Brace for Impact
Rachel Curran
Third-Party Risk
Betting on low likelihood leaves you exposed. Practical steps to reduce the impact of third-party risks before they happen.
Third-Party Risk Impact vs. Likelihood | Locktivity
Why preparing for the impact of third-party risks beats betting on the odds, plus seven practical steps to limit the fallout when a vendor fails.
Why preparing for the fallout of third-party risks beats betting on the odds.
In third-party risk management, it's easy to focus on how likely a risk might be. If something seems unlikely, why invest in mitigating it, right? But solely betting on the likelihood of a risk can leave you exposed, especially when it comes to known risks. While reducing the chances of a risk occurring is important, managing its potential impact can deliver greater resilience and long-term value.
The pitfall of likelihood-first thinking
When we assess risk likelihood, we're making educated guesses based on history and current conditions. Let's say a new vendor has strong cybersecurity measures, and you determine the chance of a breach is low. But risk landscapes change—regulations evolve, threats escalate, and human errors happen. That "unlikely" risk can still catch you off guard, and if you're unprepared for its impact, the fallout can be severe.
Why managing impact is crucial
Risk isn't just about the odds—it's about consequences. Even a low-probability event can cause significant disruption, financial losses, or reputational damage if you haven't prepared for it. That's where reducing impact becomes essential.
Focusing on impact management ensures that when something does go wrong, your business can recover quickly with minimal fallout. It shifts the strategy from "How likely is this?" to "How ready are we when this happens?" By building resilience into your third-party risk management approach, you're prepared to handle whatever comes your way, without just crossing your fingers that everything stays smooth.
How to minimize risk impact
Here are some practical steps to reduce the impact of known risks, no matter how likely they are:
Diversify vendors: Avoid over-reliance on one vendor for critical services. Spreading your vendor relationships limits your exposure to any single point of failure.
Strengthen contracts: Use contracts to clearly define roles, responsibilities, and penalties for incidents. Ensure they address recovery support from vendors when issues arise.
Apply the least privilege principle: Ensure that all access granted to a given vendor is necessary for the purposes of executing the needed services. Consider carefully what data is shared, whether it needs to be hosted by the vendor, how long the data persists on the vendor's systems, and what access is granted to other company systems.
Develop response plans: Create and regularly test incident response plans for when third-party risks materialize, ensuring you can react effectively.
Monitor continuously: Set up continuous monitoring of critical vendors to catch issues early, rather than waiting for periodic assessments. This allows you to act quickly, mitigating potential impact.
Insure and prepare financially: Cyber insurance can ease financial hits, while having reserves in place helps fund quick recovery efforts if an incident occurs.
Assess for impact, not just likelihood: During risk assessments, measure not just how likely a risk is, but how prepared you are for the worst-case scenarios.
Finding the right balance
Reducing the impact of a known risk doesn't mean you ignore its likelihood. A well-rounded third-party risk strategy addresses both—working to prevent incidents while making sure you're equipped to handle them if they happen.