By Michael Hiskey
As organizations become increasingly dependent on third-party technology providers, AI platforms, cloud services, and digital ecosystems, trust has evolved from an abstract concept into a measurable business asset. That was the central theme of discussion during the HITRUST CxO Security Forum at the 3M Open, where senior cybersecurity, technology, risk, compliance, and business leaders gathered for an open, peer-driven conversation about the future of third-party risk management.
Rather than focusing solely on compliance frameworks or security questionnaires, the discussion explored how organizations can make better business decisions by understanding operational dependencies, validating trust through credible assurance, and communicating cyber risk in language executives and boards can act upon.
The conversation also provided an early look at emerging HITRUST capabilities designed to help organizations translate existing assurance evidence into meaningful risk signals, financial impact estimates, and more practical governance decisions.
One of the strongest themes throughout the discussion was that trust has become a competitive differentiator.
Organizations are increasingly judged not only by the products and services they provide, but by their ability to demonstrate resilience, safeguard information, and manage an increasingly complex ecosystem of partners and suppliers.
As one participant challenged the group:
“If we truly viewed trust as one of our organization’s most valuable strategic assets, what would we do differently?”
That question shifted the conversation away from regulatory checklists toward business outcomes. Companies that can credibly demonstrate sound governance and validated security practices are often better positioned to win new business, strengthen customer confidence, and differentiate themselves in competitive markets.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!
Technology alone cannot solve third-party risk.
Forum participants consistently emphasized that effective programs begin with governance: clearly defined ownership, decision-making authority, acceptable risk thresholds, and escalation processes.
Organizations also need to recognize that not every vendor represents the same type of risk. A cloud infrastructure provider, professional services firm, AI platform, payment processor, and facilities contractor each create different operational and security challenges.
Without governance, even the most sophisticated assessment platform simply automates inconsistency.
The days when procurement and information security controlled every vendor relationship are largely over.
Today, business units, marketing teams, software developers, finance departments, and individual employees can introduce new technologies with little warning. Shadow IT has expanded into shadow AI, making vendor oversight even more complex.
Because of this reality, successful organizations design risk management programs that business leaders can actually use. Processes that are slow, overly complex, or difficult to navigate often encourage employees to bypass them altogether.
The most effective security teams position themselves as trusted business partners who help accelerate informed decisions rather than simply acting as gatekeepers.
Historically, many organizations classified vendors primarily according to the volume or sensitivity of data they processed.
While data protection remains essential, today’s risk landscape is significantly broader.
A vendor may present substantial organizational risk because it:
Executives increasingly want to understand not simply whether a vendor could experience a cyber incident, but what business consequences would follow if that vendor became unavailable.
Participants acknowledged a simple reality: no certification, assessment, or questionnaire can guarantee that a third party will never experience a breach or disruption.
The more important question becomes: How resilient is the organization when that disruption occurs?
That means understanding operational dependencies, mapping data flows, identifying recovery alternatives, and evaluating the potential business impact if a critical supplier fails.
Organizations that plan for resilience—not just prevention—are far better positioned to maintain operations during inevitable disruptions.
Many participants expressed frustration with lengthy, one-size-fits-all vendor questionnaires that generate large volumes of information but relatively little insight.
Meaningful assurance should reflect the specific relationship being evaluated.
A software developer should not undergo the same assessment as a consulting firm. Likewise, an AI platform presents different governance considerations than a payroll processor or managed service provider.
The objective should be improving decision quality—not simply collecting more documentation.
Another recurring theme involved the difference between claims and independently validated evidence.
Self-attestations, readiness assessments, security questionnaires, certifications, and independent audits all provide different levels of confidence.
Equally important is understanding scope.
An assessment covering one business division or public-facing website may provide very little assurance regarding the specific service a customer intends to purchase.
Organizations increasingly need to evaluate both the credibility of the evidence and whether it accurately reflects the product or environment on which they depend.
Security teams are drowning in information.
External ratings, continuous monitoring alerts, certifications, questionnaires, penetration test summaries, and audit reports continue to multiply. Unfortunately, more data has not necessarily produced greater clarity.
An emerging opportunity lies in transforming multiple forms of assurance into consistent, comparable residual-risk signals that account for the quality and credibility of each source.
Rather than performing exhaustive reviews on every vendor, organizations can focus resources where meaningful risk actually exists.
Executives and directors increasingly expect cybersecurity discussions to focus on business outcomes rather than technical controls.
Effective reporting should answer questions such as:
When cyber risk is expressed in operational and financial terms, governance becomes significantly more effective.
The discussion also explored limitations within traditional cyber insurance.
Although vendors often maintain significant insurance coverage, those policies may ultimately be shared across hundreds or even thousands of affected customers following a widespread incident.
Emerging approaches could eventually provide more targeted coverage tied directly to individual vendor relationships, offering organizations additional options for transferring defined portions of third-party risk.
The conversation concluded with an important reminder for vendors themselves.
Strong assurance is not merely about satisfying customer requirements.
Organizations that invest in independently validated security programs can shorten procurement cycles, reduce repetitive assessments, strengthen customer confidence, and expand into highly regulated industries more efficiently.
In today’s marketplace, trust has become a genuine business differentiator.
Artificial intelligence appeared throughout nearly every discussion.
AI offers tremendous opportunities to streamline assessments, analyze documentation, identify inconsistencies, and help organizations manage increasingly complex vendor ecosystems.
At the same time, AI introduces new governance challenges. Organizations often have limited visibility into how vendors are using AI, what data may be exposed to models, how autonomous agents are authenticated, or which downstream providers are involved.
As AI adoption accelerates, vendor governance must evolve beyond annual questionnaires to become a continuous process supported by ongoing assurance and monitoring.
Participants identified several immediate actions organizations can take to strengthen third-party risk programs:
The future of third-party risk management will not be defined by longer questionnaires or larger collections of documentation.
Instead, successful organizations will distinguish themselves through stronger governance, better evidence, greater visibility into operational dependencies, and the ability to translate cybersecurity into business decisions.
Trust is no longer simply a security objective—it is a strategic asset that must be earned, validated, and continuously maintained.
Organizations that can measure, communicate, and operationalize trust will be better equipped not only to reduce risk, but also to strengthen resilience, accelerate business growth, and compete with greater confidence.
Special thanks to the HITRUST leadership team—industry veteran CISO Myrna Soto, CIO Jeremy Huval, and CEO Gregory Webb—for moderating the executive roundtable and sharing their strategic perspectives on the future of trust, assurance, and third-party risk management.
We also thank A-LIGN for supporting the Forum, with guidance from Marc Solomon and Jessica Brown, CMP, whose contributions helped make this executive discussion possible.
I welcome your input on this article… please do that via the summary LinkedIn post on this same topic!