THIRD PARTYCURRENT
Newsroom

Latest third-party risk news

Reporting and analysis on the standards, companies, products, incidents, and research changing third-party risk decisions.

Product Intelligence

UpGuard release notes show fourth-party data moving into operational workflows

API availability and questionnaire-remediation changes suggest that downstream visibility is being judged less as a map and more as data that must enter governed work.

Standards Watch

ISO supplier-security standard enters systematic review

ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.

Regulatory Analysis

CPS 230 puts service-provider resilience into force in Australia

APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.

Analysis

NIST pulls supply-chain risk into the system planning record

SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.

Product Analysis

ProcessUnity launches a controls-driven risk index

The new rating approach reflects a market shift toward combining external signals with evidence from the organization's own assessment and control process.

Research Review

Censinet opens a healthcare cyber and AI governance benchmark

The 2026 study brings healthcare organizations, industry groups, and several control frameworks into one benchmarking program, creating useful peer context with important participation limits.

Partnership Analysis

CORL brings RiskRecon monitoring into its healthcare TPRM service

The partnership combines outside-in cyber signals with healthcare-specific assessment and advisory work, illustrating how managed TPRM providers are packaging intelligence into response workflows.