Research Hub > infrastructure > Third-Party Risk Management Best Practices | CDW
White Paper
12 min

Third-Party Risk Management Best Practices That Reduce Supply Chain Disruption

To reduce risk and prevent disruption, organizations must strengthen visibility, due diligence, accountability and resilience across their vendor ecosystems.

CDW Expert CDW Expert

IN THIS ARTICLE

Third-party ecosystems are expanding rapidly, and so are the risks they introduce. Today, more than a third of all cybersecurity breaches are linked to third parties, highlighting a critical but often overlooked vulnerability in modern enterprises. 

Organizations often outsource services like payroll, IT support, cloud hosting and other functions, but that does not mean all risks and responsibilities are automatically transferred to vendors. Most of these partnerships operate under a shared responsibility model, and the boundaries are not always clear. 

Combined with evolving threats such as AI-driven attacks and deepfakes, this creates a dangerous visibility gap. By focusing on continuous monitoring, improved visibility and integrated risk strategies, organizations can move from reactive vendor management to proactive third-party risk management (TPRM). 

Frequently, this challenge is too great for internal teams to handle on their own. However, a trusted partner can help organizations reduce supply chain disruption, improve compliance and protect business continuity in a rapidly evolving threat landscape.

Connect with CDW to discuss third-party risk solutions

Third-party ecosystems are expanding rapidly, and so are the risks they introduce. Today, more than a third of all cybersecurity breaches are linked to third parties, highlighting a critical but often overlooked vulnerability in modern enterprises. 

Organizations often outsource services like payroll, IT support, cloud hosting and other functions, but that does not mean all risks and responsibilities are automatically transferred to vendors. Most of these partnerships operate under a shared responsibility model, and the boundaries are not always clear. 

Combined with evolving threats such as AI-driven attacks and deepfakes, this creates a dangerous visibility gap. By focusing on continuous monitoring, improved visibility and integrated risk strategies, organizations can move from reactive vendor management to proactive third-party risk management (TPRM). 

Frequently, this challenge is too great for internal teams to handle on their own. However, a trusted partner can help organizations reduce supply chain disruption, improve compliance and protect business continuity in a rapidly evolving threat landscape.

Connect with CDW to discuss third-party risk solutions

Abstract code

The Expanding Risk Landscape

Third-party risk has become one of the most urgent challenges facing organizations today. As enterprises rely increasingly on external vendors, suppliers and cloud-based services, their attack surfaces expand significantly. 

According to the 2025 Security Scorecard Global Third-Party Breach Report, at least 36% of all data breaches originate from third-party compromises. For ransomware, the figure is 41%. And the true numbers are likely higher, since many organizations are either unaware of the third-party origins of breaches or choose not to disclose the source. 

When outsourcing data storage and workloads, many organizations continue to incorrectly assume they’re also transferring liability — just as they mistakenly assume the same for outsourced payroll, IT support and cloud hosting. Most vendor relationships operate under a shared responsibility model. Contracts and associated service agreements typically establish scope-of-service boundaries that limit vendor liability, leaving organizations exposed if they do not properly understand the boundaries and implement and validate relevant controls. 

The risk goes beyond breaches alone. Organizations face a convergence of pressures related to security and risk management, with regulatory scrutiny, board-level accountability, operational disruption and reputational brand damage all very high on most leaders’ lists of priorities. 

In addition to exposing organizations to cybersecurity risks, third-party relationships can introduce compliance, financial and operational risks simultaneously. According to EY, operational risk now claims the top spot among company considerations when monitoring subcontractors, with 57% of executives who work on TPRM citing operational risk as a factor. And, according to Ncontracts, 73% of organizations are facing pressure to improve TPRM, with 38% identifying internal management and boards as the top source of this pressure. 

For many organizations, TPRM is a highly manual exercise, with risk management teams relying largely on disconnected spreadsheets and numerous lengthy questionnaires. This lack of automation and tooling creates a significant visibility challenge. AI can help streamline repetitive due diligence tasks, using predictive analytics to uncover hidden risks as they emerge and helping  organizations with continuous monitoring of key vendors. In fact, many organizations cannot fully answer these three simple, foundational questions about third-party risk:

  • Who are our third parties (and fourth parties, and beyond)?
  • What access do they have?
  • What data are they handling?

