SlideShare a Scribd company logo
1 of 18
Download to read offline
Third-Party Crashers:
Avoiding Service Provider
Risk Headaches
May 12, 2021 | MasterSnacks Webinar Series
Welcome &
Introduction
KEVIN RICCI, CISM, CISA, CRISC, MCSE, QSA
Principal, Technology, Risk Advisory & Cybersecurity (TRAC) Practice
Citrin Cooperman
kricci@citrincooperman.com
401-421-4800
AGENDA
Stats and Facts
01
Real - Life Example 02
Avoiding Ser vice Pr ovider Risk 03
Questions? 04
Once More Unto the Breach
Data Breach Statistics
Global Average Cost per
Breach: $3.86M
Average Cost per Record
Compromised: $146
Average Days to Detect a
Breach: 207
Average Days to Contain a
Breach: 73
Average cost of downtime is
$11,600 per minute
Average cost of a breach is
39.6% higher if a company is
not prepared
43% of Cyber Attacks Target
Small Businesses
Sources: Ponemon Institute/IBM Cost of a Data Breach Report & Verizon Data Breach Investigation Report
Third-Party Security Statistics
Over 53% of respondents
have experienced a third-
party data breach in the past
2 years
58% of respondents
described their TPCRM
programs as early (not
deployed) or middle stage
(only partially deployed)
Only 24% of respondents say
their organizations
collaborate with third parties
to improve their security
measures.
56% of respondents say their
organizations require some of
their third parties to be
subject to a more thorough
assessment of their security
practices.
Less than 50% of
respondents say their
organizations earmark funds
to support its third-party
cybersecurity risk
management program.
Sources: Ponemon The Cost of Third-Party Cybersecurity Risk Management Report
Third-Party Risk Management:
Overview
• What are some examples of third-party service providers?
• Technical support providers
• Cloud-based financial applications
• Security monitoring
• Email
• Data backup solutions
• What is third-party risk management?
Third-Party Risk:
We’re All a Target
Third-Party Risk Management:
Inventory and Risk Profile
• Identify all third-party service providers
• Utilize business stakeholder surveys, accounts payable
vendor listings, and legal and/or procurement contract
databases
• Inventory each third-party service provider and collect
supplemental documentation
• Determine the risk profile
Third-Party Risk Management:
Vendor Assessments
• Require vendor due diligence questionnaires to determine their
ability to keep your data secure
Third-Party Risk Management:
Monitoring, Disruption and Policies
• Monitoring
• Frequency
• Triggers
• Third-party disruption
• COVID
• Migration to another provider
• Develop policies and procedures
• Elements include onboarding, the assessment processes,
monitoring and offboarding
Third-Party Risk Management:
SOC Reports
• Overview
• Provides detailed information and assurance about controls
at a service organization.
• Developed by the American Institute of CPAs
• Versions
• SOC 1, SOC 2, SOC 3
• Type1, Type 2
Third-Party Risk Management:
SOC Reports
• Trust Services Principles
• Security 32 Criteria
• Availability 3 Criteria
• Confidentiality 2 Criteria
• Processing Integrity 5 Criteria
• Privacy 18 Criteria
• Obtaining and reviewing the SOC report
• Complementary user entity controls
Questions?
KEVIN RICCI, CISM, CISA, CRISC, MCSE, QSA
Principal, Technology, Risk Advisory & Cybersecurity (TRAC) Practice
Citrin Cooperman
kricci@citrincooperman.com
401-421-4800
Thank You
F o r Wa t c h i n g & L i s t e n i n g
UPCOMING MASTERSNACKS: CYBERSECURITY WEBINARS:
DISASTER RECOVERY: HOPING FOR THE BEST BUT PLANNING FOR THE WORST
May 19, 2021 | 12:00 PM ET/9:00 AM PT
PLAYING OFFENSE – A PROACTIVE APPROACH TO CYBERSECURITY
May 26, 2021 | 12:00 PM ET/9:00 AM PT

More Related Content

What's hot

What CIOs Need To Tell Their Boards About Cyber Security
What CIOs Need To Tell Their Boards About Cyber SecurityWhat CIOs Need To Tell Their Boards About Cyber Security
What CIOs Need To Tell Their Boards About Cyber SecurityKaryl Scott
 
Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19
Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19
Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19Citrin Cooperman
 
Navigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryNavigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryCitrin Cooperman
 
Role of The Board In IT Governance & Cyber Security-Steve Howse
Role of The Board In IT Governance & Cyber Security-Steve HowseRole of The Board In IT Governance & Cyber Security-Steve Howse
Role of The Board In IT Governance & Cyber Security-Steve HowseCGTI
 
Top 10 leading fraud detection and prevention solution providers
Top 10 leading fraud detection and prevention solution providersTop 10 leading fraud detection and prevention solution providers
Top 10 leading fraud detection and prevention solution providersMerry D'souza
 
What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...
What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...
What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...Citrin Cooperman
 
Cyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial InstitutionsCyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial InstitutionsColleen Beck-Domanico
 
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The BreachFireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The BreachFireEye, Inc.
 
