Insurance
Home›Insurance›Industry & Deals›Insurer urges tighter vendor contracts as fourth-party…
Insurer urges tighter vendor contracts as fourth-party cyber risk grows
Pennsylvania Lumbermens Mutual’s BJ Gardner says contracts should require vendors to extend SOC 2 style security obligations down through sub-vendors, and that where data is hosted changes the risk profile.
Pennsylvania Lumbermens Mutual Insurance Company’s BJ Gardner said fourth- and fifth-party cyber risk is still widely overlooked for organizations that rely on cloud services and outsourced technology.
Gardner, assistant vice president of information technology at PLM, said many vendor agreements stop short of naming fourth parties, or sub-vendors, that a direct supplier relies on, even though that information may appear in a SOC 2 report.
He argued that buyers should push vendors to disclose those relationships and apply the same security obligations to their own sub-processors, warning that risk can differ based on where data physically resides and how a vendor accesses it, such as direct access versus exposure through an indirect subsystem like a ticketing platform.
Gardner added that a SOC 2 report should be treated as a starting point rather than a guarantee of day-to-day controls, and he said insurers are tightening vendor risk requirements so questionnaires must become more specific, beyond generic questions such as whether multi-factor authentication is used.