Without this clarity, risk management becomes reactive and incomplete. And emerging technologies complicate the landscape further. AI-driven tools and machine identities are introducing new, often ungoverned, access pathways. These systems can operate autonomously, share data across environments, and even grant access to other systems, creating the potential for exponential risk growth. The World Economic Forum reports that 66% of organizations expect AI to have the most significant impact on cybersecurity over the next year, but only 37% have processes in place to assess the security of AI tools before deployment. 

In this environment, one thing is certain: Ignorance is not bliss. To keep their own environments secure and avoid costly disruptions, leaders must seek to actively understand and manage their third-party ecosystems.

42%

Among financial firms, the percentage of breaches that now involve third parties; another 12% of incidents are fourth-party breaches

Source: Security Scorecard, “Defending the Financial Supply Chain,” May 2025

back-to-top

     Connect with CDW to discuss third-party risk solutions

The Expanding Risk Landscape

Third-party risk has become one of the most urgent challenges facing organizations today. As enterprises rely increasingly on external vendors, suppliers and cloud-based services, their attack surfaces expand significantly. 

According to the 2025 Security Scorecard Global Third-Party Breach Report, at least 36% of all data breaches originate from third-party compromises. For ransomware, the figure is 41%. And the true numbers are likely higher, since many organizations are either unaware of the third-party origins of breaches or choose not to disclose the source. 

When outsourcing data storage and workloads, many organizations continue to incorrectly assume they’re also transferring liability — just as they mistakenly assume the same for outsourced payroll, IT support and cloud hosting. Most vendor relationships operate under a shared responsibility model. Contracts and associated service agreements typically establish scope-of-service boundaries that limit vendor liability, leaving organizations exposed if they do not properly understand the boundaries and implement and validate relevant controls. 

The risk goes beyond breaches alone. Organizations face a convergence of pressures related to security and risk management, with regulatory scrutiny, board-level accountability, operational disruption and reputational brand damage all very high on most leaders’ lists of priorities. 

In addition to exposing organizations to cybersecurity risks, third-party relationships can introduce compliance, financial and operational risks simultaneously. According to EY, operational risk now claims the top spot among company considerations when monitoring subcontractors, with 57% of executives who work on TPRM citing operational risk as a factor. And, according to Ncontracts, 73% of organizations are facing pressure to improve TPRM, with 38% identifying internal management and boards as the top source of this pressure. 

For many organizations, TPRM is a highly manual exercise, with risk management teams relying largely on disconnected spreadsheets and numerous lengthy questionnaires. This lack of automation and tooling creates a significant visibility challenge. AI can help streamline repetitive due diligence tasks, using predictive analytics to uncover hidden risks as they emerge and helping  organizations with continuous monitoring of key vendors. In fact, many organizations cannot fully answer these three simple, foundational questions about third-party risk:

  • Who are our third parties (and fourth parties, and beyond)?
  • What access do they have?
  • What data are they handling?

Without this clarity, risk management becomes reactive and incomplete. And emerging technologies complicate the landscape further. AI-driven tools and machine identities are introducing new, often ungoverned, access pathways. These systems can operate autonomously, share data across environments, and even grant access to other systems, creating the potential for exponential risk growth. The World Economic Forum reports that 66% of organizations expect AI to have the most significant impact on cybersecurity over the next year, but only 37% have processes in place to assess the security of AI tools before deployment. 

In this environment, one thing is certain: Ignorance is not bliss. To keep their own environments secure and avoid costly disruptions, leaders must seek to actively understand and manage their third-party ecosystems.

Connect with CDW to discuss third-party risk solutions.

Third-Party Risk: By the Numbers

54%

The percentage of IT leaders at large organizations that identify supply chain challenges as the biggest barrier to achieving cyber resilience

 Source: World Economic Forum, “Global Cybersecurity Outlook 2025,” January 2025

49%

The percentage of organizations that review and assess third-party performance against contract standards; 24 % use independent rating services or tools to monitor third-party risk levels

63%

The percentage of TPRM programs that operate with just one or two dedicated employees, who may manage as many as 300-plus vendor relationships; 13% have no dedicated staff at all

Source: Ncontracts, “The State of Third-Party Risk Management 2026,” March 2026

Third-Party Risk: By the Numbers

54%

The percentage of IT leaders at large organizations that identify supply chain challenges as the biggest barrier to achieving cyber resilience

 Source: World Economic Forum, “Global Cybersecurity Outlook 2025,” January 2025

49%

The percentage of organizations that review and assess third-party performance against contract standards; 24 % use independent rating services or tools to monitor third-party risk levels

