Risk and governance

Vendor, MSP and Third-Party Oversight

Third-party oversight establishes which security responsibilities sit with each provider, what evidence they must supply, and who inside your organization reviews it, so nothing important is assumed to be somebody else's job.

Schedule a Confidential Consultation What you receive

At a glance

Part of
The decisions, records and oversight that turn security activity into something leadership can direct.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

Why this comes up

Managed service providers, managed security providers and software vendors carry out real and necessary security work, usually competently. Problems arise from unstated boundaries rather than from capability: both sides assume the other is handling patch exceptions, log retention, offboarding or alert triage.

The gap is invisible until a questionnaire asks who is responsible, or an incident makes it obvious that nobody was.

The service

What this engagement is

Who it is for

  • Organizations relying on several providers with overlapping or unclear responsibilities.
  • Companies where nobody internally reviews the security reporting providers send.
  • Businesses whose customers now ask how third-party risk is managed.
  • Leadership teams renewing, replacing or expanding a significant provider relationship.

Client-side governance of provider relationships. This is not an audit of your providers and it is not an attempt to displace them, it is the counterpart function that lets them do their job well, because expectations, evidence requirements and acceptance criteria are stated rather than assumed.

It covers the relationships you already have and the process for the ones you take on next, scaled to the access and data involved rather than applied uniformly to every supplier.

Scope

What Heights does

  • Responsibility mapping

    A written split of security responsibilities between your organization and each provider, agreed by both sides rather than inferred from a contract.

  • Contract and service-level review

    What existing agreements genuinely commit each provider to, including notification duties, evidence obligations and retention terms.

  • Evidence and reporting expectations

    What each provider reports, how often, and in what form, so performance can be assessed rather than assumed.

  • Proportionate vendor assessment

    An intake and reassessment process for new and existing vendors, scaled to the access and data each one has.

  • Recurring service review

    A regular review with providers, chaired on your side, with actions tracked to closure.

Timing

When organizations engage this

  • Several providers are involved and the responsibility boundaries between them are unclear.
  • Nobody on your side reviews the security reporting providers send.
  • A customer questionnaire or an audit asked how third-party risk is managed.
  • A provider relationship is coming up for renewal, replacement or expansion.
  • An incident or service failure exposed an assumption that turned out to be wrong.

What you receive

  • Responsibility assignment matrix covering internal teams and every provider
  • Vendor inventory with risk tiering
  • Provider reporting and evidence requirements
  • Recurring service review agenda with action tracking

Alignment

Frameworks this work touches

Establishing which of these apply to you

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
ISO 27001
An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.

This is where a vCISO is most often the missing piece. Providers execute; somebody accountable to your leadership has to set the expectation, review what arrives, and escalate when the service is not meeting it. That role is the vCISO's.

Read about vCISO leadership

Getting started

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

Will this damage our relationship with our MSP?

In our experience it improves it. Most friction between organizations and their providers comes from unstated expectations, and providers generally welcome a client who states clearly what is wanted and reviews what is delivered.

The work is about defining the boundary, not challenging competence. Where a provider is doing something well, that gets recorded too.

How many vendors should we be assessing?

Far fewer than the total number you have contracts with. Assessment effort should follow access and data: a provider with administrative access to core systems warrants real scrutiny; a supplier with no access to your data warrants very little.

Tiering the inventory first is usually what makes the program sustainable.

What if a provider will not supply the evidence we ask for?

That is itself useful information, and it is a decision for leadership rather than a technical impasse. Sometimes the request is disproportionate and should be reduced; sometimes the provider genuinely cannot evidence something material.

Either way it becomes a documented risk with an owner, rather than an unresolved email thread.

Talk through Vendor, MSP and Third-Party Oversight with us.

Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.