Managing third-party risks? Here’s how a holistic approach can help

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Ali H. Asseri, Head, Cybersecurity Risk Management, Saudi Aramco, Mansur Abilkasimov, Director, Cybersecurity Governance, Schneider Electric, Dennis Frio, Managing Director, PwC, Filipe Beato Lead, Centre for Cybersecurity, World Economic Forum


  • Supply chain attacks affect multiple global victims and have large economic and operational consequences;
  • The hyper-connectivity of industries makes it imperative for supply chain stakeholders collaborate and align third-party risk governance practices, in particular when 60% of organizations have to manage more than 1,000 suppliers;
  • A collaborative, aligned and holistic approach are required to streamline the process and mitigate future risks while delivering cost and time efficiencies, multi-dimensional risk coverage and increased transparency.

Recent supply chain attacks compromising multiple large organizations across various industries have had dramatic operational, financial and reputational consequences. These events don’t just affect the victim, but all stakeholders in the value chain and demonstrate the importance of taking a collaborative and holistic approach when managing third-party risks.

Managing third-party risks is challenging owing to the large number of suppliers that organizations have to onboard and manage (60% of organizations work with more than 1,000 third parties). Companies may have diverging requirements due to the singularity and the complexity of their business and business model. In the oil and gas industry, for example, the fast-paced digitization of manufacturing companies heightens the complexity of governing risk stemming from third parties within their supply chain.

Most third-party risk management approaches depend on the organization’s internal setup, culture and priorities. Current processes and requirements in the industry are still conservative and use resource-intensive methods. This hinders their ability to scale as it leads to additional overheads in terms of business engagement, including from building the capacity to onboard young organizations and start-ups with novel technologies.

Third-party risks in the oil and gas industry
Third-party risks in the oil and gas industry

Collaborative action and a holistic approach across stakeholders in the supply chain will provide multiple benefits to organizations.

The benefits of a holistic approach to risk management
The benefits of a holistic approach to risk management

The Cyber Resilience Oil and Gas community at the World Economic Forum defined such an approach based on four crucial recommendations to assess, evaluate and monitor third-party risks. These recommendations align the expectations of engagement from different stakeholders in the oil and gas industry.

We encourage organizations to consider the four following recommendations when managing third-party risks:

Recommendation 1: Establish common cybersecurity baseline requirements with third parties by following 10 key principles:

  • Govern third parties’ risk by establishing clear roles and responsibilities within the organization as well as ownership of risks;
  • Develop the cyber-literacy and education of employees handling third parties;
  • Establish access controls and management of critical assets for both employees and third-party contractors;
  • Implement change and configuration management specifically on the assets, information and facilities falling under the third party’s scope of engagement;
  • Require secure-by-design and by-default systems, services and interfaces;
  • Maintain response and recovery mechanisms by ensuring incident management, business continuity management (BCM) and disaster recovery planning (DRP) are in place, up-to-date and tested regularly following scenarios derived from intelligence and consequence-driven analysis;
  • Protect critical information while aligning with relevant regulations and policies;
  • Secure operational and physical environments by using leading safety practices;
  • Implement a secure development lifecycle of products, systems and tools;
  • Provide support for vulnerability management and patching.

Recommendation 2: Define and adopt an evaluation approach depending on the level of risk of products and services from suppliers by combining different evaluation methods. Make the choice by combining several methods based on the scalability and coverage for optimal risk coverage.

An approach for evaluating risk management
An approach for evaluating risk management

Recommendation 3: Continuously monitor and revise all third parties depending on the level of risk to the organization.

  • Agree on organizational-level standard cybersecurity contractual terms and conditions, using existing industry baseline language (for example, minimum cyber-requirements for all third parties) where possible;
  • On top of the standard contractual terms and conditions, institute more elaborate enhanced contractual terms based on the product/service type and how critical it is (for example, for IT and cloud vendors, operational technology organizations and marketing).
  • Use segmentation criteria or an internal inherent risk approach to assess the risks and determine the level of enhanced terms and conditions needed;
  • Consider the issues identified during the assessment process before executing the contract in order to adjust the terms and conditions for any changes in risk;
  • Engage with risk subject matter experts and the legal department throughout the negotiation process as an escalation path for clause negotiation.

Recommendation 4: Share, engage and continuously communicate with supply chain stakeholders to identify, monitor and mitigate cyber-risks more quickly and as a team.

  • Set a cadence to review the risk rating of the third party in order to capture any change in its risk profile or scope of engagement;
  • Perform a continuous and risk-based review of the nature, timing and extent of continuous monitoring activities;
  • Define criteria that would trigger ad-hoc assessment and audit activities, and if possible, automate the process;
  • Embed cybersecurity in business reviews with third parties and continuously communicate on the evolving risks and threat landscape;
  • Define reporting mechanisms to raise awareness and ensure timely and informed decisions by board and senior leadership, from oversight meetings to a performance scorecard and more.

