DTG-SC35 · Third-Party & Supply Chain · 4 min

Third-Party Data Flows Are the Biggest Unaudited Surface in Most Enterprises

Every internal data flow in a mature enterprise has some form of governance: a data architecture record, an access control, a monitoring capability, a retention policy.

DTG-SC33 · Third-Party & Supply Chain · 4 min

Holding Vendors Accountable Requires Evidence, Not Assurances

Vendor assurances are statements about what the vendor does. They appear in questionnaire responses, in sales presentations, in contract representations, and in certifica…

DTG-SC32 · Third-Party & Supply Chain · 4 min

Vendor Concentration Risk Is a Governance Problem, Not Just an Ops Problem

Vendor concentration risk is the risk that the organization's dependence on a small number of vendors for critical functions creates an exposure that the organization can…

DTG-SC31 · Third-Party & Supply Chain · 4 min

The Questionnaire Said Compliant. The Audit Said Different

The vendor completed the security questionnaire. Every question received a positive response. Multi-factor authentication: implemented. Encryption at rest: implemented.

DTG-SC29 · Third-Party & Supply Chain · 4 min

When the Cloud Provider Goes Down and Your BCP Assumed It Wouldn't

The business continuity plan was comprehensive. It covered data center fires, network outages, hardware failures, and cyberattacks. It covered regional disasters with fai…

DTG-SC28 · Third-Party & Supply Chain · 5 min

Inherited Data From an Acquisition Is Inherited Liability

The acquisition closed on a Thursday. By the following Monday, the acquiring organization had inherited the acquired company's customer base, their revenue contracts, the…

DTG-SC26 · Third-Party & Supply Chain · 4 min

How Shadow Procurement Creates Shadow Risk

Shadow IT is the technology adopted outside formal IT governance. Shadow procurement is the mechanism through which most shadow IT arrives: a business team identifies a t…

DTG-SC22 · Third-Party & Supply Chain · 4 min

The Difference Between a Vendor Contract and Vendor Accountability

The contract specifies what the vendor is required to do. It defines data handling obligations, security standards, breach notification timelines, audit rights, and remed…

DTG-SC19 · Third-Party & Supply Chain · 4 min

The Annual Vendor Review That Changes Nothing

The annual vendor review is scheduled, conducted, documented, and closed. The vendor completes the updated questionnaire. The questionnaire is scored.

DTG-SC16 · Third-Party & Supply Chain · 4 min

Why Procurement and Security Still Don't Talk About the Same Risks

Procurement manages vendor relationships through the lens of commercial risk: price, delivery, contract terms, supplier financial stability, and performance against servi…

DTG-SC13 · Third-Party & Supply Chain · 4 min

Continuous Vendor Monitoring Is Not Optional in a Dynamic Supply Chain

The argument for continuous vendor monitoring used to be a preference. Organizations with mature TPRM programs invested in ongoing monitoring because it was better practi…

DTG-SC08 · Third-Party & Supply Chain · 5 min

The Supply Chain Attack Nobody Modeled For

The threat model covered the obvious vectors. Direct attacks on internet-facing systems. Phishing campaigns targeting employees. Credential theft and lateral movement.

DTG-SC07 · Third-Party & Supply Chain · 5 min

What Happens to Your Data After It Leaves Your Environment?

This is not a rhetorical question. It is a governance question that most organizations cannot answer completely, and the completeness of the answer is a direct indicator…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center