Resolving Supply Chain Cyber Gaps
The cybersecurity threat landscape is significant, and it's still expanding as new technologies roll out across industries. Providing protections within organisations is a full-time endeavor. No organization is an island (to paraphrase John Donne's famous idiom), and most have dozens, hundreds, or even thousands of third-party suppliers for services and goods. Many of these suppliers are interacted with digitally via IT systems. From simply using email at one end of the spectrum to full integration of particular business systems at the more complex end.
Cybersecurity professionals within companies, or more frequently now, their outsourced IT security service providers, need to ensure that any electronic interactions with third parties do not introduce vulnerabilities that cybercriminals can exploit. This method of attack and bypassing of an organisations cyber-defences is called a supply chain attack.
Evaluating Supplier Cybersecurity Risk
Vetting third-party organisations to ensure that their cybersecurity provisions are of a high enough standard to protect themselves, and by extension, meet the security requirements of the organisations they digitally interact with is a core part of the cybersecurity function. Traditionally this vetting has been done via questionnaires sent to the organisations to complete, combined with external assessment of the third-party supplier’s cyber-defences via penetration testing or other cybersecurity probing techniques. These methods are time-consuming, and they often rely heavily on trusting the third party filling out the questionnaire. Plus, each assessment of a third-parties security posture is a snapshot at that time and is probably out of date within days given how fast the cybersecurity landscape changes. The process often doesn't capture any security issues with suppliers to the third party further up the supply chain. The fourth-party problem as it's known.
There is a better way to survey and establish the security posture of third parties and their suppliers across the whole supply chain cybersecurity environment. The better way is Panorays third-party vendor security management. The Panorays solution automates surveys and other security investigations into third parties (and their suppliers). As a result, the 2021 Forrester Cybersecurity Risk Ratings Platforms report places Panorays in the Strong Performers group. Forrester had this to say about Panorays:
Stands out for its workflow capabilities, accuracy, and risk context. Panorays differentiates with its complete questionnaire capabilities, accuracy, and workflow. The risk context delivered by Panorays combines human factors, questionnaire management for third parties, and a simple-to use fourth-party discovery feature.
And the report went on to say that Panorays customers praised the solution as follows:
Panorays references praised the accuracy of the platform, high-quality ratings reports, and low false positives rates.
A cybersecurity risk evaluation and management platform is essential for all organisations to ensure that their suppliers are not introducing a security risk. Renaissance are the distribution partner for Panorays in Ireland. Together we can ensure that organisations and security providers of all sizes have the best platform to evaluate third-party risk, and more importantly, address and remove any risks so that profitable supply chain partnerships can flourish. Contact us today to find out more, and read on for a brief overview of supply chain risk management and how Panorays addresses the issue.
The Supply Chain Security Threat
Many cyberattacks that have made the news during the last year had a supply chain attack at their root. Irrespective of how the attack ultimately played out - ransomware, data theft, deployment of additional malware, state-level & industrial espionage, or even malicious damage. The entry method was often via third-party supplier systems or the software they supplied to the attacked organisation.
Business size is not a determinant of cybersecurity risk. The Verizon Business 2020 Data Breach Investigations Report found that 28% of all data breaches that year occurred in small businesses. Data breaches are a very damaging form of cyberattack as they can lead to substantive reputational damage and fines under regulations such as GDPR.
Small businesses often don't have the resources to vet their supplier's cybersecurity posture properly. And large companies often find it hard to recruit the right professionals. The Panorays platform is an ideal solution for them, or their IT security partners to mitigate the risk from supply chain attacks via third-party suppliers.
Panorays Cybersecurity Risk Platform
The Panorays platform combines automated, dynamic security questionnaires (Smart Questionnaires) with non-intrusive external attack surface assessments and business relationship context. It is the only such platform that automates, accelerates, and scales third-party security evaluation and management. It simplifies and speeds up third-party security risk evaluation and the process of vetting potential supplier’s security.
Panorays continuously monitors and evaluates supplier cybersecurity and sends alerts about any security changes or breaches that occur in third parties. As a result, it allows businesses to decide quickly whether to risk dealing with new suppliers and whether to continue the relationship if their cybersecurity posture deteriorates.
Panorays works on a five-stage cycle that combines information from inside-out evaluations (via the automated questionnaire process) and outside-in assessments (the hacker view of the organisation):
- Analysis - a deep gap analysis of all the information gathered.
- Engagement - organisation and third parties together evaluate the findings.
- Remediation - the platform provides remediation guidance to address cybersecurity gaps in supply chain partners.
- Approval - Business approves supplier for a business relationship when all issues addressed.
- Monitoring - the Panorays platform provides continuous ongoing monitoring and alerts on any new issues. New issues are dealt with from step 1 when discovered.
In addition to evaluating and helping suppliers improve their cybersecurity posture, the Panorays platform is invaluable when assessing other businesses' cybersecurity posture during mergers and acquisitions. For example, organisations can evaluate the cybersecurity risk of integrating the systems from the merging organisation in the same way that they assess suppliers.
Find Out More
Panorays can reduce the risk from what is a widespread attack vector. See the Panorays site for more detailed information, and contact Renaissance to discuss how the solution can improve your supply-chain cybersecurity posture.

