Third-Party Risk Management (TPRM) is the discipline of identifying, assessing, and monitoring the risks that suppliers, service providers, and partners introduce into an organization throughout the entire relationship. In the cyber domain, TPRM recognizes that a third party's security posture becomes part of the exposure of the very organization that contracts it.
An organization's security boundary no longer coincides with the perimeter it controls directly. Cloud providers, payment processors, integrators, software-as-a-service platforms, and support providers maintain access to data, systems, and credentials. Each of these relationships widens the attack surface beyond the organization's own assets. Third-party risk management is the structured response to this reality, and in Brazil it has ceased to be a recommended practice to become a regulatory requirement.
Why the Attack Surface Includes the Supplier Chain
An adversary seeks the path of least resistance. When an organization's direct controls are robust, the compromise vector frequently shifts to a supplier with privileged access and an inferior security posture. The compromise of a single provider with connectivity to multiple customers can propagate across its entire portfolio, which gives these relationships a concentration risk.
This dynamic has three consequences for exposure management:
- Granted access is an extension of privilege. A supplier with integration credentials operates, in practice, inside the contracting party's environment. Its security posture governs part of the contracting party's risk.
- Visibility is asymmetric. The organization knows its own assets well and knows the supplier's poorly. This asymmetry is precisely what continuous TPRM sets out to reduce.
- Accountability remains with the contracting party. Before the regulator and before the data subject, the organization that did the contracting answers for the effects of a failure originating in the supplier, which makes diligence over third parties a non-delegable obligation.
Monitoring the external posture of suppliers is, therefore, an integral part of any attack surface management (ASM) program. The surface relevant to the organization's risk comprises the exposed assets of its critical suppliers to the extent of the access and integration they maintain.
Brazilian Regulatory Requirements
The Financial Sector: The Cybersecurity Regulation of the CMN and the BCB
The Brazilian cybersecurity framework for the financial sector establishes explicit requirements regarding the contracting of data processing and storage services and of cloud computing, including the institution's responsibility for the diligence of its providers. CMN Resolution No. 4,893/2021 governs the cybersecurity policy of institutions authorized to operate by the Central Bank and the requirements for contracting these services. Joint resolutions and related regulations of the Central Bank extend equivalent principles to other regulated segments, such as payment institutions.
The elements that this framework makes enforceable, with respect to third parties, consistently include:
- Verification, prior to contracting, of the provider's capacity to comply with the legislation and to ensure the confidentiality, integrity, and availability of the data and systems.
- Contractual provision for the institution's and the regulator's access to the relevant information and documentation.
- Monitoring and management of the service provided throughout the entire term of the contract.
- Consideration of the concentration risk in relevant providers.
The joint reading of these requirements points to an expectation that goes beyond the assessment at the moment of contracting. The duty to monitor the service throughout the relationship implies continuous monitoring of the provider's posture, beyond a point-of-entry verification. It is advisable to consult the current text of the resolutions applicable to the specific segment, given that the framework is updated periodically.
LGPD: Processors, Sub-Processors, and Accountability
The General Data Protection Law (Law No. 13,709/2018) structures the processing of personal data around the figures of the controller — the party that decides on the processing — and the processor — the party that carries out the processing on behalf of the controller. When a processor subcontracts part of the activity, the figure of the sub-processor arises, and the chain of responsibility extends.
Two points of the law are decisive for TPRM:
Accountability is joint and several in relevant scenarios. LGPD provides that the processor is jointly and severally liable for damages caused when it fails to comply with the obligations of the legislation or when it has not followed the lawful instructions of the controller. The controller, in turn, answers for the processing decisions. The practical consequence is that the selection and supervision of a processor form part of the controller's duty of diligence.
Security is an obligation of both. The law imposes on the processing agents the adoption of security measures capable of protecting personal data. This obligation falls on both processor and controller, which makes the processor's security posture a legitimate and necessary object of verification on the part of the party that contracts it.
