On Governance: Boards and the Weakest Link in Third-Party Information Security Risk Management
Our Privacy Policy has been updated! The Conference Board uses cookies to improve our website, enhance your experience, and deliver relevant messages and offers about our products. Detailed information on the use of cookies on this site is provided in our cookie policy. For more information on how The Conference Board collects and uses personal data, please visit our privacy policy. By continuing to use this Site or by clicking "OK", you acknowledge our privacy policy and consent to the use of cookies.  Our Privacy Policy has been updated! Detailed information on the use of cookies on this site is provided in our cookie policy and our privacy policy. 
TCB Tourch
Loading...
  • logoImage
  •  
    • US
    • EUROPE
    • ASIA
  • 2

    Close
    • Insights
        • Insights
        • Explore by Center
          • Explore by Center
          • CED
            Committee for Economic Development

          • Economy, Strategy & Finance

          • Governance & Sustainability

          • Human Capital

          • Marketing & Communications

        • Explore by Content Type
          • Explore by Content Type
          • Reports

          • Upcoming Webcasts

          • On Demand Webcasts

          • Podcasts

          • Charts & Infographics

        • Trending Topics
          • Trending Topics
          • Artificial Intelligence (AI)

          • Navigating Washington

          • Geopolitics

          • US Economic Forecast

          • Sustainability

          • Future of Work

    • Events
        • Events
        • Upcoming Events
          • Upcoming Events
          • People First: Opportunity and Access

          • CHRO Summit: Navigating through a Tsunami of Change

          • Future: People Asia

          • Executive Compensation in a Disruptive World

          • CED Distinguished Leadership Awards Celebration

          • The 2025 IBI/Conference Board Health and Productivity Forum

          • Explore all Upcoming Events

        • Member-Exclusive Programs
          • Member-Exclusive Programs
          • Center Briefings

          • Experts Live

          • Roundtables

          • Working Groups

          • Expert Briefings

    • Data
        • Data
        • Consumer Confidence Index

        • Data Central

        • TCB Benchmarking

        • Employment Trends Index

        • Global Economic Outlook

        • Leading Economic Indicators

        • Help Wanted OnLine

        • Labor Markets

        • Measure of CEO Confidence

        • Human Capital Benchmarking &
          Data Analytics

        • CMO+CCO Meter Dashboard

    • Centers
        • Centers
        • Our Centers
          • Our Centers
          • Committee for Economic Development

          • Economy, Strategy & Finance

          • Governance & Sustainability

          • Human Capital

          • Marketing & Communications

        • Center Membership
          • Center Membership
          • What Is a Center?

          • Benefits of Center Membership

          • Join a Center

    • Councils
        • Councils
        • Find a Council
          • Find a Council
          • Economy, Strategy & Finance

          • Governance & Sustainability

          • Human Capital

          • Marketing & Communications

        • Council Membership
          • Council Membership
          • What is a Council?

          • Benefits of Council Membership

          • Apply to a Council

    • Membership
        • Membership
        • Why Become a Member?
          • Why Become a Member?
          • Benefits of Membership

          • Check if Your Organization is a Member

          • Speak to a Membership Associate

        • Types of Membership
          • Types of Membership
          • Council

          • Committee for Economic Development

          • Economy, Strategy & Finance

          • Governance & Sustainability

          • Human Capital

          • Marketing & Communications

          • Insights

        • Already a Member?
          • Already a Member?
          • Sign In to myTCB®

          • Executive Communities

          • Member-Exclusive Programs

    • About Us
        • About Us
        • Who We Are
          • Who We Are
          • About Us

          • In the News

          • Press Releases

          • Our History

          • Support Our Work

          • Locations

          • Contact Us

        • Our Community
          • Our Community
          • Our Leadership

          • Our Experts

          • Trustees

          • Voting Members

          • Global Counsellors

          • Careers

          • This Week @ TCB

    • Careers
    • This Week @ TCB
    • Sign In to myTCB®
      • US
      • EUROPE
      • ASIA
    • Insights
      • Insights
      • Explore by Center
        • Explore by Center
        • CED
          Committee for Economic Development

        • Economy, Strategy & Finance

        • Governance & Sustainability

        • Human Capital

        • Marketing & Communications

      • Explore by Content Type
        • Explore by Content Type
        • Reports

        • Upcoming Webcasts

        • On Demand Webcasts

        • Podcasts

        • Charts & Infographics

      • Trending Topics
        • Trending Topics
        • Artificial Intelligence (AI)

