Cybatar Security Hub
Third-Party Cyber Risk / Vendor criticality
Third-party cyber risk guide

Vendor Criticality & Dependency Mapping

How should organisations determine which third parties deserve the most cybersecurity attention?

Direct answer

Classify vendors by consequence and dependency. Consider the business service supported, sensitive data handled, privileged or network access, production integration, concentration risk, substitutability, expected outage tolerance and recovery dependency. Use the criticality result to scale due diligence, evidence requests, monitoring, contract controls and incident coordination.

External reference

National Institute of Standards and Technology (NIST) — SP 800-161 Rev. 1 — Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

Current final publication with updates through November 2024. It integrates cybersecurity supply-chain risk management into enterprise risk activities and addresses supplier/product/service risk assessment and treatment.

Primary source →

Practical workflow

Step 1

Identify business dependence

Record the service owner, supported process, affected customers and acceptable disruption window.

Step 2

Map technical dependence

Record data classes, accounts, privileges, integrations, network paths, hosted assets and administrative access.

Step 3

Assess concentration and substitutability

Identify single points of external dependency, sub-tier concentration and practical alternatives or exit constraints.

Step 4

Assign criticality

Use transparent criteria that can be reviewed and updated when the service, access or business impact changes.

Step 5

Scale assurance

Increase evidence depth, monitoring cadence, incident requirements and resilience testing for the most consequential dependencies.

Relevant Cybatar sources

Claim boundary

A criticality tier is a prioritisation aid, not a security rating. It should be based on the organisation’s dependency and consequence context and reviewed after material service, access or architecture changes.

These pages are Cybatar-authored third-party cyber risk and resilience guidance. NIST publications are used as external references. The mappings are not NIST validations, certifications, endorsements, legal opinions or statements that a supplier or deployment is secure.

Evidence