Scammed: Defend Against Social Engineering
Scammed: Defend Against Social EngineeringScammed: Defend Against Social Engineering
Scammed: Defend Against Social EngineeringResolver Inc.
 
Tripwire Energy Working Group Session w/Dale Peterson
Tripwire Energy Working Group Session w/Dale PetersonTripwire Energy Working Group Session w/Dale Peterson
Tripwire Energy Working Group Session w/Dale PetersonTripwire
 
Cyber risk tips for boards and executive teams
Cyber risk tips for boards and executive teamsCyber risk tips for boards and executive teams
Cyber risk tips for boards and executive teamsWynyard Group
 
A Hacker's Playground - Cyber Risks During COVID-19
A Hacker's Playground - Cyber Risks During COVID-19A Hacker's Playground - Cyber Risks During COVID-19
A Hacker's Playground - Cyber Risks During COVID-19Citrin Cooperman
 
Board and Cyber Security
Board and Cyber SecurityBoard and Cyber Security
Board and Cyber SecurityLeon Fouche
 
Case Study: The Role of Human Error in Information Security
Case Study: The Role of Human Error in Information SecurityCase Study: The Role of Human Error in Information Security
Case Study: The Role of Human Error in Information SecurityPECB
 
Data Driven Risk Assessment
Data Driven Risk AssessmentData Driven Risk Assessment
Data Driven Risk AssessmentResolver Inc.
 
Cybersecurity & the Board of Directors
Cybersecurity & the Board of DirectorsCybersecurity & the Board of Directors
Cybersecurity & the Board of DirectorsAbdul-Hakeem Ajijola
 
Shaping Your Future in Banking Cybersecurity
Shaping Your Future in Banking Cybersecurity Shaping Your Future in Banking Cybersecurity
Shaping Your Future in Banking Cybersecurity Dawn Yankeelov
 

What's hot (20)

What CIOs Need To Tell Their Boards About Cyber Security
What CIOs Need To Tell Their Boards About Cyber SecurityWhat CIOs Need To Tell Their Boards About Cyber Security
What CIOs Need To Tell Their Boards About Cyber Security
 
Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19
Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19
Fraud and Security in Uncharted Territory: Considerations in the Age of COVID-19
 
Navigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryNavigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services Industry
 
Role of The Board In IT Governance & Cyber Security-Steve Howse
Role of The Board In IT Governance & Cyber Security-Steve HowseRole of The Board In IT Governance & Cyber Security-Steve Howse
Role of The Board In IT Governance & Cyber Security-Steve Howse
 
Top 10 leading fraud detection and prevention solution providers
Top 10 leading fraud detection and prevention solution providersTop 10 leading fraud detection and prevention solution providers
Top 10 leading fraud detection and prevention solution providers
 
What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...
What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...
What Risk Factors Not-For-Profit Organizations Need to Know in Today's COVID-...
 
Cyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial InstitutionsCyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial Institutions
 
Banks and cybersecurity v2
Banks and cybersecurity v2Banks and cybersecurity v2
Banks and cybersecurity v2
 
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The BreachFireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
 
Scammed: Defend Against Social Engineering
Scammed: Defend Against Social EngineeringScammed: Defend Against Social Engineering
Scammed: Defend Against Social Engineering
 
Tripwire Energy Working Group Session w/Dale Peterson
Tripwire Energy Working Group Session w/Dale PetersonTripwire Energy Working Group Session w/Dale Peterson
Tripwire Energy Working Group Session w/Dale Peterson
 
CRI Cyber Board Briefing
CRI Cyber Board Briefing CRI Cyber Board Briefing
CRI Cyber Board Briefing
 
Cyber risk tips for boards and executive teams
Cyber risk tips for boards and executive teamsCyber risk tips for boards and executive teams
Cyber risk tips for boards and executive teams
 
