“We are ISO 27001 certified, are we DORA compliant?” Not so fast. ISO 27001 and DORA both focus on cybersecurity and risk management, but they serve very different purposes. If you're a financial institution or an ICT provider working with financial institutions in the EU, DORA compliance is mandatory, and ISO 27001 alone won’t get you there. Let’s break it down: 1. Regulatory vs. Voluntary Framework ↳ ISO 27001 – A voluntary international standard for information security management. ↳ DORA – A mandatory EU regulation for financial entities and their ICT providers, with strict oversight and penalties for non-compliance. 2. Scope and Focus ↳ ISO 27001 – Offers a customizable scope tailored to organizational needs, focusing on information security (confidentiality, integrity, availability) based on specific risk assessments and chosen controls. ↳ DORA – Enforces a standardized scope across financial entities, extending beyond security to operational resilience. It ensures institutions can withstand, respond to, and recover from ICT disruptions while maintaining service continuity. 3. Key Compliance Gaps 🔸 Incident Reporting ↳ ISO 27001 – Requires incident management but doesn’t impose strict deadlines or mandate reporting to regulators, as it is a flexible standard. ↳ DORA – 4 hours to report a major incident, 72 hours for an update, 1 month for a root cause analysis. 🔸 Security Testing ↳ ISO 27001 – Requires vulnerability management but leaves testing methods and frequency to organizational risk. ↳ DORA – Annual resilience testing, threat-led penetration testing every 3 years, continuous vulnerability scanning. 🔸 Third-Party Risk Management: ↳ ISO 27001 – Covers supplier risk but with general security controls. ↳ DORA – Enforces contractual obligations, exit strategies, and regulatory audits for ICT providers working with financial institutions. 4. How financial institutions and ICT providers can address the delta? ✅ Perform a DORA Gap Analysis – Identify missing controls beyond ISO 27001. (Hopefully, you're not still at this stage now that DORA has been mandatory since January 17, 2025.) ✅ Upgrade Incident Response – Implement real-time monitoring and reporting mechanisms to meet DORA’s deadlines. ✅ Enhance Security Testing – Introduce formalized resilience testing and threat-led penetration testing. ✅ Strengthen Third-Party Risk Management – Update contracts, prepare for regulatory audits, and ensure exit strategies comply with DORA. ✅ Improve Business Continuity Planning – Move from cybersecurity alone to full digital operational resilience. 💡 ISO 27001 is just the tip of the iceberg - beneath the surface lie significant gaps that only DORA addresses. 👇 What’s the biggest challenge in aligning with DORA? Let’s discuss. ♻️ Repost to help someone. 🔔 Follow Amine El Gzouli for more.
Third-Party Risk Management
Explore top LinkedIn content from expert professionals.
-
-
🚨 Big Update on #DORA’s RTS for ICT #Subcontracting 🚨 After six months of review, the European Commission (EC) has rejected the adoption of the DORA RTS on subcontracting ICT services supporting critical or important functions (CIFs). 🔹 The RTS outlined risk assessment requirements for financial entities when subcontracting ICT services, including due diligence, contract management, and ongoing monitoring. 🔹 However, the EC believes certain provisions exceed the mandate given to the ESAs under DORA, particularly around monitoring subcontractors. 🔹 As a result, the ESAs must revise the RTS within six weeks, removing Article 5 & Recital 5, or the EC will step in and make the changes itself. 📌 Why this matters: This is the final missing piece of DORA’s technical standards for ICT third-party risk management (though the TLPT RTS is also still pending). Some financial institutions have already incorporated Article 5 provisions into their contracts with tech providers, creating a compliance challenge. The next few weeks will be crucial. Will the ESAs comply, or will we see further regulatory back-and-forth? #DORA #ICT #FinancialServices #RegTech #Regulation #EU #EY #EBA #ECB #EIOPA #ESMA #ITRM #Riskmanagement #RTS
