Building a Third-Party Risk Management Program for NIST CSF and SOC 2 Type II Compliance

Between 30 and 45 percent of all enterprise data breaches now trace back to a third party. The average organization shares sensitive data with 583 external vendors. Yet most security programs still treat vendor risk as an afterthought — a questionnaire sent once at onboarding, filed, and never revisited. That gap is no longer acceptable, and regulators, auditors, and attackers all know it.

David Laurin

With a recent focus on Third-Party Risk Management (TPRM) and security monitoring, my commitment to data integrity is central to my role at New Era Technology. At the heart of my work lies a partnership with Mass Mutual where I conduct meticulous risk assessments to secure third-party vendor engagements and maintain regulatory compliance. My expertise extends to Office 365 administration, supporting my efforts in eDiscovery and data preservation for a Global Insurance Agency.

The strategic application of my skills as an IT Systems Engineer and Consultant empowers organizations to overcome complex technical challenges. Leading with a consultative approach, my contributions enhance business continuity and resilience. The success of our collaborative endeavors is grounded in a shared vision of fortifying data protection mechanisms and driving operational excellence within the IT landscape.

https://www.itmsmp-consult.com
Sign up to read this post
Join Now
Previous
Previous

How SMBs Can Select the Right Managed IT Services Provider

Next
Next

Cyber Readiness: Building a Resilient Organization in an Age of Constant Threat