A Hacker's Playground - Cyber Risks During COVID-19
A Hacker's Playground - Cyber Risks During COVID-19A Hacker's Playground - Cyber Risks During COVID-19
A Hacker's Playground - Cyber Risks During COVID-19
 
Board and Cyber Security
Board and Cyber SecurityBoard and Cyber Security
Board and Cyber Security
 
HEMISPHERE SMB Case Study
HEMISPHERE SMB Case StudyHEMISPHERE SMB Case Study
HEMISPHERE SMB Case Study
 
Case Study: The Role of Human Error in Information Security
Case Study: The Role of Human Error in Information SecurityCase Study: The Role of Human Error in Information Security
Case Study: The Role of Human Error in Information Security
 
Data Driven Risk Assessment
Data Driven Risk AssessmentData Driven Risk Assessment
Data Driven Risk Assessment
 
Cybersecurity & the Board of Directors
Cybersecurity & the Board of DirectorsCybersecurity & the Board of Directors
Cybersecurity & the Board of Directors
 
Shaping Your Future in Banking Cybersecurity
Shaping Your Future in Banking Cybersecurity Shaping Your Future in Banking Cybersecurity
Shaping Your Future in Banking Cybersecurity
 

Similar to MasterSnacks: Cybersecurity - Third-Party Crashers: Avoiding Service Provider Risk Headaches

Overcoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOvercoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOnRamp
 
Ingenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM complianceIngenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM complianceSami Benafia
 
bsi-cyber-resilience-presentation
bsi-cyber-resilience-presentationbsi-cyber-resilience-presentation
bsi-cyber-resilience-presentationAjai Srivastava
 
Emerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and SecurityEmerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and SecurityJessica Santamaria
 
Emerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and SecurityEmerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and SecurityJessica Santamaria
 
Ivanti Threat Thursday for January 23
Ivanti Threat Thursday for January 23Ivanti Threat Thursday for January 23
Ivanti Threat Thursday for January 23Ivanti
 
Increasing Challenges in Healthcare Privacy and Security
Increasing Challenges in Healthcare Privacy and SecurityIncreasing Challenges in Healthcare Privacy and Security
Increasing Challenges in Healthcare Privacy and SecurityCynergisTek, Inc.
 
Get Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security SolutionGet Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security SolutionPrecisely
 
New Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law RequirementsNew Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law RequirementsSkoda Minotti
 
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfQuestions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfinfosecTrain
 
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬priyanshamadhwal2
 
Moving to the Cloud: A Security and Hosting Introduction
Moving to the Cloud: A Security and Hosting IntroductionMoving to the Cloud: A Security and Hosting Introduction
Moving to the Cloud: A Security and Hosting IntroductionBlackbaud
 
A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103DVV Solutions Third Party Risk Management
 
Presentation for FPANJ Spring 2015 Conference
Presentation for FPANJ Spring 2015 ConferencePresentation for FPANJ Spring 2015 Conference
Presentation for FPANJ Spring 2015 ConferenceBill Despo
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk ManagementEC-Council
 
Securing Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best PracticesSecuring Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best PracticesUlf Mattsson
 
How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2
How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2
How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2TechSoup Canada
 

Similar to MasterSnacks: Cybersecurity - Third-Party Crashers: Avoiding Service Provider Risk Headaches (20)

Overcoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOvercoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security Model
 
Grc f42
Grc f42Grc f42
Grc f42
 
Ingenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM complianceIngenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM compliance
 
bsi-cyber-resilience-presentation
bsi-cyber-resilience-presentationbsi-cyber-resilience-presentation
bsi-cyber-resilience-presentation
 
Emerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and SecurityEmerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and Security
 
Emerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and SecurityEmerging Trends in Information Privacy and Security
Emerging Trends in Information Privacy and Security
 
ISACA ISSA Presentation
ISACA ISSA PresentationISACA ISSA Presentation
ISACA ISSA Presentation
 
Ivanti Threat Thursday for January 23
Ivanti Threat Thursday for January 23Ivanti Threat Thursday for January 23
Ivanti Threat Thursday for January 23
 
Increasing Challenges in Healthcare Privacy and Security
Increasing Challenges in Healthcare Privacy and SecurityIncreasing Challenges in Healthcare Privacy and Security
Increasing Challenges in Healthcare Privacy and Security
 
Get Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security SolutionGet Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security Solution
 
New Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law RequirementsNew Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law Requirements
 
