From more of an IT view:
Virustotal can see if any security vendors have flagged a vendor's URL as malicious.
https://www.virustotal.com/gui/home/url
NIST's National Vulnerability Database can be helpful to see if any of the vendor's offerings have vulnerabilities reported.
https://nvd.nist.gov/vuln/search
Original Message:
Sent: 02-07-2025 02:44 PM
From: Ashley Markwick
Subject: Vendor Research - Enforcement Action
Hi everyone!
Currently, as part of our risk assessment/due diligence we research vendors via the following:
- Better Business Bureau
- CFPB
- FTC
- Google
- Vendor's website
- Vendor references
- OFAC checks
I am interested to learn what other organizations are utilizing to research their vendors for complaints and enforcement actions. Please share your resources.
Thank you!
Ashley M.
Risk and Compliance Rep