Due Diligence and Ongoing Monitoring

 View Only
Expand all | Collapse all

Vendor News Monitoring

  • 1.  Vendor News Monitoring

    Posted 10-07-2020 01:56 PM

    We don't have any subscriptions for monitoring vendors' negative news or whether they're in any regulatory trouble, so we generally do this manually during review time for critical and high-risk vendors only... While I know this isn't often enough, it is also a time-consuming task. Any tips or tricks in this area? Is anyone using a specific monitoring timeline?



  • 2.  RE: Vendor News Monitoring

    Posted 10-07-2020 02:12 PM
    Does anyone use google alerts? If you do, will you please share with me how you set them up?


  • 3.  RE: Vendor News Monitoring

    Posted 10-07-2020 02:15 PM
    I have one set up for my company. Here's the page that I used from Google that has the steps. 



  • 4.  RE: Vendor News Monitoring

    Posted 10-07-2020 02:58 PM

    We recently started using Google Alerts. We also use SecurityScorecard and Argos Risk. We have all of these set up to email us when significant changes or events occur.

     

    To set up Google alerts, visit google.com/alerts. You will have to sign in with a gmail account. I created the alerts with a gmail account I use only for this purpose. I then added my work email address as the Deliver to address. Alerts are very easy to set up but it can be time consuming if you want to setup alerts for all of your vendors at once. You'll have to be careful about the wording of your alert to avoid receiving too many useless emails.



    Erica Lane, CompTIA Sec+ Certification | Information Security Analyst II






  • 5.  RE: Vendor News Monitoring

    Posted 10-08-2020 04:42 PM
    Hi Erica,

    You mention using Security Scorecard and Argos Risk.
    How do you use these services?  Do you monitor all vendors or just certain ones?
    Do you have any success stories or failures you can share with me?

    I'm new to vendor management and would appreciate any and all information you are willing to provide.

    If you could email me directly at *email removed to protect privacy* that would be great!

    Thank you,
    Dawn


  • 6.  RE: Vendor News Monitoring

    Posted 10-09-2020 04:14 PM
    We use Argos Risk. It monitors financial information somewhat similarly to a D&B report.  Also picks up on news regarding mergers, acquisitions & changes in leadership.  We monitor critical/high risk vendors particularly if there are any concerns resulting from our annual financial reviews or if the vendor does not provide financials. We've had discussions with security scorecard and bitsight w/regard to cybersecurity monitoring and may explore that further in the near future.


  • 7.  RE: Vendor News Monitoring

    Posted 10-12-2020 08:14 AM
    I don't monitor all of my vendors, since there are too many. I focus on the more significant, higher tiered vendors.


  • 8.  RE: Vendor News Monitoring

    Posted 10-08-2020 09:35 PM
    What do you think of SecurityScorecard and ArgosRisk? I've typically used Google Alerts but recently saw demos of both SS and AR. Nice products, but I'm curious to hear from someone who's used them. Do you find one is better than the other?


  • 9.  RE: Vendor News Monitoring

    Posted 10-09-2020 09:08 AM
    I have used Security Scorecard before and it is very good but have you looked into Recorded Future?  It review both financial and security items to give a full view on risk.

    ------------------------------
    Jamie Sumter
    Vendor Risk Lead
    ------------------------------



  • 10.  RE: Vendor News Monitoring

    Posted 10-13-2020 09:34 AM

    Hi Joseph,

     

    I'm not sure how to compare them because they assess different areas. Argos assesses financial risk and SecurityScorecard assesses cybersecurity. I probably prefer the SecurityScorecard because it goes really in depth, but the Argos report is pretty good also. SecurityScorecard grades based on network security, DNS health, patching cadence, endpoint security, IP reputation, application security, cubit score, hacker chatter, information leak, and social engineering. Argos looks at things such as consistency of payments, business health index, trends for the past 180 days, any litigation, press releases, and mergers and acquisitions.



    Erica Lane, CompTIA Sec+ Certification | Information Security Analyst II
    City Bank


    Member FDIC | Equal Housing Lender

    Confidentiality Notice: This message may contain confidential and/or privileged information. If you are not the addressee or authorized to receive this for the addressee, you must not use, copy, disclose, or take any action based on this message or any information herein. If you have received this message in error, please delete this message immediately and advise the sender that you have received this message in error by reply e-mail or by calling 1-800-687-2265. Thank you for your cooperation.








  • 11.  RE: Vendor News Monitoring

    Posted 10-13-2020 11:38 AM
    Hello Joseph & Erica,
    I am a Contract Manager and we are attempting to implement a Third Party Vendor Risk Rating Program.  I have been following your posts and would like to ask if either of you have used or have an opinion on Dun & Bradstreet's Supplier Risk Manager tool? 

    Joseph - if you have used D&B SRM tool, can you please tell me how it would compare to Argos, which I am currently understanding is supplying about the same information?


    Thank you both for your attention.
    Best Regards,
    Charlotte ​


  • 12.  RE: Vendor News Monitoring

    Posted 10-13-2020 12:56 PM

    Hi Charlotte,

     

    I have heard of Dun & Bradstreet but have not used them. From my understanding, they provide similar information to Argos Risk but I could not tell you the differences.



    Erica Lane, CompTIA Sec+ Certification | Information Security Analyst II
    City Bank



    Member FDIC | Equal Housing Lender

    Confidentiality Notice: This message may contain confidential and/or privileged information. If you are not the addressee or authorized to receive this for the addressee, you must not use, copy, disclose, or take any action based on this message or any information herein. If you have received this message in error, please delete this message immediately and advise the sender that you have received this message in error by reply e-mail or by calling 1-800-687-2265. Thank you for your cooperation.








  • 13.  RE: Vendor News Monitoring

    Posted 10-13-2020 01:42 PM
    ​Thank you anyway Erica, I appreciate that you responded.


  • 14.  RE: Vendor News Monitoring

    Posted 10-14-2020 08:04 AM

    Hi Charlotte,

    Unfortunately, although I've heard of D&B's tool I have never used it, so I cannot compare the two.
    Sorry!

    Joe




  • 15.  RE: Vendor News Monitoring

    Posted 10-14-2020 10:05 AM
    ​Thank you Joe, I appreciate your response anyway.  I also read your bio and hope you do not mind that I added you to my contact list?  You have a great deal more experience than I do around the Vendor Management subject and I am always trying to expand my knowledge around this area. 

    Thanks again,
    Charlotte

    ------------------------------
    Charlotte Pennella
    シャーロット ペネラ
    Contracts Manager

    ------------------------------



  • 16.  RE: Vendor News Monitoring

    Posted 10-14-2020 11:39 AM
    We currently use Security Scorecard and find it really useful.  We are contracting this week to add Argos for all of our critical and high risk vendors.  We feel it will provide us much better information than we're currently getting and also create efficiency for us.​

    ------------------------------
    Lori A. Pook CUERME, CRVPM III | AVP Enterprise Risk Management | Summit Credit Union

    ------------------------------



  • 17.  RE: Vendor News Monitoring

    Posted 10-12-2020 08:16 AM
    Of the three -- Google Alerts, ArgosRisk and SecurityScorecard -- which give you better results?


  • 18.  RE: Vendor News Monitoring

    This message was posted by a user wishing to remain anonymous
    Posted 10-09-2020 12:54 PM
    This message was posted by a user wishing to remain anonymous

    We had our first meeting with Interos yesterday to explore their capabilities re: this topic area. Does anyone here have experience with them? Thanks.