Third-Party Cyber Risk Management - W Training

Third-Party Cyber Risk Management

Course Category : Risk Management

A specialised programme for establishing an integrated approach to identifying, assessing, monitoring, and governing cyber risks arising from vendors, partners, and external service providers throughout the third-party lifecycle.

Introduction

Modern organisations increasingly depend on extensive ecosystems of vendors, partners, cloud providers, contractors, and technology suppliers. This dependency extends the cyber risk perimeter beyond direct organisational control, making weaknesses within a third party potentially consequential for information confidentiality, service continuity, and regulatory compliance.
This course addresses third-party cyber risk management through an integrated governance perspective, covering third-party identification and segmentation, cyber due diligence, risk assessment, contractual controls, continuous monitoring, incident coordination, and secure relationship termination..

Targeted Audience

  • Cybersecurity and Information Security Managers
  • Enterprise and Cyber Risk Professionals
  • Cybersecurity Governance and Compliance Officers
  • Vendor and Third-Party Management Professionals
  • Procurement and Technology Contract Specialists
  • Internal Audit and Control Professionals
  • Business Continuity and Operational Resilience Professionals
  • Technology Leaders Responsible for Outsourced and Cloud Services

Targeted Skills

  • Third-Party Cyber Risk Governance
  • Vendor Criticality and Risk Segmentation
  • Cybersecurity Due Diligence and Assessment
  • Inherent and Residual Risk Analysis
  • Contractual Cybersecurity Control Definition
  • Continuous Third-Party Risk Monitoring
  • Third-Party Cyber Incident Management
  • Cyber Risk and Performance Indicator Development

Expected Outcomes

  • Explain the principal cyber risks created by third-party dependencies.
  • Establish a structured approach for vendor identification, criticality classification, and risk segmentation.
  • Assess third-party cybersecurity posture against defined requirements and controls.
  • Distinguish inherent risk, existing controls, and residual cyber risk.
  • Define appropriate cybersecurity requirements within contracts and service agreements.
  • Develop an approach for continuous monitoring and periodic reassessment.
  • Structure responses to cyber incidents involving vendors and external partners.
  • Support informed decisions on risk acceptance, treatment, escalation, and remediation.

Training Topics Index

  • Third-party ecosystems and sources of cyber exposure
  • Identification of relevant vendors, partners, and service providers
  • Third-party segmentation based on criticality, data access, and system access
  • Inherent risk, residual risk, and risk appetite
  • Governance structures, roles, responsibilities, and accountability

  • Pre-contract cybersecurity assessment and vendor selection
  • Cybersecurity questionnaires and assessment requirements
  • Evaluation of access, data, identity, and service continuity controls
  • Evidence analysis, control gaps, and risk determination
  • Findings documentation, remediation plans, and risk acceptance decisions

  • Cybersecurity requirements in contracts and service-level agreements
  • Audit rights, incident notification, and information protection provisions
  • Fourth-party and extended supply-chain dependencies
  • Change management, renewal, and periodic reassessment
  • Secure termination, access revocation, and data disposition

  • Transition from periodic assessment to continuous oversight
  • Vendor-related Key Risk Indicators and Key Performance Indicators
  • Monitoring vulnerabilities, incidents, and risk-profile changes
  • Escalation of non-compliance and overdue remediation
  • Management reporting and third-party cyber risk dashboards

  • Third-party cyber incident management
  • Responsibilities, communication, and escalation during incidents
  • Concentration risk and dependency on critical providers
  • Business continuity and resilience against third-party disruption
  • TPRM maturity measurement and continuous improvement

Course Features

  • Updated and Interactive Content
  • Hypothetical Examples and Case Studies
  • Pre- and Post-assessments to Measure Impact
  • Verified Certificate with a QR Verification Code

No suitable date? Register your interest in this course and our team will contact you to arrange the date and location.

Register for this Course