The Weakest Link – Managing Supplier and Third Party Risk

Third party vendors and suppliers often have access to your network and your organisation’s confidential information. The best way to prevent a data breach is to have robust program to assess how your third parties are managing their risk and protecting your data. Organisations must have a clear understanding of the risks inherent in their business relationships with third parties. Continually assessing your vendors is the best way to manage your third party risk. How should you approach managing third party risk?

This presentation will cover the following topics:

·         Discuss the major failings of traditional third party risk management programs

·         Creating a supply chain awareness program

·         Creating a comprehensive catalogue of vendors and suppliers

·         Risk based segmentation of identified vendors and suppliers

·         Risk assessment and rules based due diligence activities

·         The key contractual clauses all contracts with third parties should contain and why

·         Methods for continuous monitoring

·         A model for a comprehensive process to effectively and efficiently manage third party risk


Third party actors often directly interact with sensitive data and business processes– organisations have been forced to adopt new controls, tactics, and technology to shield their enterprise from cyber threats.


CPE Hours

1.5 hours, based on the assumption you have signed the attendance sheet when attending


Registration and Admittance

•           Due to our sponsoring partner’s facilities, access requirements and for catering purposes, we request that you register for this event to ensure you are able to attend.

•           Registration to this session is open and free of charge to all current ISACA members.

•           A registration door prize will be drawn from the list of duly registered attendees.


  • 5.30pm – Registration and session sign-in – required to receive applicable CPE credits
  • 6:00pm – START – Welcome, Introductions, Agenda
  • 6:05pm – Monthly PD Session, Questions & Answers
  • 6:50pm – The Soapbox – Chapter Updates, Announcements and Issues of interest to members
  • 7:00pm – 15min Topic presentation
  • 7:15pm – Networking opportunity – drinks and finger food to be served
  • 8.00pm – Event Ends

About the Speaker

Wayne Tufek

Director, CyberRisk

Professional background

For over 20 years he has formulated pragmatic, business driven strategies to establish, execute and improve cyber risk management in ASX listed companies and some of Australia’s largest organisations across the public sector, Big 4, financial services, consumer products, education and retail sectors. Wayne is a member of Chartered Accountants Australia and New Zealand and holds the SABSA SCF, CISSP, CRISC, CISM, CISA, PCI QSA and ISO/IEC 27001 Lead Implementer qualifications. He is frequently asked to present at security conferences and events in Australia and internationally including the Australian Cyber Security Centre Conference, AusCERT, RSA APJ and CeBit.