-
What Defines a Strong TPRM Strategy in 2025? 🤔 A mature TPRM program in 2025 isn’t just about checking boxes, it’s about building a defensible, risk-based framework that withstands scrutiny from regulators, auditors, and internal stakeholders alike. As regulatory expectations evolve globally, the benchmark for "compliance" is increasingly tied to demonstrable, ongoing due diligence, monitoring, and governance. Here’s what that looks like in practice: Key Pillars of a TPRM Strategy 1. Centralized Third Party Inventory: Maintain a dynamic inventory of all third parties, with visibility into their services, access to systems/data, and criticality to business operations. 2. Risk-Based Segmentation: Classify vendors by risk tiers (e.g., critical, high, moderate, low) based on the sensitivity of data and impact on operations. This enables proportional oversight. 3. Standardized Due Diligence and Risk Assessments: Use consistent, framework-aligned assessments (e.g., NIST CSF, ISO 27001, SIG questionnaires) for onboarding and periodic reviews. Tailor depth and frequency to risk level. 4. Continuous Monitoring: Leverage technology (e.g., security ratings, threat intelligence, performance dashboards) to track vendor health in real time, not just point-in-time reviews. 5. Strong Contractual Controls: Embed clear requirements in contracts around data protection, right to audit, breach notifications, and fourth-party oversight. Contracts are your enforcement tool. 6. Incident Response and Contingency Planning: Include third parties in your incident response playbooks. Simulate breach scenarios to test coordination, escalation, and communication processes. 7. Cross-Functional Ownership and Governance: Engage legal, procurement, cybersecurity, and business unit leaders throughout the lifecycle. Risk ownership must be shared, not siloed. To demonstrate that your program is more than just policy on paper: - Documentation – Keep detailed records of risk assessments, remediation plans, monitoring reports, and vendor interactions. - Audit Trails – Ensure transparency in decision-making: how vendors are approved, how exceptions are granted, and how issues are addressed. - Performance Metrics – Track and report KPIs (e.g., % of vendors with updated risk reviews, average remediation time) to show continuous improvement. - Regulatory Mapping – Align your TPRM framework to applicable regulations (e.g., OCC, DORA, EBA, MAS), and document how requirements are being met. Board Reporting – Periodically update senior management and the Board on third-party risk exposure, residual risk, and mitigation actions. In 2025, "being compliant enough" means being able to show that your TPRM program is consistent, risk-aligned, and operationalized. It’s not about perfection, it’s about visibility, defensibility, and accountability. #2025 #riskmanagement #riskassessment #regulations #compliance #occ #3prm #boardreporting #businessrisk #residualrisk #riskmitigation #tprm
-
Most fintech execs still think DORA is just about internal controls. But the new oversight framework gives regulators something far more powerful: direct access to your third-party tech providers. Here’s what that means: ↳ Regulators can now inspect your cloud vendor’s offices, systems, and risk controls, not just yours. ↳ Even non-EU providers fall under the scope if they serve EU financial entities. ↳ CTPPs (Critical Third Party Providers) must respond to data requests, remediation plans, and real-time inspections. ↳ If your vendor doesn’t comply, your regulators may instruct you to exit the contract. The DORA Guide on oversight of critical activities outlines exactly how inspections, investigations, and follow-ups will happen and what regulators will expect.
