Reporting

 View Only
  • 1.  4th party reporting

    This message was posted by a user wishing to remain anonymous
    Posted 07-09-2025 09:47 AM
    This message was posted by a user wishing to remain anonymous

    Hello!

    We're trying to make some changes to our current reporting and have run into a question that we aren't sure the answer to. 

    How are you incorporating 4th parties in your reporting? Do you filter them out? include them in the overall program reporting or have separate reporting over 4th parties?

    Any suggestions or guidance is welcome.

    Thanks!



  • 2.  RE: 4th party reporting

    Posted 07-10-2025 02:18 PM

    In my experience, reporting on fourth-party vendors can be challenging due to the inherent lack of visibility into those relationships. These entities are often excluded from the formal third-party risk management program, and there's typically no direct access to their contracts or communication channels. This makes it difficult to fully assess the risks they pose, even though they may be integral to the services your third parties provide.

    That said, I've seen organizations incorporate some level of fourth-party reporting into their broader vendor risk reporting framework. While the data may not be as robust, even partial insight can be valuable. Metrics I've found helpful include:

    • Fourth-party criticality exposure – identifying how many of your critical third parties rely on high-risk or essential fourth parties.

    • Geographic distribution – understanding where key fourth parties (e.g., data centers, developers, or support teams) are located, especially in regions with geopolitical or regulatory risk.

    • Incident reporting and missed SLAs – tracking whether service disruptions or compliance issues are tied to a fourth party.

    Ultimately, the scope and depth of your fourth-party reporting will depend on your organization's risk appetite and the maturity of your vendor risk management program. But even limited visibility, when consistently monitored and reported, can help create a stronger picture of your extended vendor ecosystem.

    Best of luck to you.  But I'm sure you will determine the correct reporting for your program.



  • 3.  RE: 4th party reporting

    Posted 07-10-2025 04:29 PM

    Has anyone found any decent Open Source Intelligence (OSINT) tools for fourth-party tracking/discovery? I feel like I've been looking forever and it probably doesn't exist, but always nice to hear from others what they may have found or tried.



    ------------------------------
    Security and Privacy sitting in a tree.
    ------------------------------



  • 4.  RE: 4th party reporting

    Posted 07-11-2025 09:00 AM

    I'm not aware of any open source intelligence, but I am aware of a product offered by one of the insurance brokers, Marsh, that works well for manufacturing organizations. The solution they offer is called Sentrisk.



    ------------------------------
    Mark Ewert, CPCU, CIC
    Director Vendor Management
    Penn National Insurance
    ------------------------------