        • Navigating Washington

        • Geopolitics

        • US Economic Forecast

        • Sustainability

        • Future of Work

    • Events
      • Events
      • Upcoming Events
        • Upcoming Events
        • People First: Opportunity and Access

        • CHRO Summit: Navigating through a Tsunami of Change

        • Future: People Asia

        • Executive Compensation in a Disruptive World

        • CED Distinguished Leadership Awards Celebration

        • The 2025 IBI/Conference Board Health and Productivity Forum

        • Explore all Upcoming Events

      • Member-Exclusive Programs
        • Member-Exclusive Programs
        • Center Briefings

        • Experts Live

        • Roundtables

        • Working Groups

        • Expert Briefings

    • Data
      • Data
      • Consumer Confidence Index

      • Data Central

      • TCB Benchmarking

      • Employment Trends Index

      • Global Economic Outlook

      • Leading Economic Indicators

      • Help Wanted OnLine

      • Labor Markets

      • Measure of CEO Confidence

      • Human Capital Benchmarking & Data Analytics

      • CMO+CCO Meter Dashboard

    • Centers
      • Centers
      • Our Centers
        • Our Centers
        • Committee for Economic Development

        • Economy, Strategy & Finance

        • Governance & Sustainability

        • Human Capital

        • Marketing & Communications

      • Center Membership
        • Center Membership
        • What is a Center?

        • Benefits of Center Membership

        • Join a Center

    • Councils
      • Councils
      • Find a Council
        • Find a Council
        • Economy, Strategy & Finance

        • Governance & Sustainability

        • Human Capital

        • Marketing & Communications

      • Council Membership
        • Council Membership
        • What is a Council?

        • Benefits of Council Membership

        • Apply to a Council

    • Membership
      • Membership
      • Why Become a Member?
        • Why Become a Member?
        • Benefits of Membership

        • Check if Your Organization is a Member

        • Speak to a Membership Associate

      • Types of Membership
        • Types of Membership
        • Council

        • Committee for Economic Development

        • Economy, Strategy & Finance

        • Governance & Sustainability

        • Human Capital

        • Marketing & Communications

        • Insights

      • Already a Member?
        • Already a Member?
        • Sign In to myTCB®

        • Executive Communities

        • Member-Exclusive Programs

    • About Us
      • About Us
      • Who We Are
        • Who We Are
        • About Us

        • In the News

        • Press Releases

        • This Week @ TCB

        • Our History

        • Support Our Work

        • Locations

        • Contact Us

      • Our Community
        • Our Community
        • Our Leadership

        • Our Experts

        • Trustees

        • Voting Members

        • Global Counsellors

        • Careers

        • This Week @ TCB

    • Careers
    • Sign In to myTCB®
    • Download TCB Insights App
  • Insights
    Insights

    Our research and analysis have helped the world's leading companies navigate challenges and seize opportunities for over 100 years.

    Explore All Research

    Economic Indicators

    • Explore by Center
    • CED
      Committee for Economic Development
    • Economy, Strategy & Finance
    • Governance & Sustainability
    • Human Capital
    • Marketing & Communications
    • Explore by Content Type
    • Reports
    • Upcoming Webcasts
    • On Demand Webcasts
    • Podcasts
    • Charts & Infographics
    • Trending Topics
    • Artificial Intelligence (AI)
    • Navigating Washington
    • Geopolitics
    • US Economic Forecast
    • Sustainability
    • Future of Work
  • Events
    Events

    Our in-person and virtual events offer unmatched opportunities for professional development, featuring top experts and practitioners.

    See Everything Happening This Week

    Sponsor a Program

    • Upcoming Events
    • People First: Opportunity and Access

      June 12 - 13, 2025

      CHRO Summit: Navigating through a Tsunami of Change

      June 24, 2025

      Future: People Asia

      September 04 - 05, 2025

    •  
    • Executive Compensation in a Disruptive World

      September 16 - 17, 2025

      CED Distinguished Leadership Awards Celebration

      October 08, 2025

      The 2025 IBI/Conference Board Health and Productivity Forum

      October 16 - 17, 2025

    • Member-Exclusive Programs
    • Center Briefings
    • Experts Live
    • Roundtables
    • Working Groups
    • Expert Briefings
    • Explore by Type
    • Events
    • Webcasts
    • Podcasts
    • Member-Exclusive Programs
    • Center Briefings
    • Experts Live
    • Roundtables
    • Working Groups
    • Expert Briefings
  • Data
    Corporate Disclosure Data

    TCB Benchmarking

    Real-time data & analytical tools to benchmark your governance, compensation, environmental, human capital management (HCM) and social practices against US public companies.