-
In 2026, Third Parties should be your First Priority! But before you rip and replace your vendor scoring tool, consider this: most risk teams don’t need more tools; they need the right tool with clearer signals. Your partners, their partners, and the technologies they use can introduce risk that becomes yours when something goes wrong. Here’s how forward‑thinking teams are evolving TPRM in 2026: - Treat the vendor lifecycle as continuous: Onboard, assess, monitor, and offboard with real‑time risk signals instead of annual checklists. - Build a centralized vendor inventory: You can’t manage what you don’t know you have. Cross‑functional collaboration with procurement, legal, and business units makes this achievable and meaningful. - Replace static ratings with dynamic monitoring: AI‑powered tools that ingest signals help catch emerging vulnerabilities or breach warnings before they become crises. - Connect risk to business impact: Translate vendor risk into financial terms so decisions are based on what matters to the business, not just subjective ratings. For a comprehensive view of where TPRM is headed and why continuous, automated approaches are essential in 2026, check out this guide from Safe Security. https://lnkd.in/gka3desW #ThirdPartyRisk #TPRM #RiskManagement #VendorRisk #CyberSecurity #FutureOfRisk
-
Most organisations don't do Third-Party Risk Management. They do Third-Party Management. The "risk" dropped out somewhere between the procurement guidelines and the questionnaire template. Look at how it works in practice: a vendor enters the pipeline, someone sends a spreadsheet, the vendor fills it in, someone checks for SOC 2, the vendor gets approved. CYA complete. Where was the risk? Not your risk register. Not your threat model. Not your control priorities. The assessment wasn't shaped by any of them. It was shaped by a certifying body and a standard questionnaire template someone downloaded three years ago. This happens because TPRM is disconnected from the first-party risk program. And it's disconnected because, in most organisations, the first-party risk program isn't strong enough to connect to. When your own risk program is mature, extending it to third parties is natural: → You know which risks matter, so you ask vendors about those risks → You understand control depth, so you assess vendors at proportional depth → Your risk register is alive, so vendor risk feeds back into it → Third-party risk becomes a node in your graph, not a separate spreadsheet When your own risk program is weak, TPRM becomes what it is today: a procurement checkbox that exists to say "we reviewed them" without ever answering "what risk do they actually introduce?" You don't fix TPRM by fixing TPRM. You fix it by building a first-party risk program worth extending. #GRCEngineering #TPRM
-
Third-Party Risk: The Hidden Cybersecurity Battlefield in Modern Supply Chains In our interconnected digital ecosystem, your security posture is only as strong as your weakest vendor. Modern enterprises rely on 100s of third-party vendors, creating an exponentially expanding attack surface. Supply chain attacks have become the preferred vector for sophisticated threat actors. Instead of targeting well-defended enterprises directly, attackers exploit vulnerabilities in trusted vendors to simultaneously breach hundreds of downstream organizations. Game-Changing Examples SolarWinds (2020): Compromised software updates affected 18,000+ customers including Fortune 500 companies and government agencies, demonstrating how a single vendor breach cascades across entire sectors. MOVEit (2023): A single vulnerability led to data breaches affecting over 600 organizations globally, showcasing the massive scale of modern supply chain impacts. Why Third-Party Risk Monitoring is Critical Continuous Visibility: Traditional annual assessments are insufficient. Organizations need real-time monitoring of vendor security posture, breach notifications, and compliance status changes. Risk Amplification: When attackers target managed service providers or software vendors, the impact multiplies across all their clients. One compromised vendor can expose thousands of organizations simultaneously. Regulatory Liability: With GDPR, CCPA, and emerging supply chain regulations, organizations face increasing liability for third-party security failures. Proactive monitoring demonstrates due diligence. Building Effective Defense Continuous Assessment: Implement real-time vendor risk scoring across your entire ecosystem Zero Trust Extension: Apply least-privilege access controls to all third-party connections Incident Response Integration: Ensure your IR plans account for vendor breaches with clear communication protocols Contractual Protection: Update vendor agreements with security requirements and liability provisions The Bottom Line Organizations can no longer treat vendor risk as procurement afterthought. The question isn't whether your supply chain will be targeted — it's whether you'll detect and respond effectively when it happens. The strongest security programs extend beyond organizational boundaries to create defensible ecosystems, not just defensible enterprises. #ThirdPartyRisk #TRPM #SupplyChainAttack #CyberSecurity
-
🚨 #DORA #Compliance & Third-Party Risk: Are You Ready? 🚨 Financial institutions are facing a new era of operational resilience with the Digital Operational Resilience Act (DORA) being effective since January. One of the biggest challenges? Managing third-party vendors in a way that aligns with these stringent requirements. 🔍 Why does this matter? DORA makes it clear: Your vendors are an extension of your operational risk and their failures can become yours. That means financial organizations must step up their Third-Party Risk Management (TPRM) game to ensure compliance. Here’s how to get ahead of the curve: 1️⃣ Centralize Vendor Risk Management – Map out all third-party relationships and continuously monitor their risk profiles. 2️⃣ Go Beyond Initial Due Diligence – Ongoing risk assessments are key. DORA mandates that vendors’ resilience capabilities be regularly tested and reviewed. 3️⃣ Establish Incident Reporting Protocols – Ensure third parties have clear procedures for reporting cyber incidents in real time to minimize damage. 4️⃣ Include DORA-Specific Clauses in Contracts – Ensure outsourcing agreements reflect the regulatory obligations placed on your organization. 5️⃣ Stress Test Your Vendors – Don’t just take their word for it - run simulations to assess their operational resilience in real-world scenarios. 🚀 Proactive compliance is the best compliance. Now is the time to strengthen your vendor risk management framework and ensure resilience across your entire digital supply chain.