To reach a cyber-resilient environment via a collaborative and risk-informed approach, the Cyber Risk Resilience in Oil and Gas community put forth a list of 39 baseline requirements and a common assessment approach to increase cybersecurity maturity and improve the effectiveness of how third-party risk is managed across the industry. This represents the first step of industry collaboration on this issue – will you align to this initiative?


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

Libya’s political process regains momentum, but window for action is narrowing, UN envoy warns

This article is published in association with United Nations. Libya has been mired in political dysfunction since the collapse of Muammar Gaddafi’s regime in 2011, which shattered State institutions and triggered recurring struggles over legitimacy and power.  The country’s current stalemate pits the UN-recognised Government of National Unity in the capital Tripoli against eastern-based authorities backed […]
© UNICEF Chad hosts refugees from conflicts in neighbouring Sudan, the Central African Republic and Cameroon.

World Refugee Day: UN calls for renewed commitment and solidarity

This article is published in association with United Nations. The UN High Commissioner for Refugees has called on the international community to strengthen support for the nearly 42 million people worldwide who have fled their home countries to escape conflict, violence or persecution. Barham Salih highlighted the contributions refugees make to their host communities as workers, students, neighbours, […]
© WFP/Htet Oo Linn Families in Myanmar have been hit hard by rising prices, with the most vulnerable struggling to meet their daily needs.

US makes $1 billion contribution to UN child rights and food agencies

This article is published in association with United Nations. Two United Nations agencies have together welcomed more than $1 billion in assistance from the United States to support their operations targeting millions of children and hungry families in more than 40 countries. This week the US State Department announced a more than $800 million contribution to the […]
© UNICEF/Oleksii Filippov A bouquet of flowers and soft toys placed near the site of a missile strike, left in memory of the children killed in the early morning attack in Kyiv, Ukraine, on 24 April 2025.

‘Darkest chapter’: Record child violations in 2025, with national forces leading the way

This article is published in association with United Nations. For the first time, soldiers and Government forces were responsible for more grave violations against children in armed conflict than non-State armed groups – and 2025 set a grim new record for the total number of child victims.  The findings come in the annual UN report on Children and Armed […]
© UNICEF/Sukhum Preechapanich Children in Thailand are enduring extremely hot temperatures and drought. (file)

Triple climate threats affect nearly half the world’s children

This article is published in association with United Nations. Drought, extreme heat and heatwaves are the most prevalent trio of hazards endangering millions of children globally, warned a newly released climate report by the UN Children’s Fund (UNICEF). About 1.1 billion children now face at least three overlapping climate hazards, threatening their health, education and survival, […]
© UNOCHA Kyiv Pechersk Lavra is a UNESCO World Heritage Site and one of Ukraine's most significant religious and cultural landmarks.

Ukraine: Latest Russian attack kills civilians, damages cultural landmark

This article is published in association with United Nations. eral civilians were killed and dozens more were injured in the latest wave of overnight attacks in Ukraine that targeted the capital Kyiv, the city of Kharkiv and the country’s history and cultural heritage, the United Nations said on Monday. The Russian strikes damaged homes, schools and […]
© NASA/GSFC/Jacques Descloitres The Strait of Hormuz is a narrow but vital shipping route linking the Persian Gulf to the Gulf of Oman and the wider Arabian Sea. It lies between Iran to the north and Oman and UAE to the south.

Guterres welcomes US-Iran peace deal as ‘critical step’ toward ending conflict

This article is published in association with United Nations. UN Secretary General António Guterres welcomed on Sunday a new peace deal between the United States and Iran, calling it a “critical step” toward ending the conflict. According to a statement issued by his Spokesman, the agreement provides for an immediate and permanent ceasefire, the reopening of […]

Three seafarers killed in Hormuz strike as UN warns of widening fallout

This article is published in association with United Nations. Three Indian seafarers were killed in an attack on an oil tanker near the Strait of Hormuz on Wednesday, as renewed hostilities in one of the world’s most critical shipping corridors once again heightened concern over food security, fuel prices and broken global supply chains. The latest […]
© UNICEF/Royena Rasnat A group of Rohingya refugee children attend an activity centre in Cox's Bazar in Bangladesh.

Refugee numbers drop for first time in a decade, but millions remain trapped

This article is published in association with United Nations. Global forced displacement has decreased for the first time in a decade, the UN refugee agency (UNHCR) reported on Thursday, though the figure remains unacceptably high and tens of millions of people are still trapped in prolonged exile with little prospect of rebuilding their lives. UNHCR‘s flagship […]
This article is published in association with European Investment Bank.