    Economic Data

    All Data

    See current direction and trends across key indicators

    Consumer Confidence Index

    US consumers' thoughts on the economy, jobs, finances and more

    Data Central

    One-stop, member-exclusive portal for the entire suite of indicators

    Labor Markets

    Covering all aspects of labor markets, from monthly development to long-term trends

    Measure of CEO Confidence

    Examines the health of the US economy from the perspective of CEOs

     

    Recession & Growth Trackers

    See the current and future state of 16 economies.

    Global Economic Outlook

    Track the latest short-, medium-, and long-term growth outlooks for 77 economies

    Leading Economic Indicators

    Track the state of the business cycle for 12 global economies across Asia and Europe

    Help Wanted OnLine

    Track the status of job markets across the US through online job listings

    Other Featured Data

    Human Capital Analytics Tools

    Tools to understand human capital management and corporate performance

    CMO+CCO Meter Dashboard

    Tracks the impact, resources, and satisfaction of CMOs and CCOs

  • Centers
    Centers

    Centers offer access to world-class experts, research, events, and senior executive communities.

    Our Centers
    • Committee for Economic Development
    • Economy, Strategy & Finance
    • Governance & Sustainability
    • Human Capital
    • Marketing & Communications
    Center Membership
    • What Is a Center?
    • Benefits of Center Membership
    • Join a Center
  • Councils
    Councils

    Councils are invitation-only, peer-led communities of senior executives that come together to exchange knowledge, accelerate career development, and advance their function.

    Find a Council
    • Economy, Strategy & Finance
    • Governance & Sustainability
    • Human Capital
    • Marketing & Communications
    Council Membership
    • What Is a Council?
    • Benefits of Council Membership
    • Apply to a Council
  • Membership
    Membership

    Membership in The Conference Board arms your team with an arsenal of knowledge, networks, and expertise that's unmatched in scope and depth.

    • Why Become a Member?
    • Benefits of Membership
    • Check if Your Organization is a Member
    • Speak to a Membership Associate
    • Types of Membership
    • Council
    • Committee for Economic Development
    • Economy, Strategy & Finance
    • Governance & Sustainability
    • Human Capital
    • Marketing & Communications
    • Insights
    • Already a Member?
    • Sign in to myTCB®
    • Executive Communities
    • Member-Exclusive Programs
  • About Us
    About Us

    The Conference Board is the global, nonprofit think tank and business membership organization that delivers Trusted Insights for What's Ahead®. For over 100 years, our cutting-edge research, data, events and executive networks have helped the world's leading companies understand the present and shape the future.

    Learn more about Membership

    • Who We Are
    • About Us
    • In the News
    • Press Releases
    • Our History
    • Support Our Work
    • Locations
    • Contact Us
    • Our Community
    • Our Leadership
    • Our Experts
    • Trustees
    • Voting Members
    • Careers
    • This Week @ TCB
Check if You're a Member
Create Account
Forgot Your Password?

Members of The Conference Board get exclusive access to the full range of products and services that deliver Trusted Insights for What's Ahead ® including webcasts, publications, data and analysis, plus discounts to conferences and events.

Environmental, Social & Governance Briefs

Timely insights from the Governance & Sustainability Center

  • Email
  • Linkedin
  • Facebook
  • Twitter
  • Copy Link

On Governance: Boards and the Weakest Link in Third-Party Information Security Risk Management

January 19, 2018

On Governance is a new series of guest blog posts from corporate governance thought leaders. The series, which is curated by the Governance Center research team, is meant to serve as a way to spark discussion on some of the most important corporate governance issues.

 

Should you outsource information security risk management to better govern and manage third-party information security risk? 

Cybersecurity crosses all lines of business and all support functions within a business regardless of vertical industry placement.  Most business functions use an information system, digital device, or network service to produce their product or deliver and support their services.  Increasingly, third parties are being used to shape and deliver these end-to-end value propositions; outsourcing is no longer just about cost reduction.  

