{"id":14626,"date":"2026-09-04T09:39:07","date_gmt":"2026-09-04T07:39:07","guid":{"rendered":"https:\/\/www.inprosec.com\/?p=14626"},"modified":"2026-09-04T09:39:07","modified_gmt":"2026-09-04T07:39:07","slug":"third-party-risk-management-why-ongoing-oversight-matters","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/","title":{"rendered":"Third-Party Risk Management: Why Ongoing Oversight Matters"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Organizations increasingly rely on external providers to support critical business processes. Cloud services, technology providers, managed services, system integrators, software vendors, and other third parties may have access to sensitive information, connect to corporate environments, or support functions that are essential to business operations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This growing interdependence also expands the organization\u2019s risk exposure. A company may have strong security controls in place and still face significant risks through third parties that operate outside its direct control.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For this reason, <\/span><a href=\"https:\/\/www.inprosec.com\/en\/services\/information-security\/governance-and-strategy\/\"><b>third-party risk management<\/b><\/a><span style=\"font-weight: 400;\"> should be part of an organization\u2019s broader information security and risk management strategy rather than limited to a one-time assessment performed before a contract is signed.<\/span><\/p>\n<h2><b>Understanding the Scope of Third-Party Risk<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Third-party risk management has become an increasingly important part of cybersecurity and supply chain risk management in the United States.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In July 2026, the National Institute of Standards and Technology (NIST) finalized its <\/span><b>Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide<\/b><span style=\"font-weight: 400;\">, providing a practical approach for assessing potential ICT suppliers and supporting informed decisions about new acquisitions and existing systems. The guidance considers factors such as supplier provenance, resilience, foundational cybersecurity practices, and supply chain tiers.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">NIST&#8217;s broader Cybersecurity Supply Chain Risk Management guidance also emphasizes integrating supply chain risk into an organization&#8217;s overall risk management activities rather than treating it as a separate process.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This approach reflects a fundamental principle: <\/span><b>the security and resilience of critical third parties can directly affect the security and resilience of the organization itself.<\/b><\/p>\n<h2><b>Understanding the Organization&#8217;s Exposure<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The first step is understanding which third parties are part of the organization\u2019s ecosystem and what role they play.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Not every supplier represents the same level of risk. The potential impact may depend on the services provided, the information accessed, system connectivity, operational dependency, or the criticality of the business process supported by the provider.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Establishing a risk-based classification helps organizations <\/span><b>prioritize assessment and oversight efforts according to actual exposure<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">NIST&#8217;s due diligence guidance similarly emphasizes gathering relevant information about suppliers and products so that organizations can make informed, risk-based decisions before entering into supplier relationships or making technology acquisitions.<\/span><\/p>\n<h2><b>The Initial Assessment Is Only the Starting Point<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Third-party assessments can provide valuable insight into a supplier\u2019s security posture before a relationship is established or renewed. These assessments may cover policies and controls, certifications, technical safeguards, incident management, business continuity, and other security practices.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, an assessment represents a point in time.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A supplier relationship can change. Services may expand, access privileges may increase, technologies may change, or additional subcontractors may become involved. At the same time, the organization\u2019s own risk profile and business dependencies may evolve.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As a result, an initial assessment loses value if there is no process for <\/span><b>maintaining an up-to-date understanding of the third party and its associated risk<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">NIST&#8217;s recent due diligence guidance reinforces the importance of gathering and analyzing relevant information to support informed decisions about both new acquisitions and existing systems.<\/span><\/p>\n<h2><b>Moving Beyond Questionnaires<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">One of the challenges of third-party risk management is avoiding a process that becomes little more than a recurring questionnaire exercise.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">An effective program should establish:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which suppliers need to be assessed and at what level of depth.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which security requirements apply based on their criticality.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">How frequently each third party should be reviewed.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which changes or events should trigger a reassessment.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">How identified gaps and risks will be addressed.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which risks can be accepted and which require additional mitigation.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This turns assessment information into an input for <\/span><b>risk management and decision-making<\/b><span style=\"font-weight: 400;\">, rather than treating it as a documentation exercise.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">NIST&#8217;s supply chain risk management practices emphasize establishing defined processes, responsibilities, and risk management activities that can be integrated into the organization&#8217;s broader cybersecurity program.<\/span><\/p>\n<h2><b>Integrating Third-Party Risk into the Information Security Program<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Third-party risk is connected to multiple areas of information security, including risk management, business continuity, access control, information protection, compliance, and incident response.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For that reason, information gathered about suppliers should be connected to the organization&#8217;s broader risk management framework.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This can help identify critical dependencies, prioritize remediation efforts, and determine where additional security requirements or controls may be necessary.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It also supports a fundamental objective: <\/span><b>making supplier decisions based not only on operational or commercial considerations, but also on the security risk associated with the relationship.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NIST&#8217;s Cybersecurity Supply Chain Risk Management approach is designed to help organizations identify, assess, and manage cybersecurity risks throughout their supply chains as part of a broader enterprise risk management effort.