Fourth-party cyber risk demands sharper vendor contracts, insurer says

Pennsylvania Lumbermens Mutual's BJ Gardner on SOC 2 limits and vendor oversight

Fourth-party cyber risk demands sharper vendor contracts, insurer says

Cyber

By Chris Davis

BJ Gardner (pictured), assistant vice president of information technology at Pennsylvania Lumbermens Mutual Insurance Company (PLM), says fourth- and fifth-party cyber risk remains one of the most overlooked exposures for organizations relying on cloud platforms and outsourced technology, and that closing the gap starts with contracts that go further than most vendors currently require.

The blind spot in fourth-party exposure

Most vendor contracts, Gardner said, stop short of naming the sub-vendors, or fourth parties, that a direct vendor relies on. That information sometimes surfaces in a SOC 2 report, but rarely in the contract itself. He said vendors should be required not just to disclose those relationships, but to push the same security obligations down to their own sub-processors, so the standard doesn't weaken further down the chain.

Where that data physically lives, he said, is the detail that matters most and the one that should shape every other question an organization asks. A data center or SaaS provider with direct access to company information carries a different risk profile than a vendor using a subsystem, such as a third-party ticketing platform, where a breach elsewhere could still expose client data indirectly. That distinction has become harder to track as reliance on cloud infrastructure deepens, an issue reflected in third-party risk management now treated as a governance priority at banks.

"The data is the critical piece," Gardner said. "It's probably the biggest concern to flush out, and it also determines the questionnaire details based on what service is being provided."

Why SOC 2 reports fall short

A SOC 2 report functions less like a guarantee and more like an instruction sheet, Gardner said, laying out where data is stored, what security controls are in place and what certifications a vendor holds. It carries real weight because it has been independently audited. But he cautioned against treating it as the final word on a vendor's day-to-day operations, a distinction that has taken on new urgency as insurers tighten vendor risk controls across the cyber market.

"It shouldn't be treated as the end-all-be-all for their controls and how they're actually operating on a daily basis," Gardner said. "Use it to verify that they're meeting the basic standards, before you then send out a questionnaire."

From there, he said, the questionnaire itself needs to get far more specific than it used to. A generic question about whether multi-factor authentication is in place no longer cuts it. Gardner said organizations now need to ask separately about MFA for privileged access, VPN access and role-based systems, and to press vendors on encryption standards both in transit and at rest, including how data is protected once it reaches a vendor's own servers.

Contracts need firm, defined breach timelines

Regulatory pressure is also reshaping how quickly vendors must report incidents. Under the New York State Department of Financial Services (NY DFS) cybersecurity rule, PLM has 72 hours to notify regulators once a breach is confirmed, which means its own vendor contracts need to build a faster window upstream. Gardner said vague language promising notification "as fast as possible" no longer holds up against that kind of regulatory clock.

"A vendor, whether a third or fourth party, needs to notify us within 24 hours," Gardner said. "If we have to report ourselves to regulators within 72 hours, we need to know there's a confirmed incident as quickly as possible."

He added that breach of notification in this context isn't about a vendor publicizing an incident. It's about making sure both sides know exactly who to contact, through what channel and within what timeframe, so a response doesn't stall while someone tracks down the right person.

Oversight has to be ongoing, not a one-time check

Vendor risk management doesn't end at onboarding, Gardner said, an approach increasingly common as brokers report growing scrutiny of vendor exposure across cyber accounts. PLM holds quarterly business reviews with its tier-one vendors, those handling financially significant systems or company data, to track changes to their organization, processes and subcontractors. Annually, PLM verifies that those vendors carry their own cyber insurance. A requirement Gardner said is meaningful. Because it isn't easy to obtain, carriers demand proof of real controls before writing a policy.

PLM also runs annual tabletop exercises modeled on current, real-world cyber incidents, and encourages its vendors to do the same.

"You pick a vendor, pick a platform, pick a service, and run through your incident response plan looking for holes," Gardner said. "A lot of times, an incident response plan is not about fixing the incident. It's notifications, the triaging, the reputational risk, all of that goes into the whole plan."

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!