-
DORA (Digital Operational Resilience Act) changed everything for financial services - especially mid-market orgs that suddenly found themselves in its remit. Suddenly ,there were specific requirements about ICT third-party risk management, detailed reporting obligations, and real consequences for non-compliance. That regulatory pressure created the clearest use case I've seen for agents. The DORA agent monitors our ICT supplier relationships against the regulatory requirements. Concentration risk thresholds. Exit strategy documentation. Incident reporting timelines. Sub-contractor oversight. It doesn't replace the compliance team's judgment about whether we're meeting the spirit of the regulation. It ensures nothing falls through the cracks on the letter of it. When a supplier's status changes - new contract, renewed agreement, terminated relationship - the agent automatically reassesses our DORA exposure and updates the relevant registers. Before: quarterly manual reviews that took weeks and still missed things. After: continuous monitoring that catches changes as they happen. Financial services arrived first because the regulation forced them to. Everyone else will follow. Tomorrow: ESG assessment, and why third party data is the bottleneck everyone ignores.
-
Third-Party Risk Management is nuts & out of control. Somewhere along the way, TPRM turned into a bureaucratic sport where we measure effort instead of risk reduction. 300-question spreadsheets. Endless “follow-ups.” Security teams playing document collector. Most orgs are pretending to “manage” vendor risk when they’re really just manufacturing paperwork. You do NOT have the leverage to run your vendors’ security programs. You do NOT have the resources to deeply assess a bunch of SaaS providers. And you definitely do NOT need a Big 4 inspired monstrosity to manage practical risk. From a CISO perspective, here’s a simplified TPRM model that actually works for most of us... Step 1: Classify Every Vendor Into 3 Tiers ->High Vendor has external (remote) access into your environment (Small number & might be zero.) ->Medium Vendor stores, processes, or transmits your sensitive data or your customers’ sensitive data (PII, etc) ->Low Everyone else (This is most likely 50% + of your vendor base.) Step 2: Set Clear, Non Negotiable Expectations ->High & Medium Vendors -Must provide a recognized audit report (SOC 2, ISO 27001, etc.) -Must maintain it throughout the contract -If handling customer data, sign a DPA or equivalent ->High Vendors (with access to your environment) -Must agree to follow your security policies while operating in your environment -Least privilege. Logged access. No exceptions. ->Low Vendors -Ask for audit reports. -If they can provide one, awesome, they’re more attractive commercially. -If not, confirm they don’t handle sensitive data or have access, contractually limit what they can receive, control exposure by only sharing what’s necessary, document the low-risk classification, and move on...low risk should mean low friction, not a 300 question spreadsheet. Step 3: Shrink the Legal Theater Your security addendum should focus on what actually matters: -Ongoing audit reporting -Data retention -Incident notification -Flow-down requirements to sub-processors Not 14 pages of fantasy control over systems you don’t run. Here’s the part security teams don’t like admitting: You can't manage your vendors’ security programs. At best, you can: Choose mature partners. Contractually require transparency. Enforce boundaries where they touch your environment or your data. Everything else is illusion. When you simplify TPRM: -Procurement moves faster. -Business partners stop avoiding security. -Your team focuses on real risk. -And when you need political capital for something that actually matters, you have it. Mature CISOs know the difference between control and control theater. For most SMB companies, a disciplined 3-tier model & mandatory assurance for real risk exposure is adult supervision, and adult supervision scales. #ciso #vciso #TPRM #security