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfQuestions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
 
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
 
Moving to the Cloud: A Security and Hosting Introduction
Moving to the Cloud: A Security and Hosting IntroductionMoving to the Cloud: A Security and Hosting Introduction
Moving to the Cloud: A Security and Hosting Introduction
 
A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103
 
Presentation for FPANJ Spring 2015 Conference
Presentation for FPANJ Spring 2015 ConferencePresentation for FPANJ Spring 2015 Conference
Presentation for FPANJ Spring 2015 Conference
 
Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19 Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk Management
 
Securing Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best PracticesSecuring Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best Practices
 
How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2
How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2
How Your Nonprofit Can Avoid Data Breaches and Ensure Privacy Part 2
 

More from Citrin Cooperman

How About Provider Relief Funds: Deadlines, Reporting, and Auditing Nuances
How About Provider Relief Funds: Deadlines, Reporting, and Auditing NuancesHow About Provider Relief Funds: Deadlines, Reporting, and Auditing Nuances
How About Provider Relief Funds: Deadlines, Reporting, and Auditing NuancesCitrin Cooperman
 
C-Suite Snacks Webinar Series: Modern Decision Support
C-Suite Snacks Webinar Series: Modern Decision SupportC-Suite Snacks Webinar Series: Modern Decision Support
C-Suite Snacks Webinar Series: Modern Decision SupportCitrin Cooperman
 
C-Suite Snacks Webinar Series: Building an Advisory Board
C-Suite Snacks Webinar Series: Building an Advisory BoardC-Suite Snacks Webinar Series: Building an Advisory Board
C-Suite Snacks Webinar Series: Building an Advisory BoardCitrin Cooperman
 
C-Suite Snacks Webinar Series: Prepping Your Company's Financials for Sale
C-Suite Snacks Webinar Series: Prepping Your Company's Financials for SaleC-Suite Snacks Webinar Series: Prepping Your Company's Financials for Sale
C-Suite Snacks Webinar Series: Prepping Your Company's Financials for SaleCitrin Cooperman
 
Preparing for the New Lease Accounting Standard
Preparing for the New Lease Accounting StandardPreparing for the New Lease Accounting Standard
Preparing for the New Lease Accounting StandardCitrin Cooperman
 
Lease Accounting: Preparing Your Business for 2022
Lease Accounting: Preparing Your Business for 2022Lease Accounting: Preparing Your Business for 2022
Lease Accounting: Preparing Your Business for 2022Citrin Cooperman
 
High Net Worth Webinar Series - Tax Planning and Update for 2022
High Net Worth Webinar Series - Tax Planning and Update for 2022High Net Worth Webinar Series - Tax Planning and Update for 2022
High Net Worth Webinar Series - Tax Planning and Update for 2022Citrin Cooperman
 
C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...
C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...
C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...Citrin Cooperman
 
High Net Worth Webinar Series - The Business of Digital Assets​ & Blockchain
High Net Worth Webinar Series - The Business of Digital Assets​ & BlockchainHigh Net Worth Webinar Series - The Business of Digital Assets​ & Blockchain
High Net Worth Webinar Series - The Business of Digital Assets​ & BlockchainCitrin Cooperman
 
High Net Worth Webinar Series - Estate Planning Strategies and Updates
High Net Worth Webinar Series - Estate Planning Strategies and UpdatesHigh Net Worth Webinar Series - Estate Planning Strategies and Updates
High Net Worth Webinar Series - Estate Planning Strategies and UpdatesCitrin Cooperman
 
Showtime for Shuttered Venue Operators Grant (SVOG) Recipients
Showtime for Shuttered Venue Operators Grant (SVOG) RecipientsShowtime for Shuttered Venue Operators Grant (SVOG) Recipients
Showtime for Shuttered Venue Operators Grant (SVOG) RecipientsCitrin Cooperman
 
C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...
C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...
C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...Citrin Cooperman
 
Manufacturing & Distribution Update: The Economic Impact on the Industry
Manufacturing & Distribution Update: The Economic Impact on the IndustryManufacturing & Distribution Update: The Economic Impact on the Industry
Manufacturing & Distribution Update: The Economic Impact on the IndustryCitrin Cooperman
 
High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...
High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...
High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...Citrin Cooperman
 
The New Rage in SALT: State Pass-Through Entity Tax
The New Rage in SALT: State Pass-Through Entity TaxThe New Rage in SALT: State Pass-Through Entity Tax
The New Rage in SALT: State Pass-Through Entity TaxCitrin Cooperman
 
