How often does procurement include cyber risk assessment requirements in their engagement requests?
Always20%
Often40%
Sometimes24%
Rarely12%
Never1%
Not sure
427 PARTICIPANTS
3.1k views1 Comment
Sort by:
Content you might like
How does your cyber compliance team stay informed about new and changing regulations impacting your organization's compliance? Additionally, how are cyber compliance teams tracking, measuring and reporting on internal compliance?
Strongly agree10%
Agree57%
Neutral11%
Disagree13%
Strongly disagree6%
How are you currently leveraging your cyber-risk quantification methodologies at your organization?
Prioritizing cyber risks43%
Communicating to risk owners64%
Communicating to C-Suite56%
Communicating to Board24%
Aligning cyber risks with other risk practices15%
It depends on the size of the business. In my experience, most of the publicly listed companies' procurement team will have this requirement as part of due diligence of vendor onboarding process.
For private companies, it depends on the size and agility of the business that matters the most.
Another driver for this requirement comes from regulatory compliance side and that too depends on which sector the company is operating.