Vendor Vulnerabilities: Understanding Third-Party Risk Management

Goering Center Blog

2026

Vendor Vulnerabilities: Understanding Third-Party Risk Management

Vendor Vulnerabilities: Understanding Third-Party Risk Management

Goering Center Newsletter for February | Third-Party Risk Management Article

Local contact to include (not author):

Ryan Reckman – Commercial Group Manager, Huntington Bank

Vendor vulnerabilities: Understanding third-party risk management

Imagine discovering one of your vendors has suffered a data breach. Suddenly, despite all the cybersecurity controls you’ve put in place, your organization is exposed. It’s a tough reality, but not an uncommon one.

As businesses increasingly rely more on third-party providers for every type of service from cloud storage to customer management, our digital perimeter is expanding. This creates more opportunities, but it also means more risk and exposure.

The answer is not to eliminate all reliance on third party vendors. Instead, companies should endeavor to understand their third-party risks, strengthen risk management practices to build resiliency, and build a sustainable third-party risk management framework.

How third-party risk impacts businesses

Third-party risk refers to the potential disruptions, losses, and security vulnerabilities that arise from outsourcing business operations to external entities. These entities include vendors, service providers, or suppliers that have access to your data, systems, or processes.

Data responsibility represents one such third-party risk: When your company shares data with third parties, you retain responsibility for its security. If a vendor experiences a data breach that exposes a company’s data, that company may be liable and face consequences, including notification requirements, legal and financial penalties, operational disruption, reputational damage, and costs for investigation and mitigation.

Risks associated with third parties aren’t limited to your vendors. If a secondary entity – vendors your primary vendor relies on – suffers a security breach, it could unexpectedly introduce risk into your environment.

Best practices to help mitigate third-party risk

  • Develop an incident response plan: This guides an organization’s response to an incident and includes regular tabletop exercises with all stakeholders that simulate vendor security breaches to test responses and refine strategies.
  • Employee training and awareness: Employees play a critical role in maintaining cybersecurity in your organization. Provide training to educate employees about risks associated with third-party vendors and their role in preventing and responding to security events.
  • Third-party security audits: Schedule periodic security audits to evaluate the cybersecurity measures of third-party vendors, then use the results to identify and address discrepancies or vulnerabilities.
  • Vulnerability management: Threat actors can exploit vulnerabilities, or security weaknesses, in networks, software, operating systems, and equipment – and they do, often. Managing vulnerabilities is one way in which organizations could help prevent malicious access through compromised vendor software or systems.
  • Regulatory compliance: Ensure your company and its vendors adhere strictly to these regulations to avoid legal and reputational risks, especially if your organization is beholden to additional regulatory standards.
  • Dedicated third-party management team: Establishing a dedicated third-party risk management program or team can further help organizations centralize oversight of vendor, supplier, and other third-party relationships. Bringing this responsibility into one place can help enhance the effectiveness of risk management strategies and ensure compliance with security standards.

Managing risk from vendors, suppliers, and other third parties

Businesses will continue to rely on third parties to access specialized expertise, reduce costs, and enhance efficiencies. As this reliance grows, so do the risks associated with it. However, organizations can help mitigate risks by holding their vendors to the same security standards they follow, building a strong incident response plan, and dedicating a team to protect against threats.

Disclosures

The information provided in this document is intended solely for general informational purposes and is provided with the understanding that neither Huntington, its affiliates nor any other party is engaging in rendering tax, financial, legal, technical or other professional advice or services or endorsing any third-party product or service. Any use of this information should be done only in consultation with a qualified and licensed professional who can take into account all relevant factors and desired outcomes in the context of the facts surrounding your particular circumstances. The information in this document was developed with reasonable care and attention. However, it is possible that some of the information is incomplete, incorrect, or inapplicable to particular circumstances or conditions. NEITHER HUNTINGTON NOR ITS AFFILIATES SHALL BE LIABLE FOR ANY DAMAGES, LOSSES, COSTS OR EXPENSES (DIRECT, CONSEQUENTIAL, SPECIAL, INDIRECT OR OTHERWISE) RESULTING FROM USING, RELYING ON OR ACTING UPON INFORMATION IN THIS DOCUMENT OR THIRD-PARTY RESOURCES IDENTIFIED IN THIS DOCUMENT EVEN IF HUNTINGTON AND/OR ITS AFFILIATES HAVE BEEN ADVISED OF OR FORESEEN THE POSSIBILITY OF SUCH DAMAGES, LOSSES, COSTS OR EXPENSES.

Huntington, Huntington Bank, and the Huntington Brandmark are service marks of Huntington Bancshares Incorporated.