Managing third-party risks? Here’s how a holistic approach can help

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Ali H. Asseri, Head, Cybersecurity Risk Management, Saudi Aramco, Mansur Abilkasimov, Director, Cybersecurity Governance, Schneider Electric, Dennis Frio, Managing Director, PwC, Filipe Beato Lead, Centre for Cybersecurity, World Economic Forum


  • Supply chain attacks affect multiple global victims and have large economic and operational consequences;
  • The hyper-connectivity of industries makes it imperative for supply chain stakeholders collaborate and align third-party risk governance practices, in particular when 60% of organizations have to manage more than 1,000 suppliers;
  • A collaborative, aligned and holistic approach are required to streamline the process and mitigate future risks while delivering cost and time efficiencies, multi-dimensional risk coverage and increased transparency.

Recent supply chain attacks compromising multiple large organizations across various industries have had dramatic operational, financial and reputational consequences. These events don’t just affect the victim, but all stakeholders in the value chain and demonstrate the importance of taking a collaborative and holistic approach when managing third-party risks.

Managing third-party risks is challenging owing to the large number of suppliers that organizations have to onboard and manage (60% of organizations work with more than 1,000 third parties). Companies may have diverging requirements due to the singularity and the complexity of their business and business model. In the oil and gas industry, for example, the fast-paced digitization of manufacturing companies heightens the complexity of governing risk stemming from third parties within their supply chain.

Most third-party risk management approaches depend on the organization’s internal setup, culture and priorities. Current processes and requirements in the industry are still conservative and use resource-intensive methods. This hinders their ability to scale as it leads to additional overheads in terms of business engagement, including from building the capacity to onboard young organizations and start-ups with novel technologies.

Third-party risks in the oil and gas industry
Third-party risks in the oil and gas industry

Collaborative action and a holistic approach across stakeholders in the supply chain will provide multiple benefits to organizations.

The benefits of a holistic approach to risk management
The benefits of a holistic approach to risk management

The Cyber Resilience Oil and Gas community at the World Economic Forum defined such an approach based on four crucial recommendations to assess, evaluate and monitor third-party risks. These recommendations align the expectations of engagement from different stakeholders in the oil and gas industry.

We encourage organizations to consider the four following recommendations when managing third-party risks:

Recommendation 1: Establish common cybersecurity baseline requirements with third parties by following 10 key principles:

  • Govern third parties’ risk by establishing clear roles and responsibilities within the organization as well as ownership of risks;
  • Develop the cyber-literacy and education of employees handling third parties;
  • Establish access controls and management of critical assets for both employees and third-party contractors;
  • Implement change and configuration management specifically on the assets, information and facilities falling under the third party’s scope of engagement;
  • Require secure-by-design and by-default systems, services and interfaces;
  • Maintain response and recovery mechanisms by ensuring incident management, business continuity management (BCM) and disaster recovery planning (DRP) are in place, up-to-date and tested regularly following scenarios derived from intelligence and consequence-driven analysis;
  • Protect critical information while aligning with relevant regulations and policies;
  • Secure operational and physical environments by using leading safety practices;
  • Implement a secure development lifecycle of products, systems and tools;
  • Provide support for vulnerability management and patching.

Recommendation 2: Define and adopt an evaluation approach depending on the level of risk of products and services from suppliers by combining different evaluation methods. Make the choice by combining several methods based on the scalability and coverage for optimal risk coverage.

An approach for evaluating risk management
An approach for evaluating risk management

Recommendation 3: Continuously monitor and revise all third parties depending on the level of risk to the organization.

  • Agree on organizational-level standard cybersecurity contractual terms and conditions, using existing industry baseline language (for example, minimum cyber-requirements for all third parties) where possible;
  • On top of the standard contractual terms and conditions, institute more elaborate enhanced contractual terms based on the product/service type and how critical it is (for example, for IT and cloud vendors, operational technology organizations and marketing).
  • Use segmentation criteria or an internal inherent risk approach to assess the risks and determine the level of enhanced terms and conditions needed;
  • Consider the issues identified during the assessment process before executing the contract in order to adjust the terms and conditions for any changes in risk;
  • Engage with risk subject matter experts and the legal department throughout the negotiation process as an escalation path for clause negotiation.

