Required Structural Changes for Appropriate Cyber-Risk Oversight and Management

Ralph A. Young · Productivity Press eBooks · 2025

Many organizations outsource activities such as the manufacturing of product components and the provision of services to vendors referred to as third-party providers. Such organizations that outsource activities to third-party providers within or outside their jurisdiction must understand that they are responsible for the activities of these vendors and their strategic partners (fourth-party vendors) ( Berman, 2018 ). Fourth-party providers are individuals to whom third-party vendors outsource their activities. Some of these activities include mobile banking, bill payments, core processing, and other services. According to Berman (2018) , it is quintessential for organizations to identify high-risk vendors before outsourcing their services to these third-party providers. High-risk vendors or critical vendors are providers who are involved in activities that could have a detrimental impact on the business operations of an organization. Such business operations include information technology or payments services ( Berman, 2018 ).

Read the paper · More papers on PaperTik