Almost 75 percent of respondents in Deloitte’s 2016 Third Party Governance and Risk Management Survey indicated that their third-party partners would play a highly important or critical role in their businesses, up from 60 percent in 2015. As the extended enterprise continues its expansion, third party ecosystem partners create a new and very complex information security risk environment. 

In a business environment where the weakest link in an ecosystem can jeopardize the entire community, effectively governing and managing third party risk takes on greater importance.  Complexity, business continuity, transparency and an extended attack surface are just some of the new challenges facing third-party information security risk governance and management.  When your company can be attacked through a vulnerability in a business partner’s environment, how risk is identified and mitigated takes on an exponential level of complexity.  As companies become more dependent on their partners for delivery of their entire value proposition, risk probabilities and impacts can change dramatically.      

While having a third party manage information security risk to better manage third-party information security risk may sound like a paradox, rethinking assumptions and perspectives in a volatile business and risk environment is always a best practice.

With so much at stake around information security, does it make sense to have a third party manage information security risk? No board wants to hear that their customer list or IP has been stolen as a result of a security breach, but the consensus is that a breach is more a matter of when, not if for most organizations. The financial, reputational and legal risks of these breaches play out in the daily news headlines and given the growing systemic complexity of the extended enterprise, is a third party now the best option to mitigate the overall information security risk landscape?        

The decision to outsource is no longer driven by a desire to leverage cost arbitrage.  It involves a thorough understanding of the business risks and all relevant trade-offs.   For example, a CIO of a large bank in Europe commented that he could not replicate what a managed information security service provider could do in terms of continuous monitoring and real-time views into emerging global threats and the ability to react to them.  Real-time monitoring, a rapid response capability and the ability to understand as broad of a risk environment as possible are critical value drivers in today’s information security world.  

Additional advantages and disadvantages to consider include:

Threat intelligence

Trying to establish a threat management capability is difficult for even the best organizations.  Most managed service organizations provide a threat intelligence service that correlates, evaluates and analyzes the threat landscape and provides real-time reporting to their clients.  This function is essential for a high-performing information security function because preventing attacks is always a more efficient approach than reacting to an attack or widespread breach.

Systemic Global Risk

Using a third party allows a client to leverage the provider’s customer base, threat intelligence, and correlation capability to identify attack vectors and provide the client with a valuable early warning capability. Hackers find and hack the weakest link, and they move quickly. Bad actors start somewhere across the globe, and the right third party partner can leverage their global view and have visibility into these attacks early in the attack sequence. They can then advise their clients of impending threats well in advance of a threat being made on their client’s landscape. This helps all companies and is a unique advantage that a third party can bring.

Short- and Long-Term Costs

While cost synergies can remain, the short- and long-term nature of costs and their related benefits needs to be re-examined.  Repurposing or reducing labor costs and streamlining the application landscape and costs are often early wins.  Functions such as 24-hour security operations and Security Information and Event Management (SIEM) can usually leverage a third-party vendor’s economies of scale and scope.  

A board member of a large conglomerate in the Philippines recognized that the conglomerate’s companies were struggling to attract and retain talent to operate an effective security program and needed to look to a large reliable partner to provide the right talent to make their approach sustainable.

Third-party information security vendors can usually provide cost advantages in onboarding, protecting and assessing assets during M&A. Moreover, there may also be advantages in testing the current controls and systems prior to closing the deal.  Post-acquisition bad news can have a significant impact on deal valuation as has been seen recently. 

C-Suite and Board Transparency

Near real-time monitoring and reporting is often a hallmark of third-party providers in information security.  Key metrics reflected in easy-to-consume dashboard reporting structures can greatly simplify, educate and reassure a board. Digital success starts in the boardroom, and a board that comprehends this increasingly complex environment is a key part of effectively governing it.    

Risk Reduction

Perceptions are strong that in-house security can naturally be provided that is better than what a third party can provide.  However, in the age of the rapid fire, global attack landscape, the right third-party information security partner might be the only way to adequately address the scope and speed of the global risk environment in a cost-effective manner.  This is one functional area where third parties may actually become the most viable choice because of these global issues, the expansion of the extended enterprise, their scale and their unique position in the marketplace.   

