A TPRM Perspective on Cybersecurity Risk | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Business leaders are entering the second half of 2026 with a clear signal: growth depends on how well organizations spread risk and opportunity across markets, supply chains, capital, and technology. In the C-Suite Barometer 2026 mid-year survey from Forvis Mazars, 57% of executives named diversifying resources as their leading response to uncertainty, the top answer globally. Growth optimism held steady at 92%, but the Confidence Index dropped eight points to 35%, its lowest reading since 2021, and the Investment Index softened by seven points to 62%.

The combination of ambition paired with lagging confidence is reshaping how organizations engage third parties. U.S. leaders are moving in the same direction, only faster. In the U.S. C-Suite Barometer, 97% of executives report optimism about growth, with transforming IT and technology as the top strategic priority across industries and company sizes, and nearly nine in 10 companies have restructured teams to implement AI. More vendors, more AI-embedded tools, more cross-border activity, and more supply chain diversification all point to a wider third-party attack surface and higher expectations for how organizations govern it.

For any organization that relies on third parties for more than incidental services, vendor cybersecurity risk sits at the intersection of operational resilience, incident response, regulatory scrutiny, and board reporting. Third-Party Risk Management (TPRM) is where that intersection can be managed.

Cybersecurity risk has moved from a control conversation to an operational resilience conversation, and TPRM may need to answer for both.

What Has Changed in the Third-Party Risk Landscape?

Third-party cybersecurity risk refers to the potential security, privacy, and/or operational impacts that can arise from an organization’s relationships with external vendors and service providers.

Three areas of focus can change the scoping, tiering, and evidencing of vendor cybersecurity risk:

  1. Vendors have become part of core workflows. Cloud service providers, artificial intelligence (AI) tooling, and specialized Software as a Service (SaaS) platforms are now embedded within finance, human resources, operations, and customer service. When a critical vendor goes down or gets compromised, the business feels it within hours, not weeks.
  2. Investment is being redirected toward stabilizers. In the mid-year C-Suite Barometer survey, supply chain and supplier management became higher priorities for capital expenditures, sitting alongside AI (72%) and customer acquisition (70%) as leading investment areas, which helps elevate vendor governance from a compliance function to a growth enabler.
  3. The macro backdrop has reshuffled. Economic trends (40%), energy prices and shortages (37%), and geopolitical instability (32%) now lead the list of forces expected to influence business, with AI slipping to second place. Each of those forces has a vendor dimension: concentration risk, fourth- and fifth-party exposure, and cross-border data flows subject to overlapping regulatory guidance.

The regulatory environment has moved in parallel. Interagency guidance from the Office of the Comptroller of the Currency (OCC), Federal Reserve, and FDIC has clarified expectations for due diligence, contracting, and continuous monitoring. State-level requirements such as NYDFS Part 500 amendments speak directly to third-party governance. Cross-border activity brings additional expectations from frameworks, including the Digital Operational Resilience Act (DORA) and the Network and Information Systems (NIS2) Directive, and industry frameworks such as HITRUST® and the Payment Card Industry Data Security Standard (PCI DSS) continue to inform how vendor controls are evaluated.

How to Assess Vendor Cybersecurity Risk

Vendor cybersecurity risk assessments can be the most useful when they connect technical concerns to the actual vendor relationship. Before reviewing a vendor’s control evidence, organizations should confirm what services the vendor provides, what data or systems the vendor can access, whether subservice organizations are involved, and how critical the vendor is to daily operations.

Common areas that may require closer attention include the following:

  • Scope mismatch, where vendor evidence does not cover the services, systems, or locations the organization uses;
  • Unclear access responsibilities, particularly when the vendor has privileged or administrative access;
  • Downstream dependency risk, including subservice organizations that support sensitive processing or critical operations;
  • Unclear business continuity evidence, where recovery commitments are stated but not supported by testing or reporting;
  • Incident notification gaps, including timelines that may not align with the organization’s regulatory or customer obligations; and
  • New technology usage, including AI-enabled services or data-processing activities not reflected in the original vendor review.

Organizations that manage these reviews well treat cybersecurity as one component of a broader vendor risk profile.

What Should TPRM Teams Look for in Vendor Evidence?

System and Organization Controls (SOC) and HITRUST Reports can help TPRM teams move beyond questionnaires and vendor assertions. These reports can be especially useful when a vendor supports critical financial, operational, and/or data-sensitive activities.

Rather than using the reports as a check-the-box requirement, TPRM teams should use them to help inform business decisions. Key questions to consider include the following:

  • Does the report cover the service the organization uses?
  • Does the reporting period align with the organization’s review cycle?
  • Are there exceptions that affect relevant controls or services?
  • Are Complementary User Entity Controls (CUECs) clearly understood and assigned?
  • Are subservice organizations identified and addressed appropriately?
  • Does the evidence support the vendor’s assigned risk tier?
  • Are follow-up items documented and tracked until they are closed or formally accepted?

SOC & HITRUST practitioners at Forvis Mazars can help organizations evaluate whether third-party evidence is complete, relevant, and aligned with the services being used.

Can SOC Reports Be Defensible Evidence?

Independent assessments can carry more weight in a diversification-driven environment because they translate vendor claims into evidence that boards, regulators, and business partners can use.

SOC 1 and SOC 2 Reports can help organizations understand how controls are designed and how they operate at service organizations. Reports should be evaluated in context. Scope, report type, opinion, testing results, CUECs, and subservice organizations may each affect the review.

A defensible vendor risk management review typically documents the following:

  • Scope alignment between the services used and the services covered in the report;
  • Testing results and exceptions, with an indication of whether identified issues affect the user entity;
  • CUEC coverage, with evidence that the receiving organization has implemented the controls it’s expected to operate;
  • Subservice organization treatment, whether carve-out or inclusive, and how downstream risk is monitored; and
  • Report cadence and bridge letters covering periods between report dates.

For organizations working with vendors that handle personal information or higher-risk data, HITRUST Assessments can add depth by mapping controls to a broad set of regulatory and industry sources. Both SOC and HITRUST evidence can provide TPRM programs with a defensible foundation for the decisions that follow.

Actions to Consider

Vendor cybersecurity risk reviews can involve many variables, including service scope, report cadence, subservice organizations, contractual obligations, and the organization’s own risk tolerance. As a starting point, organizations may want to focus on these three areas:

  • Refresh your vendor inventory and confirm that risk tiering reflects current service scope, data access, AI usage, and business criticality.
  • Standardize how SOC and HITRUST Reports are reviewed so teams evaluate scope, opinion, testing results, CUECs, and subservice organizations consistently.
  • Retain review documentation so vendor risk decisions can be explained to auditors, regulators, and the board if questions arise.

How Forvis Mazars Can Help

Our SOC & HITRUST professionals can help organizations strengthen cybersecurity oversight of critical vendors in a defensible manner. Whether you are refreshing a mature program or building a structured approach, we can help you assess your current state, strengthen contracts and controls, and connect vendor risk to operational resilience. Connect with us today to learn more.

——————————————————-


Click Here For The Original Source.