63%

The percentage of TPRM programs that operate with just one or two dedicated employees, who may manage as many as 300-plus vendor relationships; 13% have no dedicated staff at all

Source: Ncontracts, “The State of Third-Party Risk Management 2026,” March 2026

cdw

Building a Strong TPRM Foundation

Effective third-party risk management begins with governance, clarity, structure and accountability across the vendor lifecycle. As the business world becomes even more digital, organizations are expanding their reliance on external providers — including cloud hyperscalers, Software as a Service (SaaS) providers and AI-enabled platforms — which can expand organizations’ attack surfaces. To establish a strong TPRM foundation, organizations must inventory their vendor ecosystem, map access and data flows, prioritize risks and standardize due diligence, all while validating vendor claims at every step of the process. 

KNOW YOUR VENDORS: A comprehensive inventory of third parties is the obvious starting point for any effective TPRM program. However, many organizations lack a complete and current view of their vendor ecosystem. This gap is particularly pronounced for fourth-party and downstream dependencies. (According to Ncontracts, 58% of organizations report that they review their vendors’ vendors, but 35% say they only monitor especially critical or high-risk fourth-party vendors, and 26% do not monitor or assess fourth parties at all.) Closing this visibility gap requires more than maintaining a simple list of current vendors. Organizations must continuously identify, document and update all vendor relationships, including vendor-of-vendor dependencies.

MAP ACCESS AND DATA FLOWS: Understanding who has access to systems and how data moves between them is essential for identifying and managing risk. But the shared responsibility model complicates things. While vendors may provide secure platforms and services, organizations are often responsible for configuring and managing access within those environments. 

According to Gartner, under half (46%) of organizations clearly define the roles and responsibilities associated with due diligence and risk identification. Misunderstandings and missteps here can lead to significant security gaps, particularly when organizations assume that vendors are managing access controls that remain their own responsibility.

ASSESS RISK BY CRITICALITY: Not all risks are equal. A third-party vulnerability that exposes low-sensitivity operational information may be a nuisance, while a gap that exposes customer data, financial systems or intellectual property could be catastrophic. Effective TPRM programs prioritize vendors based not only on whether a risk exists, but also on the potential operational and financial impacts if that risk were to be exploited. Ncontracts reports that most organizations classify 5% or less of their vendor pool as “critical,” enabling TPRM teams to focus their oversight activities on the relationships that matter most. 

STANDARDIZE DUE DILIGENCE: Due diligence is a foundational component of TPRM, surfacing the information leaders need to evaluate vendor controls and risk posture. Common practices include questionnaires, control assessments, security operations center (SOC) reports and minimum requirements for insurance or certifications. However, in many organizations, due diligence processes are inconsistent, duplicative or cumbersome. Vendors may be asked to complete multiple questionnaires covering similar topics, while internal teams may struggle to interpret and act on the information collected. Gartner notes that organizations with streamlined due diligence questionnaires are actually far more likely to surface potential risks than those with a more exhaustive approach. 

VALIDATE, DON’T ASSUME: One of the most overlooked risks in TPRM arises from overreliance on vendor attestations and assurance reports. SOC reports and similar documents are valuable tools, but they are frequently misunderstood, and they may not provide the level of assurance organizations expect. For example, a SOC report may attest to certain controls in place but also contain language noting that a subservice provider is used. If the SOC report indicates that the subservice provider is “carved out,” then there is no visibility over the subservice provider’s control posture, which can create hidden gaps in risk assurance that can only be uncovered with proactive due diligence.

Click Below To Continue Reading

arrow

3 Key TPRM Questions

By simply answering these three questions, leaders can build a foundation for a scalable third-party risk management program.

1. Who are our third parties (and fourth parties and beyond)?

Organizations first need a complete view of the vendors that support the business. This inventory should include not only direct relationships but also downstream suppliers and service providers that can impact operations, security or compliance. 

2. What access do they have?

Third parties may connect to internal systems, cloud environments, credentials, privileged accounts or operational technology environments. Understanding this access helps organizations differentiate routine vendor relationships from higher-risk exposure points. 

To minimize third-party risks, it’s essential to implement consistent and rigorous procedures throughout your vendor lifecycle. During onboarding, you create a secure foundation by thoroughly assessing vendors’ security and compliance. Offboarding, meanwhile, promptly revokes data and terminates system access, safeguarding your organization from potential threats.

