for SaaS are always something that has to be done both for clients and internally.

    Mike's methods do not change the need for detailed vendor reviews, but it can help a security practitioner do qualitative research quickly in small, move-fast environments.

    mike-sheward.medium.com/the-60

    #VendorManagement #TPRM #MSP #SMB #InfoSec

  32. And sometimes while doing due diligence on companies you just get really happy they've got their stuff seemingly under control and take the time and effort to properly answer your questions.

    Yay!

    #security #infosec #governance #vendormanagement