About this course
This course explains how an organization’s security depends on the suppliers, vendors and partners it works with, and where that risk comes in: the software and cloud services you rely on, the contractors with access to your systems, and the partners you share data with. It covers the security questions to ask a vendor before you sign, how to share data and access safely, the warning signs of a supplier breach, a fake vendor or a hijacked account, and what to do when a supplier has an incident. It’s written for every employee who works with third parties, in plain language, with scenarios from everyday procurement and partnership work.
Many of the largest breaches now start at a supplier: a compromised software update, a contractor’s stolen credentials, or a partner who kept more data than they needed. The people who choose vendors, share files with them and answer their emails are rarely security specialists, so questions go unasked, access is granted and never removed, and a supplier’s incident reaches the organization before anyone knows to react. Customers, insurers and rules such as NIS2 now ask organizations to show how they manage this risk.
- Scenarios and a knowledge check
- Web and mobile app, including offline