CONTACT US
Third Party Risk Management - Consultancy, Assessment & Advisory

Blog

Maintaining “Business As Usual” through COVID-19 – A letter from our Managing Director

Remote Working Strategy to Support our Staff and Customers  In response to the latest guidance from the British Government and NHS regarding COVID-19, DVV Solutions have, like many businesses, activated our remote working strategy across the organisation. We have taken this decision primarily in the interests of ensuring the safety of our employees and their…

LEARN MORE

The 7 Essential Disciplines of Third-Party Risk Management Programs

In an era when corporations commonly have hundreds and sometimes hundreds of thousands of third-party suppliers, managing the risk these third parties represent is no small task yet has become essential for corporate success. Obviously in these circumstances, your third-party risk-management (TPRM) program becomes critical to ensure operational continuity and possibly even financial survival. But…

LEARN MORE

Risk Management & Natural Disasters – Mother Nature, The Ultimate Regulator

Headlines like “Coronavirus Outbreak,” “Killer Cyclone”, “Catastrophic Bushfires”, and “Deadly Earthquake” are happening with alarming and increasing frequency. Unfortunately what were “once-in-a-century disasters” are taking place with frightening regularity. Extreme weather, infectious diseases, natural disasters and climate action failure are among the most destructive, impactful, and at the same time, most likely to occur global…

LEARN MORE

Responding to Coronavirus Disease 2019 (COVID-19): Business Continuity & Resilience

With the current reaction to the Coronavirus epidemic in the US, you might be surprised to know that the CDC’s current goal of mitigation involves slowing down the spread of infection so that the epidemic lasts longer. That’s right, the CDC actually wants to spread out, the spread of this disease. Though on the surface…

LEARN MORE

What is “Cyber Risk” in Third-Party Cyber Risk Management?

Continuing NormShield’s blog series on third-party cyber risk management, this article’s topic is Cyber Risk. In a digital world, organisations are exposed to a range of risks resulting from cyber events like phishing, data theft, ransomware, corporate espionage, etc… What’s more, these events might happen beyond the company’s knowledge. Within a company ecosystem, the effect…

LEARN MORE

What is “Third-Party” in Third-Party Risk Management?

Businesses rely on Third-Parties to deliver a service or product to their customers. In a tightly-linked digital world, Third-Parties are indispensable and inherently risky elements of a digital ecosystem. Before going deep into the risks they pose to the business, we need to understand the definition and be able to identify the ones critical to…

LEARN MORE

Monitoring Third-Parties Continuously – A NIST Perspective

NIST released two industry standards to drive security requirements around supply-chain (a.k.a third-party) management. Here’s an overview of the NIST guidelines regarding continuous third-party risk monitoring. NIST 800-53 NIST 800-53 Security and Privacy Controls for Federal Information Systems and Organisations sets out guidelines and controls for protecting the government’s sensitive information as well as citizens’ personal information…

LEARN MORE

Dynamic Due Diligence – The Shared Assessments TPRM Framework Module 6

While at first glance the topic of due diligence may appear to be a stodgy one, the reality of a rapidly changing risk landscape and the evolution of due diligence techniques suggests that the opposite is true. The latest section of the Shared Assessments Third Party Risk Management (TPRM) Framework has just been released, providing…

LEARN MORE

Monitoring Third-Parties Continuously: A NIST Perspective

NIST released two industry standards to drive security requirements around supply-chain (a.k.a Third-Party) management. Here’s an overview of the NIST guidelines regarding continuous Third-Party risk monitoring.   NIST 800-53 NIST 800-53 Security and Privacy Controls for Federal Information Systems and Organisations sets out guidelines and controls for protecting the government’s sensitive information as well as…

LEARN MORE

Data Protection Day 2020 – Your annual reminder of the criticality of Data Privacy & Protection in your cyber supply chain

Happy Data Protection Day! January 28th is Data Protection Day (a.k.a. Data Privacy Day), providing a focal point to the importance of respecting privacy, safeguarding data and enabling trust between data subjects and those who store, process and use their data. In support of Data Protection Day the web site www.staysafeonline.org provides a suite of…

LEARN MORE