Directors can start to understand this issue by asking the following questions:

 

  • Have we performed a third-party risk assessment, and have we prioritized the risks identified?
  • How do we coordinate and work with all of our third parties to raise awareness and manage and monitor collective risk?
  • What outbound risks do we present to our ecosystem partners as one of their third-party suppliers?  What are we liable for, is this insurable and how do we mitigate this risk?
  • What metrics do we track in this area? 
  • Have we assessed the relative risk based advantages that an information security managed services provider could bring to this issue? 

Conclusion

Cybersecurity risk is a key business issue that most boards, executives and companies are continuing to struggle with.  Protiviti’s research report Executive Perspectives on Top Risks in 2018 lists the speed of disruptions and technology innovations along with cyber threats as two of the top three risks that directors and executives are concerned with as the year begins.

Deloitte estimates that companies that excel at third party risk management outperform their peers by an additional 4 to 5 percent of return on equity. It would seem risk and return increasingly runs through third-party ecosystems.  Ironically, having a third-party manage information security risk might offer the most effective way to manage the pervasive and complex nature of third-party information security risk.  

The views presented on the Governance Center Blog are not the official views of The Conference Board or the Governance Center and are not necessarily endorsed by all members, sponsors, advisors, contributors, staff members, or others associated with The Conference Board or the Governance Center.     

Download Brief
Great News!

You already have an account with The Conference Board.

Please try to login in with your email or click here if you have forgotten your password.

  • Download
  • Download Brief

Authors

Kazunori Yozawa

Kazunori Yozawa

Global CTO, CEO (Japan Region)

Read BioKazunori Yozawa

Bob Zukis

Bob Zukis

Founder and CEO, Digital Directors Network

Read BioBob Zukis

More From This Series

Brief

80 Years of Corporate Citizenship & Philanthropy Leadership

November 27, 2023

Brief

How CEOs and Boards Can Enhance Digital Trust

April 04, 2023

Brief

Reaching Net-Zero Emissions

January 31, 2023

Brief

Why Support for Political Activity Proposals is Declining

June 21, 2022

Brief

70% of Environmental Shareholder Proposals Going To Vote

May 20, 2022

Brief

First 2022 Racial Equity Audit Proposals Successful

March 22, 2022

View Less View More

Conference Board Sample Web Chat
chatbot-Icon TCB Logo
chatbot-Icon
Navigating Washington - Sign up to receive the latest business insights related to executive orders, new laws, and changing regulations.
ABOUT US
  • Who We Are
  • Annual Report
  • Our History
  • Our Experts
  • Our Leadership
  • In the News
  • Press Releases
MEMBERSHIP
  • Become a Member
  • Sign In to myTCB®
  • Access Experts
  • Member-Only Events
  • Data & Benchmarking
  • Manage Account
EXPLORE
  • Centers
  • Councils
  • Latest Research
  • Events
  • Webcasts
  • Podcasts
  • This Week @ TCB
CONTACT US
  • Americas
    +1 212 759 0900
    customer.service@tcb.org
  • Europe/Africa/Middle East
    +32 2 675 5405
    brussels@tcb.org
  • Asia
    Hong Kong | +852 2804 1000
    Singapore | +65 8298 3403
    service.ap@tcb.org
CAREERS
  • See Open Positions
Terms Of Use | Privacy Policy | Event Code of Conduct | Trademarks
© 2025 The Conference Board Inc. All rights reserved. The Conference Board and torch logo are registered trademarks of The Conference Board.
The use of all The Conference Board data and materials is subject to the Terms of Use. Reprint requests are reviewed individually and may be subject to additional fees.The Conference Board reserves the right to deny any request.
Terms of Use | Privacy Policy | Event Code of Conduct | Trademarks
© 2025 The Conference Board Inc. All rights reserved. The Conference Board and torch logo are registered trademarks of The Conference Board.
The use of all data from The Conference Board data and materials is subject to the Terms of Use. Reprint requests are reviewed individually and may be subject to additional fees.The Conference Board reserves the right to deny any request.

Thank you for signing up. You will now receive CEO Insights for What's Ahead every Wednesday morning. You can unsubscribe at any time or manage your preferences to receive more content from The Conference Board.

Announcing The Conference Board AI Virtual Conference Series

Explore the Impact of AI on Your Business

Members receive complimentary registration - Learn more >>