Miles for Water: The Daily Health Burden of Climate Change on Women

This article was exclusively written for The European Sting by Ms. Jasminy Musa Belotti Dessiyeh, a 19-year-old medical student at FACISB (Faculdade de Ciências da Saúde de Barretos), Brazil. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and […]
© UNICEF A child is vaccinated against multiple diseases at a health centre in Cuba.

Children are dying as US sanctions push Cuba to the brink, warns UN human rights chief

This article is published in association with United Nations. Children are dying because doctors cannot access essential medicines, UN human rights chief Volker Türk said in a stark warning on Monday, calling for the immediate lifting of United States sanctions against the Caribbean nation that were causing “widespread harm”. “The fuel restrictions imposed since early 2026 and recent tightening of […]
© UNOCHA/Adedeji Ademigbuji Children displaced by the recent violence in Jonglei State, South Sudan, sit outside a church, home to thousands of displaced people.

World News in Brief: Millions displaced in South Sudan, global meat supply quadruples, Middle East crisis deepens global hunger

This article is published in association with United Nations. Months of fighting and insecurity have forced hundreds of thousands of people to flee their homes in South Sudan’s eastern Jonglei State, triggering “one of the most severe conflict-related displacement emergencies in recent years”, the UN refugee agency (UNHCR) said on Friday.  Tweet URL Fighting between the […]
© WFP/Marco Frattini Aid is distributed to displaced families in northern Lebanon.

Lebanon crisis: Needs soar as UN launches new funding appeal

This article is published in association with United Nations. The UN in Lebanon appealed for an additional $331.5 million on Friday to help 1.4 million people in crisis as already massive needs continue to grow, three months since deadly violence erupted between Hezbollah fighters and Israeli forces. “Humanitarian needs are soaring with each day of the […]
© UNICEF/Amer Almohibany Destroyed buildings in Harasta, Ghouta. A suburb of Damascus, Ghouta was the site of a deadly chemical weapons attack in August 2013.

Undeclared chemical weapons found in Syria, including type used in notorious Ghouta massacre

This article is published in association with United Nations. Chemical weapons inspectors have uncovered a significant cache of previously undeclared chemical weapons in Syria – including rockets of the same type used in the notorious 2013 Ghouta attack – in what the UN’s top disarmament official called a “momentous discovery” for international security. Izumi Nakamitsu briefed […]
© UNICEF Vanessa Frazier, Special Representative on Children and Armed Conflict, during a visit to frontline areas in Ukraine.

Growing up with sirens: UN child rights envoy on the toll of the Ukraine-Russia war

This article is published in association with United Nations. Children in Ukraine have been profoundly impacted by years of war, sheltering in underground schools – or forced to study online – and living with the psychological strain of constant air raid sirens that could spell death for them and their families. But children on both sides […]
OCHA/Charlotte Cans The El Niño-induced drought in Ziway Dugda, Oromia region of Ethiopia, is affecting every family and they don't have enough food at home to feed themselves. (file photo).

El Niño confirmed, set to fuel more extreme weather, says WMO

This article is published in association with United Nations. The UN urged all countries on Tuesday to bolster early warning systems after confirming the onset of El Niño, warning that the Pacific Ocean-warming phenomenon will bring above-average temperatures “nearly everywhere” and fuel more extreme weather. According to the World Meteorological Organization (WMO), there is an 80 […]
© UNICEF The aftermath of a Russian strike on a residential area in Kyiv, Ukraine’s capital.

UN deplores another wave of Russian attacks across Ukraine

This article is published in association with United Nations. Overnight attacks in three key cities in Ukraine have left several civilians dead, scores more injured, and homes, hospitals and shops destroyed or damaged, the UN Humanitarian Coordinator in the country said on Tuesday.  Matthias Schmale condemned the large-scale Russian assault on the capital Kyiv, as well as Dnipro and Kharkiv, […]
© WHO/Joël Lumbala A shipment of essential medical supplies for the Ebola response arrives at Bunia airport in Ituri province, DR Congo.

DR Congo Ebola outbreak: Nurses discharged after full recovery

This article is published in association with United Nations. Four nurses who fell ill with Ebola in the eastern Democratic Republic of the Congo (DRC) have been discharged from hospital after recovering from the often-fatal illness that sparked an international health alert.  “More recoveries are expected, especially when people are diagnosed early and able to access care, and […]
This article is published in association with United Nations.

Under fire, Kharkiv is already building for a peaceful tomorrow

This article is published in association with United Nations. Every day in Kharkiv begins with uncertainty: air raid sirens interrupt sleep; missiles strike residential neighbourhoods, industrial sites, and roads. Anxious citizens rush into metro stations during bombardments and children study underground. Yet amid the destruction, Ukraine’s second-largest city is doing something that may seem almost impossible […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com