Security

SecurityScorecard Bolsters Supply Chain Security for Financial Firms’ Third-Party IT Risk Management

TECHWORLD ·

Titan AI is a third-party risk management platform that combines AI with real-time threat intelligence. [Photo: SecurityScorecard]

✦ AI Summary

SecurityScorecard outlined measures to strengthen supply chain security in the financial sector in line with the "Guidelines for Third-Party IT Risk Management for Financial Companies," set to take effect in November.

The Financial Supervisory Service prepared the guidelines on July 30 and required lifecycle management of risks in the use of external IT services such as cloud and SaaS.

SecurityScorecard introduced its AI threat intelligence-based third-party risk management platform, TITAN AI, and explained its functions for monitoring, prioritizing and responding to risks across vendors and the extended supply chain.

SecurityScorecard has outlined measures to strengthen supply chain security in the financial sector in line with the upcoming "Guidelines for Third-Party IT Risk Management for Financial Companies," set to take effect in November. To support stronger risk management for financial companies’ use of third-party IT services, SecurityScorecard introduced its AI threat intelligence-based third-party risk management (TPRM) platform, TITAN AI, as the proposed solution.

The Financial Supervisory Service prepared the "Guidelines for Third-Party IT Risk Management for Financial Companies" on July 30. The core of the guidelines is to manage, throughout the full lifecycle, the risks of disruptions, hacking and information leaks that arise in the use of external IT services such as cloud and Software as a Service (SaaS).

According to the company, the guidelines clarify the responsibilities of boards and management and require a continuous management framework for the entire third-party relationship, from pre-contract due diligence to regular assessments, incident response, the return of information assets after contract termination and the removal of access rights. The company said the guidelines also include phased management standards and are scheduled to be rolled out sequentially by sector after November.

In financial companies, the importance of a continuous management system is growing beyond annual or point-in-time assessments. The scope of continuous management includes the security posture of third parties and the extended supply chain, with the goal of continuously identifying new threats. When risks arise, rapid response is required.

As a response to these changes, SecurityScorecard introduced the TITAN AI platform. In its announcement, SecurityScorecard said TITAN AI continuously monitors cyber risks across vendors and the extended supply chain, while providing threat intelligence, AI-based risk identification, risk prioritization and response support functions.

TITAN AI is a third-party risk management platform that combines AI and real-time Threat Intelligence. The platform complements the limitations of periodic security assessments and helps identify real threats across vendors and the extended supply chain. It also supports risk prioritization and response.

TITAN AI is a product suite made up of TITAN Watch, TITAN Assess and TITAN Secure, and supports supply chain monitoring, automated third-party security assessments, threat-based risk response and third-party risk management overall.

TITAN Watch combines threat data, AI automation and continuous monitoring. Through this, it helps identify security risks across the supply chain and respond quickly to third-party threats, while reducing financial companies’ reliance on point-in-time security assessments and helping them continuously verify vendors’ changing security posture.

TITAN Assess automates security questionnaires, compliance documentation and existing manual third-party assessment work using AI-based technology. It supports the continuous and efficient operation of third-party assessment processes by using self-reported vendor information and objective security ratings.

TITAN Secure combines Threat Intelligence and third-party risk management to support real-time monitoring of vendor risk and response to emerging threats.

In the process, it provides support for identifying unknown third-party vendors, identifying unknown fourth-party vendors and identifying risks within the extended supply chain. It also links real threat information with vendor business criticality and control information to support response prioritization.

SecurityScorecard described this as a TITAN AI-based delivery model. The target is financial institutions, and the company said it is a threat intelligence-based third-party risk management approach that includes support for ongoing visibility across third parties and the supply chain, support for risk prioritization based on real threat information, support for managing response processes and support for managing remediation processes.

SecurityScorecard emphasized that the management scope for financial companies is not limited to directly contracted third parties. It said the scope can extend to fourth parties used by vendors and beyond, underscoring the importance of securing visibility across the extended supply chain.

Woo Cheong-ha, head of SecurityScorecard’s Korea operations, said that as the scope of financial companies’ IT environments expands to cloud, SaaS and various external IT services, third-party risk has become a key factor that directly affects financial companies’ security and business continuity. He said this makes a shift in third-party IT risk management necessary for financial companies, and that they should move away from point-in-time partner security checks and toward a system that leads from continuous risk discovery to prioritization based on real threat intelligence and then to response. He added that with the upcoming rollout of the guidelines as a catalyst, SecurityScorecard’s TITAN AI will help financial companies understand and manage changing supply chain risks more efficiently by combining third-party data, Threat Intelligence and AI-based automation, and will support them in going beyond regulatory compliance to strengthen supply chain cyber resilience.

Source: TECHWORLD · Lee Gwang-jae
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406480

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.