The National Data Protection Authority enforces compliance with these obligations and holds sanctioning powers. The demonstration of diligence over the chain of processors is, thus, an element of compliance that the organization needs to be able to evidence.
Point-in-Time Assessment and Continuous Monitoring
The consolidated practice of third-party risk management was born supported by questionnaires. The supplier answers a security form at the contracting phase, the organization files the responses, and the relationship proceeds. This approach presents structural limitations that render it insufficient in the face of current requirements.
The security questionnaire captures a self-declaration referring to an instant. It describes what the supplier states about its posture at the moment it responded. The effective security posture, however, varies continuously: certificates expire, services are published with inadequate configuration, assets are exposed by mistake, credentials leak. A questionnaire answered at the start of the contract says nothing about the state of the supplier six months later.
Continuous monitoring of the supplier's exposure observes the third party's external posture on a recurring basis, from its publicly observable surface, without depending on self-declaration. This observation evidences the current state of the supplier's posture and signals degradations as they occur. The two approaches are complementary and fulfill distinct functions:
- Point-in-time questionnaire. Establishes the contractual understanding, documents commitments, and covers internal aspects not externally observable, such as governance policies and processes.
- Continuous monitoring. Verifies, independently and over time, the alignment of the supplier's observable posture with what it declared, and detects the introduction of new exposures.
The combination of the two meets the regulatory expectation of monitoring throughout the term of the contract and sustains the demonstration of diligence both before the Central Bank and before the ANPD. An organization that merely files questionnaires holds evidence of compliance at the moment of contracting; an organization that monitors continuously holds evidence of compliance at any moment it may be required.
Structuring a Defensible TPRM Program
A third-party risk management program equal to the Brazilian framework is organized around a few operational principles:
- Classification by criticality. Not every supplier introduces the same risk. The intensity of diligence and monitoring should be proportional to the access, the volume and sensitivity of the data, and the relevance of the service to business continuity.
- Documented prior diligence. The verification of the provider's capacity before contracting should be recorded on an auditable basis, with contractual provision for the information access rights required by the regulation.
- Continuous monitoring of external posture. The monitoring of the observable surface of critical suppliers throughout the term of the contract materializes the duty to manage the service provided.
- Route for handling degradations. The detection of an exposure at a supplier needs to trigger a defined flow of communication and correction, with timelines proportional to criticality.
CSURFACE's third-party risk solution was designed to sustain this program, continuously observing the external posture of suppliers and integrating that view into the attack surface management of the contracting organization. The objective is to allow the organization to maintain, at any moment, current evidence of the diligence exercised over its third-party chain — the standard that BACEN and LGPD, each in its own domain, have made enforceable.
Frequently Asked Questions
What does Brazilian legislation require in relation to third-party risk?
In the financial sector, the cybersecurity framework of the CMN and the Central Bank requires prior verification of the provider's capacity, contractual provision for access to information, and monitoring of the service throughout the term of the contract. LGPD, applicable to any sector, holds both controller and processor accountable for the security of personal data and provides for joint and several liability in cases of non-compliance, which makes diligence over processors part of compliance.
Is a security questionnaire sufficient to meet the requirements?
The questionnaire documents commitments and covers internal aspects that escape external observation, although it captures a self-declaration referring to a single instant. The regulatory expectation of monitoring the service throughout the contract points to the need for continuous monitoring of the supplier's posture, which independently and recurrently verifies the current state of its exposure.
What distinguishes continuous monitoring from point-in-time assessment?
The point-in-time assessment describes what the supplier declares at a specific moment. Continuous monitoring observes the supplier's external posture on a recurring and independent basis, evidencing the current state of its surface and signaling new exposures as they arise. The two approaches are complementary.
How does third-party risk relate to the attack surface?
Suppliers with access to data and systems extend the organization's attack surface. Their exposed assets become part of the contracting party's risk to the extent of the access they maintain. For this reason, third-party monitoring is part of attack surface management. Consult the glossary for the technical terms cited.