C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...
C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...
C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...Citrin Cooperman
 
C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...
C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...
C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...Citrin Cooperman
 
C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...
C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...
C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...Citrin Cooperman
 
MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...
MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...
MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...Citrin Cooperman
 
C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...
C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...
C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...Citrin Cooperman
 

More from Citrin Cooperman (20)

How About Provider Relief Funds: Deadlines, Reporting, and Auditing Nuances
How About Provider Relief Funds: Deadlines, Reporting, and Auditing NuancesHow About Provider Relief Funds: Deadlines, Reporting, and Auditing Nuances
How About Provider Relief Funds: Deadlines, Reporting, and Auditing Nuances
 
C-Suite Snacks Webinar Series: Modern Decision Support
C-Suite Snacks Webinar Series: Modern Decision SupportC-Suite Snacks Webinar Series: Modern Decision Support
C-Suite Snacks Webinar Series: Modern Decision Support
 
C-Suite Snacks Webinar Series: Building an Advisory Board
C-Suite Snacks Webinar Series: Building an Advisory BoardC-Suite Snacks Webinar Series: Building an Advisory Board
C-Suite Snacks Webinar Series: Building an Advisory Board
 
C-Suite Snacks Webinar Series: Prepping Your Company's Financials for Sale
C-Suite Snacks Webinar Series: Prepping Your Company's Financials for SaleC-Suite Snacks Webinar Series: Prepping Your Company's Financials for Sale
C-Suite Snacks Webinar Series: Prepping Your Company's Financials for Sale
 
Preparing for the New Lease Accounting Standard
Preparing for the New Lease Accounting StandardPreparing for the New Lease Accounting Standard
Preparing for the New Lease Accounting Standard
 
Lease Accounting: Preparing Your Business for 2022
Lease Accounting: Preparing Your Business for 2022Lease Accounting: Preparing Your Business for 2022
Lease Accounting: Preparing Your Business for 2022
 
High Net Worth Webinar Series - Tax Planning and Update for 2022
High Net Worth Webinar Series - Tax Planning and Update for 2022High Net Worth Webinar Series - Tax Planning and Update for 2022
High Net Worth Webinar Series - Tax Planning and Update for 2022
 
C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...
C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...
C-Suite Snacks Webinar Series: The Talent Wars - Can Benefits Be Your Secret ...
 
High Net Worth Webinar Series - The Business of Digital Assets​ & Blockchain
High Net Worth Webinar Series - The Business of Digital Assets​ & BlockchainHigh Net Worth Webinar Series - The Business of Digital Assets​ & Blockchain
High Net Worth Webinar Series - The Business of Digital Assets​ & Blockchain
 
High Net Worth Webinar Series - Estate Planning Strategies and Updates
High Net Worth Webinar Series - Estate Planning Strategies and UpdatesHigh Net Worth Webinar Series - Estate Planning Strategies and Updates
High Net Worth Webinar Series - Estate Planning Strategies and Updates
 
Showtime for Shuttered Venue Operators Grant (SVOG) Recipients
Showtime for Shuttered Venue Operators Grant (SVOG) RecipientsShowtime for Shuttered Venue Operators Grant (SVOG) Recipients
Showtime for Shuttered Venue Operators Grant (SVOG) Recipients
 
C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...
C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...
C-Suite Snacks Webinar Series: A Year Like No Other - Manufacturing and Distr...
 
Manufacturing & Distribution Update: The Economic Impact on the Industry
Manufacturing & Distribution Update: The Economic Impact on the IndustryManufacturing & Distribution Update: The Economic Impact on the Industry
Manufacturing & Distribution Update: The Economic Impact on the Industry
 
High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...
High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...
High Net Worth Webinar Series: SALT Thoughts - Pass-Through Entity Taxes & Re...
 
The New Rage in SALT: State Pass-Through Entity Tax
The New Rage in SALT: State Pass-Through Entity TaxThe New Rage in SALT: State Pass-Through Entity Tax
The New Rage in SALT: State Pass-Through Entity Tax
 
C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...
C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...
C-Suite Snacks Webinar Series: What's Your IP Worth? Discovering the Value of...
 
C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...
C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...
C-Suite Snacks Webinar Series: Best-In-Class Finance and Accounting: Should Y...
 
C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...
C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...
C-Suite Snacks Webinar Series: Not Sold on Selling Your Business? Why Now is ...
 
MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...
MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...
MasterSnacks: Cybersecurity - Disaster Recovery: Hoping for the Best but Plan...
 
C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...
C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...
C-Suite Snacks Webinar Series: Mise en Place: Ensuring the Success of Your Bu...
 

Recently uploaded

RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechNewman George Leech
 
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc.../:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...lizamodels9
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...lizamodels9
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfPaul Menig
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 

Recently uploaded (20)

Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman Leech
 
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc.../:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Best Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting PartnershipBest Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting Partnership
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 

MasterSnacks: Cybersecurity - Third-Party Crashers: Avoiding Service Provider Risk Headaches

  • 1. Third-Party Crashers: Avoiding Service Provider Risk Headaches May 12, 2021 | MasterSnacks Webinar Series
  • 2. Welcome & Introduction KEVIN RICCI, CISM, CISA, CRISC, MCSE, QSA Principal, Technology, Risk Advisory & Cybersecurity (TRAC) Practice Citrin Cooperman kricci@citrincooperman.com 401-421-4800
  • 3. AGENDA Stats and Facts 01 Real - Life Example 02 Avoiding Ser vice Pr ovider Risk 03 Questions? 04
  • 4. Once More Unto the Breach
  • 5. Data Breach Statistics Global Average Cost per Breach: $3.86M Average Cost per Record Compromised: $146 Average Days to Detect a Breach: 207 Average Days to Contain a Breach: 73 Average cost of downtime is $11,600 per minute Average cost of a breach is 39.6% higher if a company is not prepared 43% of Cyber Attacks Target Small Businesses Sources: Ponemon Institute/IBM Cost of a Data Breach Report & Verizon Data Breach Investigation Report
  • 6. Third-Party Security Statistics Over 53% of respondents have experienced a third- party data breach in the past 2 years 58% of respondents described their TPCRM programs as early (not deployed) or middle stage (only partially deployed) Only 24% of respondents say their organizations collaborate with third parties to improve their security measures. 56% of respondents say their organizations require some of their third parties to be subject to a more thorough assessment of their security practices. Less than 50% of respondents say their organizations earmark funds to support its third-party cybersecurity risk management program. Sources: Ponemon The Cost of Third-Party Cybersecurity Risk Management Report
  • 7. Third-Party Risk Management: Overview • What are some examples of third-party service providers? • Technical support providers • Cloud-based financial applications • Security monitoring • Email • Data backup solutions • What is third-party risk management?
  • 9. Third-Party Risk Management: Inventory and Risk Profile • Identify all third-party service providers • Utilize business stakeholder surveys, accounts payable vendor listings, and legal and/or procurement contract databases • Inventory each third-party service provider and collect supplemental documentation • Determine the risk profile
  • 10. Third-Party Risk Management: Vendor Assessments • Require vendor due diligence questionnaires to determine their ability to keep your data secure
  • 11. Third-Party Risk Management: Monitoring, Disruption and Policies • Monitoring • Frequency • Triggers • Third-party disruption • COVID • Migration to another provider • Develop policies and procedures • Elements include onboarding, the assessment processes, monitoring and offboarding
  • 12. Third-Party Risk Management: SOC Reports • Overview • Provides detailed information and assurance about controls at a service organization. • Developed by the American Institute of CPAs • Versions • SOC 1, SOC 2, SOC 3 • Type1, Type 2
  • 13. Third-Party Risk Management: SOC Reports • Trust Services Principles • Security 32 Criteria • Availability 3 Criteria • Confidentiality 2 Criteria • Processing Integrity 5 Criteria • Privacy 18 Criteria • Obtaining and reviewing the SOC report • Complementary user entity controls
  • 14.
  • 15.
  • 16.
  • 17. Questions? KEVIN RICCI, CISM, CISA, CRISC, MCSE, QSA Principal, Technology, Risk Advisory & Cybersecurity (TRAC) Practice Citrin Cooperman kricci@citrincooperman.com 401-421-4800
  • 18. Thank You F o r Wa t c h i n g & L i s t e n i n g UPCOMING MASTERSNACKS: CYBERSECURITY WEBINARS: DISASTER RECOVERY: HOPING FOR THE BEST BUT PLANNING FOR THE WORST May 19, 2021 | 12:00 PM ET/9:00 AM PT PLAYING OFFENSE – A PROACTIVE APPROACH TO CYBERSECURITY May 26, 2021 | 12:00 PM ET/9:00 AM PT