<\/span><\/p>\n<h2><b>A Risk-Based Approach<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Managing third-party risk does not mean applying the same controls to every supplier.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">An effective program should be proportional to the criticality and exposure associated with each relationship. This allows organizations to focus resources on third parties that could have a greater impact on the confidentiality, integrity, or availability of information and business operations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The goal is therefore to move beyond a model based solely on assessment and establish a process that combines <\/span><b>identification, classification, assessment, and ongoing monitoring<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This approach helps organizations avoid both excessive controls for low-impact suppliers and insufficient oversight of providers that support critical business functions.<\/span><\/p>\n<h2><b>Risk Changes Over Time<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Third-party risk management should not be treated as an isolated security activity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As organizations expand their supplier ecosystems and increasingly rely on external services, understanding and managing those dependencies becomes an increasingly important part of cybersecurity and enterprise risk management.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">An assessment provides a snapshot. <\/span><b>A management process provides ongoing visibility and control.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">At Inprosec, we help organizations structure and improve their <\/span><a href=\"https:\/\/www.inprosec.com\/en\/services\/information-security\/governance-and-strategy\/\"><b>Vendor Risk Management<\/b><\/a><span style=\"font-weight: 400;\"> processes through supplier classification, security assessments, ongoing monitoring, and information security requirements tailored to each organization\u2019s context and risk exposure.<\/span><\/p>\n<h2><b>Sources<\/b><\/h2>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/1326\/final?utm_source=chatgpt.com\"><span style=\"font-weight: 400;\">NIST \u2013 Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.nist.gov\/publications\/cybersecurity-supply-chain-risk-management-practices-systems-and-organizations?utm_source=chatgpt.com\"><span style=\"font-weight: 400;\">NIST \u2013 Cybersecurity Supply Chain Risk Management Practices<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/csrc.nist.gov\/Projects\/cyber-supply-chain-risk-management\/publications?utm_source=chatgpt.com\"><span style=\"font-weight: 400;\">NIST \u2013 Cybersecurity Supply Chain Risk Management Publications<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/reducing-ict-supply-chain-risk-small-and-medium-sized-businesses-fact-sheet?utm_source=chatgpt.com\"><span style=\"font-weight: 400;\">CISA \u2013 Reducing ICT Supply Chain Risk for Small and Medium-Sized Businesses<\/span><\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Organizations increasingly rely on external providers to support critical business processes. Cloud services, technology providers, managed services, system integrators, software vendors, and other third parties may have access to sensitive information, connect to corporate environments, or support functions that are essential to business operations. This growing interdependence also expands the organization\u2019s risk exposure. A company&#8230;<\/p>\n","protected":false},"author":6,"featured_media":14630,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-14626","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Third-Party Risk Management: Why Ongoing Oversight Matters - Inprosec<\/title>\n<meta name=\"description\" content=\"ICT supply chain risk is a growing priority in the US. How to manage third-party risk with a proportional, risk-based and continuous approach.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Third-Party Risk Management: Why Ongoing Oversight Matters\" \/>\n<meta property=\"og:description\" content=\"ICT supply chain risk is a growing priority in the US. How to manage third-party risk with a proportional, risk-based and continuous approach.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-04T07:39:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"Third-Party Risk Management: Why Ongoing Oversight Matters\",\"datePublished\":\"2026-09-04T07:39:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/\"},\"wordCount\":983,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/1.jpg\",\"articleSection\":[\"General\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/\",\"name\":\"Third-Party Risk Management: Why Ongoing Oversight Matters - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/1.jpg\",\"datePublished\":\"2026-09-04T07:39:07+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"description\":\"ICT supply chain risk is a growing priority in the US. How to manage third-party risk with a proportional, risk-based and continuous approach.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/1.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/third-party-risk-management-why-ongoing-oversight-matters\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Third-Party Risk Management: Why Ongoing Oversight Matters\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Third-Party Risk Management: Why Ongoing Oversight Matters - Inprosec","description":"ICT supply chain risk is a growing priority in the US. How to manage third-party risk with a proportional, risk-based and continuous approach.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/","og_locale":"en_US","og_type":"article","og_title":"Third-Party Risk Management: Why Ongoing Oversight Matters","og_description":"ICT supply chain risk is a growing priority in the US. How to manage third-party risk with a proportional, risk-based and continuous approach.","og_url":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/","og_site_name":"Inprosec","article_published_time":"2026-09-04T07:39:07+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/1.jpg","type":"image\/jpeg"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"Third-Party Risk Management: Why Ongoing Oversight Matters","datePublished":"2026-09-04T07:39:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/"},"wordCount":983,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/1.jpg","articleSection":["General"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/","url":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/","name":"Third-Party Risk Management: Why Ongoing Oversight Matters - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/1.jpg","datePublished":"2026-09-04T07:39:07+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"description":"ICT supply chain risk is a growing priority in the US. How to manage third-party risk with a proportional, risk-based and continuous approach.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/1.jpg","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/1.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/third-party-risk-management-why-ongoing-oversight-matters\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"Third-Party Risk Management: Why Ongoing Oversight Matters"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=14626"}],"version-history":[{"count":1,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14626\/revisions"}],"predecessor-version":[{"id":14628,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14626\/revisions\/14628"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/14630"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=14626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=14626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=14626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}