<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom"><title>Third Party Current</title><id>https://thirdpartycurrent.com/</id><updated>2026-07-18T15:00:00.000Z</updated><link href="https://thirdpartycurrent.com/feed.xml" rel="self"/><entry><title>UpGuard release notes show fourth-party data moving into operational workflows</title><id>https://thirdpartycurrent.com/news/upguard-adds-fourth-party-api-and-remediation-controls/</id><link href="https://thirdpartycurrent.com/news/upguard-adds-fourth-party-api-and-remediation-controls/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-07-15T18:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>API availability and questionnaire-remediation changes suggest that downstream visibility is being judged less as a map and more as data that must enter governed work.</summary></entry><entry><title>ISO supplier-security standard enters systematic review</title><id>https://thirdpartycurrent.com/news/iso-27036-enters-systematic-review/</id><link href="https://thirdpartycurrent.com/news/iso-27036-enters-systematic-review/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2026-07-15T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.</summary></entry><entry><title>NIST turns supplier due diligence into a minimum viable practice</title><id>https://thirdpartycurrent.com/news/nist-finalizes-c-scrm-due-diligence-guide/</id><link href="https://thirdpartycurrent.com/news/nist-finalizes-c-scrm-due-diligence-guide/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-07-08T15:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The finalized C-SCRM quick-start guide gives organizations a clearer floor for evaluating technology suppliers before risk teams build a larger program around it.</summary></entry><entry><title>UpGuard study maps vendor breach exposure across higher education</title><id>https://thirdpartycurrent.com/news/upguard-higher-education-vendor-breach-study/</id><link href="https://thirdpartycurrent.com/news/upguard-higher-education-vendor-breach-study/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-07-01T13:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The vendor-funded analysis shows the value—and the limits—of using relationship-scale datasets to understand concentration and downstream cyber exposure.</summary></entry><entry><title>CPS 230 puts service-provider resilience into force in Australia</title><id>https://thirdpartycurrent.com/news/apra-cps-230-enters-force/</id><link href="https://thirdpartycurrent.com/news/apra-cps-230-enters-force/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2026-07-01T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.</summary></entry><entry><title>NIST pulls supply-chain risk into the system planning record</title><id>https://thirdpartycurrent.com/news/nist-sp-800-18r2-integrates-supply-chain-planning/</id><link href="https://thirdpartycurrent.com/news/nist-sp-800-18r2-integrates-supply-chain-planning/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-06-30T16:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.</summary></entry><entry><title>OneTrust incident update puts third-party OAuth access under scrutiny</title><id>https://thirdpartycurrent.com/news/onetrust-klue-salesforce-incident-third-party-oauth/</id><link href="https://thirdpartycurrent.com/news/onetrust-klue-salesforce-incident-third-party-oauth/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-06-24T19:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>A compromised third-party integration involving Klue and Salesforce shows why application connections need their own inventory, ownership, and revocation playbook.</summary></entry><entry><title>SecurityScorecard adds Driftnet as cyber ratings platforms widen their data layer</title><id>https://thirdpartycurrent.com/news/securityscorecard-acquires-driftnet/</id><link href="https://thirdpartycurrent.com/news/securityscorecard-acquires-driftnet/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-05-14T14:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The acquisition extends a broader contest over who can map external assets, dependencies, and threat signals into a third-party decision workflow.</summary></entry><entry><title>APRA finalizes targeted CPS 230 amendments and a revised service-provider register</title><id>https://thirdpartycurrent.com/news/apra-finalizes-cps-230-amendments/</id><link href="https://thirdpartycurrent.com/news/apra-finalizes-cps-230-amendments/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2026-04-30T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The April package adds limited contractual exemptions, clarifies their management, and updates the material service-provider register ahead of the July commencement date.</summary></entry><entry><title>Sayari and Source Intelligence connect entity risk to individual parts</title><id>https://thirdpartycurrent.com/news/sayari-source-intelligence-integration/</id><link href="https://thirdpartycurrent.com/news/sayari-source-intelligence-integration/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2026-04-20T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The announced integration joins corporate ownership and trade intelligence with component- and material-level sourcing data, pushing third-party analysis deeper into product-specific exposure.</summary></entry><entry><title>PRA finalizes material third-party reporting for 2027 implementation</title><id>https://thirdpartycurrent.com/news/pra-finalizes-third-party-reporting-policy/</id><link href="https://thirdpartycurrent.com/news/pra-finalizes-third-party-reporting-policy/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2026-03-18T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The UK policy expands reporting beyond outsourcing, separates notification from register templates, and gives firms a year to govern the data behind material third-party arrangements.</summary></entry><entry><title>ProcessUnity launches a controls-driven risk index</title><id>https://thirdpartycurrent.com/news/processunity-launches-risk-index/</id><link href="https://thirdpartycurrent.com/news/processunity-launches-risk-index/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-03-12T14:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The new rating approach reflects a market shift toward combining external signals with evidence from the organization's own assessment and control process.</summary></entry><entry><title>Assessment study finds response speed lagging behind third-party incidents</title><id>https://thirdpartycurrent.com/news/processunity-ponemon-assessment-maturity-study/</id><link href="https://thirdpartycurrent.com/news/processunity-ponemon-assessment-maturity-study/"/><updated>2026-07-18T15:00:00.000Z</updated><published>2026-01-27T15:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>ProcessUnity and Ponemon Institute report a gap between incident volume and assessment response, but buyers should separate the study's directional signal from a universal benchmark.</summary></entry><entry><title>Censinet opens a healthcare cyber and AI governance benchmark</title><id>https://thirdpartycurrent.com/news/censinet-launches-2026-healthcare-benchmark-study/</id><link href="https://thirdpartycurrent.com/news/censinet-launches-2026-healthcare-benchmark-study/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2025-09-09T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The 2026 study brings healthcare organizations, industry groups, and several control frameworks into one benchmarking program, creating useful peer context with important participation limits.</summary></entry><entry><title>CORL brings RiskRecon monitoring into its healthcare TPRM service</title><id>https://thirdpartycurrent.com/news/corl-riskrecon-healthcare-partnership/</id><link href="https://thirdpartycurrent.com/news/corl-riskrecon-healthcare-partnership/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2025-08-20T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The partnership combines outside-in cyber signals with healthcare-specific assessment and advisory work, illustrating how managed TPRM providers are packaging intelligence into response workflows.</summary></entry><entry><title>Sayari acquisition joins commercial network intelligence with TPRM orchestration</title><id>https://thirdpartycurrent.com/news/sayari-acquires-mirato/</id><link href="https://thirdpartycurrent.com/news/sayari-acquires-mirato/"/><updated>2026-07-19T15:00:00.000Z</updated><published>2025-07-28T12:00:00.000Z</published><author><name>Third Party Current Research Desk</name></author><summary>The Mirato deal connects corporate and trade data with AI-assisted assessment workflow, creating a broader risk-intelligence operating model whose post-acquisition packaging still requires scrutiny.</summary></entry></feed>