Galink Logo

Solution

Partners

Resources

About

Log in

Galink the TPRM solution No. 1

Vendor Risk: The Lean Method by Joseph Graceffa

Sep 1, 2026

I have been working in cyber security for nearly 30 years. Throughout my career, I have been fortunate enough to support businesses across the entire spectrum: seed-stage start-ups, scale-ups, SMEs and large corporations. I have come to the following conclusion: there are two ways to get it wrong.


The first is to do nothing. The second, less obvious one, is to copy a large corporation: endless questionnaires, processes that nobody knows how to implement, files that end up buried in a cloud drive without ever influencing a single decision.


The fundamental principle to accept from the outset is: 100 per cent security does not exist.


At some point, you have to stop and adopt a residual risk approach. Once a reasonable effort has been made, the rest comes down to a conscious risk decision: either we accept it, or we transfer it to an insurer.


As a CISO, the temptation and pressure to strive for perfection are strong. Yet our role is different. It consists of helping the organisation take conscious risks with its suppliers, rather than risks it is forced to accept.


Today I’d like to share with you four key guiding principles behind a supplier strategy that aligns with the business.


Distinguishing what creates value from the rest

Supplier risk management begins by stopping pretending that all suppliers are a priority.


We identify the few truly critical service providers – those who handle sensitive data or who could bring the business to a standstill – and focus our energy on them.


The basic principles are universal and apply across all sectors and organisation sizes:

  • an honest mapping of critical suppliers;

  • the principle of least privilege: everyone is granted access strictly in line with their needs;

  • prioritisation through the right question: does this partner really need access to this data?

  • basic security hygiene: identities, patching, backups, and malware control.


Most of what you then need to know about a new supplier will boil down to two questions:

  • Is there someone in charge of security?

  • Is the security policy documented? Without written rules, there is no framework.


Any silence or undue delay in responding will be indicative of a lack of maturity.


From there, you’ll be better able to gauge the effort required and the level of guidance needed when you begin the contractual process.


Include security clauses, and where justified, a Security Assurance Plan as an annex, which sets out in black and white the expected measures, incident reporting procedures, audit rights and business continuity commitments. This obliges partners to exercise a minimum level of due diligence.


Be careful, however: paper can bear anything, but reality far less so. A contract does not prevent unpleasant surprises. Hence the real issue: monitoring.


Sending out questionnaires with 200 questions without ever reading the responses thoroughly and failing to draw any conclusions from them is not security; it is a waste. A waste that creates an illusion of security even more dangerous than the complete absence of any process.


Invest in processes and people, not in tools

A mistake I frequently see is piling up tools to compensate for a lack of method.


The best investments I have seen boil down to three points:

  • Well-thought-out contractual models,

  • Time to adapt them to the specific use case, and

  • Professionals capable of reading between the lines and challenging a supplier.


Ultimately, everything comes down to people. But how, then, do you choose the right candidate?


I would start by recommending someone with a certain level of technical expertise.


This foundation must be sufficient to understand what the supplier actually does, how it integrates with the information system, what data it handles, and where things might go wrong.


I would then add a certain contractual acumen; the kind that enables them to read clauses, propose amendments, but also identify areas of ambiguity from which problems may arise.


As you might expect, these skills are only half the story. The crux of the matter actually lies elsewhere. I am, of course, referring to soft skills: explaining risk in layman’s terms, negotiating without causing friction, and maintaining the relationship over the long term.


You need to find someone who is organised, inquisitive, tenacious, capable of challenging a supplier without going on the warpath, and sufficiently in tune with the business so as not to turn TPRM into a bureaucratic nightmare.


Finally, I’ll conclude with the most crucial point: your ideal candidate will accept that nothing will ever be perfect.


The CISO as a business partner, not ‘Doctor No’

An effective TPRM is one that is accepted as an integral and strategic part of the business.


One thing is certain, however: managing supplier risk early on will deliver the best return on investment. As a vCISO for a wide variety of start-ups, I have seen this time and again: good cyber security is a corporate asset in its own right, just like your order book or your brand.


We’re talking about very tangible issues here. Being able to quickly demonstrate a certain level of cyber security can prove decisive in closing a deal with a major client or even securing funding.


Maturity is assessed, and it carries weight in negotiations.


The CISO must be the guardian and champion of this corporate asset. Without dedicating some time to listening and making suggestions, you become an obstacle rather than a partner.


What must be avoided at all costs is the ‘Doctor No’ CISO attitude: overwhelmed, holed up behind their antivirus console and firewalls, only emerging from their shell to impose bans. The opposite approach that has served me best can be summed up in one sentence: “We want to do this — I suggest we look at it from this angle instead.”


By opposing everything, we lose the upper hand and the business ends up managing without us.


AI: the dawn of a new era

The fourth principle has been the subject of much discussion. Whilst AI has certainly made its fair share of false promises, the reality is that it is now part of the landscape and is here to stay.


Recent years have allowed us to iterate and identify the use cases where it can genuinely transform the way we work. The key is to maintain a clear-eyed view of its strengths and weaknesses.


One of its undeniable strengths lies in document analysis: preparing and analysing questionnaires, comparing responses across suppliers, generating summaries that are understandable to business units, and standardising expectations by supplier type.


Between reading, sorting, formatting and comparing, the time savings amount to around 30–50 per cent. The challenge then is to reallocate this time to what really matters: talking to business units, challenging key suppliers, and drawing up realistic action plans rather than churning out slide after slide.


Be careful, however: safeguards are non-negotiable. Avoid automated decisions without human review. Ensure your data is fed into controlled environments.


As for the rest, I remain firmly convinced that certain things are not meant to be delegated to technology: context, direct discussion with a key supplier, and risk assessments.


Certain tasks require a level of nuance and human intelligence that goes beyond that of algorithms.


What the future holds

If I look ahead to 2030, I see a more integrated and dynamic TPRM. I see supplier data being continuously updated, evolving risk scores, and a CISO spending more time on strategic discussions than on gathering responses.


Lean is not a constraint imposed by a tight budget, but the direction in which the industry is heading. We might as well adopt the right habits right now.


I look forward to discussing this with you.

In the meantime, if these topics resonate with challenges facing your organisation, we’ll have the opportunity to discuss them on 30 September at 10.00 am with six other supplier risk experts. Free registration.