3. What data do they handle?

Organizations must also understand what information third parties store, process, transmit or support. Vendors that handle regulated, confidential or business-critical data require stronger oversight than those with limited exposure.

back-to-top-white
cdw

Building a Strong TPRM Foundation

Effective third-party risk management begins with governance, clarity, structure and accountability across the vendor lifecycle. As the business world becomes even more digital, organizations are expanding their reliance on external providers — including cloud hyperscalers, Software as a Service (SaaS) providers and AI-enabled platforms — which can expand organizations’ attack surfaces. To establish a strong TPRM foundation, organizations must inventory their vendor ecosystem, map access and data flows, prioritize risks and standardize due diligence, all while validating vendor claims at every step of the process. 

KNOW YOUR VENDORS: A comprehensive inventory of third parties is the obvious starting point for any effective TPRM program. However, many organizations lack a complete and current view of their vendor ecosystem. This gap is particularly pronounced for fourth-party and downstream dependencies. (According to Ncontracts, 58% of organizations report that they review their vendors’ vendors, but 35% say they only monitor especially critical or high-risk fourth-party vendors, and 26% do not monitor or assess fourth parties at all.) Closing this visibility gap requires more than maintaining a simple list of current vendors. Organizations must continuously identify, document and update all vendor relationships, including vendor-of-vendor dependencies.

MAP ACCESS AND DATA FLOWS: Understanding who has access to systems and how data moves between them is essential for identifying and managing risk. But the shared responsibility model complicates things. While vendors may provide secure platforms and services, organizations are often responsible for configuring and managing access within those environments. 

According to Gartner, under half (46%) of organizations clearly define the roles and responsibilities associated with due diligence and risk identification. Misunderstandings and missteps here can lead to significant security gaps, particularly when organizations assume that vendors are managing access controls that remain their own responsibility.

ASSESS RISK BY CRITICALITY: Not all risks are equal. A third-party vulnerability that exposes low-sensitivity operational information may be a nuisance, while a gap that exposes customer data, financial systems or intellectual property could be catastrophic. Effective TPRM programs prioritize vendors based not only on whether a risk exists, but also on the potential operational and financial impacts if that risk were to be exploited. Ncontracts reports that most organizations classify 5% or less of their vendor pool as “critical,” enabling TPRM teams to focus their oversight activities on the relationships that matter most. 

STANDARDIZE DUE DILIGENCE: Due diligence is a foundational component of TPRM, surfacing the information leaders need to evaluate vendor controls and risk posture. Common practices include questionnaires, control assessments, security operations center (SOC) reports and minimum requirements for insurance or certifications. However, in many organizations, due diligence processes are inconsistent, duplicative or cumbersome. Vendors may be asked to complete multiple questionnaires covering similar topics, while internal teams may struggle to interpret and act on the information collected. Gartner notes that organizations with streamlined due diligence questionnaires are actually far more likely to surface potential risks than those with a more exhaustive approach. 

VALIDATE, DON’T ASSUME: One of the most overlooked risks in TPRM arises from overreliance on vendor attestations and assurance reports. SOC reports and similar documents are valuable tools, but they are frequently misunderstood, and they may not provide the level of assurance organizations expect. For example, a SOC report may attest to certain controls in place but also contain language noting that a subservice provider is used. If the SOC report indicates that the subservice provider is “carved out,” then there is no visibility over the subservice provider’s control posture, which can create hidden gaps in risk assurance that can only be uncovered with proactive due diligence.

Click Below To Continue Reading

arrow

3 Key TPRM Questions

By simply answering these three questions, leaders can build a foundation for a scalable third-party risk management program.

1. Who are our third parties (and fourth parties and beyond)?

Organizations first need a complete view of the vendors that support the business. This inventory should include not only direct relationships but also downstream suppliers and service providers that can impact operations, security or compliance. 

2. What access do they have?

Third parties may connect to internal systems, cloud environments, credentials, privileged accounts or operational technology environments. Understanding this access helps organizations differentiate routine vendor relationships from higher-risk exposure points. 

To minimize third-party risks, it’s essential to implement consistent and rigorous procedures throughout your vendor lifecycle. During onboarding, you create a secure foundation by thoroughly assessing vendors’ security and compliance. Offboarding, meanwhile, promptly revokes data and terminates system access, safeguarding your organization from potential threats.

3. What data do they handle?

Organizations must also understand what information third parties store, process, transmit or support. Vendors that handle regulated, confidential or business-critical data require stronger oversight than those with limited exposure.

Connect with a CDW expert to discuss building or improving your TPRM program.

Absolute
Absolute
Cloudflare
KnowBe4