Recommendation 4: Share, engage and continuously communicate with supply chain stakeholders to identify, monitor and mitigate cyber-risks more quickly and as a team.

  • Set a cadence to review the risk rating of the third party in order to capture any change in its risk profile or scope of engagement;
  • Perform a continuous and risk-based review of the nature, timing and extent of continuous monitoring activities;
  • Define criteria that would trigger ad-hoc assessment and audit activities, and if possible, automate the process;
  • Embed cybersecurity in business reviews with third parties and continuously communicate on the evolving risks and threat landscape;
  • Define reporting mechanisms to raise awareness and ensure timely and informed decisions by board and senior leadership, from oversight meetings to a performance scorecard and more.

To reach a cyber-resilient environment via a collaborative and risk-informed approach, the Cyber Risk Resilience in Oil and Gas community put forth a list of 39 baseline requirements and a common assessment approach to increase cybersecurity maturity and improve the effectiveness of how third-party risk is managed across the industry. This represents the first step of industry collaboration on this issue – will you align to this initiative?


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

This article is published in association with United Nations.

UN agencies step up Ebola response in eastern DR Congo

This article is published in association with United Nations. United Nations agencies have moved swiftly to support efforts to contain the latest Ebola outbreak in eastern Democratic Republic of the Congo (DRC), delivering emergency medical supplies, protective equipment and logistics support. As health authorities in both the DRC and Uganda respond to the deadly resurgence, the […]
© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]
UN Photo/Eskinder Debebe UN Relief Chief Tom Fletcher (centre) along with Ambassador Mike Waltz (right) and Jeremy P. Lewin of the United States hold a joint press briefing on funding to the humanitarian system.

UN welcomes $1.8 billion US boost for humanitarian operations

This article is published in association with United Nations. An additional $1.8 billion in US humanitarian funding will allow the United Nations and its partners to expand emergency relief operations reaching millions of people worldwide, as rising global needs and funding shortfalls force aid agencies to scale back assistance. The funding announcement, made on Wednesday by […]
© WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]
This article was exclusively written for The European Sting by Mr. Franco Miguel Nodado, a 4th-year medical student from the Philippines. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Autism Spectrum Disorders in Global Health: Bridging the Gap in  Awareness, Early Diagnosis, and Inclusive Care 

This article was exclusively written for The European Sting by Ms. Georgia Maria Vardalachaki, a medical student from the Medical University of Crete, Greece. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s […]
© WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

Hantavirus-hit ship evacuation completed as quarantines begin

This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Strait of Hormuz de-escalation is urgent, says UN chief

This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
This article is published in association with United Nations.

Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
Nuclear energy in the Middle East: A realistic choice or a risk?

Nuclear energy in the Middle East: A realistic choice or a risk?

This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Bahrain and US float Security Council resolution on the Strait of Hormuz

This article is published in association with United Nations. Bahrain and the United States have circulated a draft Security Council resolution calling for Iran to cease attacks in the Strait of Hormuz, their ambassadors outlined to journalists at UN Headquarters in New York on Thursday. The text is supported by Kuwait, Qatar, Saudi Arabia and the […]
© CDC An enhanced microscopic image shows the Hantavirus.

Hantavirus outbreak: Another passenger contracts disease

This article is published in association with United Nations. It’s been confirmed that another passenger from the cruise liner linked to the outbreak of hantavirus has contracted the disease, which has claimed the lives of three people on board and sparked an international alert coordinated by the UN World Health Organization (WHO). The individual, who is […]
This article is published in association with United Nations.

UN warns of worsening human rights crisis in Mali after deadly attacks

This article is published in association with United Nations. The human rights situation in Mali is rapidly deteriorating following coordinated attacks by armed groups across the country, with civilians killed, displaced and cut off from food and aid, UN rights office OHCHR said on Tuesday. The violence, which erupted on 25 and 26 April, saw large-scale […]
© UNICEF A damaged ambulance in Tebnine in southern Lebanon.

In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
© Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

Uncertainty continues over safety in the Strait of Hormuz

This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com