Resources

[Blog](/blog)[Events](/events)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Third-Party Risk Management

Articles, news, and research on third-party risk management.

##### Categories

[View all](/blog)

[Attack Surface Management](/category/attack-surface-management)

[Company news](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cyber Risk Posture Management](/category/cyber-risk-posture-management)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risk Automations](/category/risk-automations)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Trust Exchange](/category/trust-exchange)

[Vendor Risk Management](/category/vendor-risk-management)

[UpGuard](/blog/upguard-named-leader-in-idc-marketscape)

[The Evidence Is In: UpGuard Named a Leader in the IDC MarketScape for Worldwide Third-Party Risk Management](/blog/upguard-named-leader-in-idc-marketscape)

## [The Evidence Is In: UpGuard Named a Leader in the IDC MarketScape for Worldwide Third-Party Risk Management](/blog/upguard-named-leader-in-idc-marketscape)

UpGuard has been named a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Services 2026 Vendor Assessment. Find out why.

[Cassy van Eeden](/team/cassy-van-eeden)

September 22, 2026

### Third-Party Risk Management

Third-Party Risk Management

#### The Evidence Is In: UpGuard Named a Leader in the IDC MarketScape for Worldwide Third-Party Risk Management

UpGuard has been named a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Services 2026 Vendor Assessment. Find out why.

[Read more](/blog/upguard-named-leader-in-idc-marketscape)

[Cassy van Eeden](/team/cassy-van-eeden)

September 22, 2026

Third-Party Risk Management

#### We Researched Four AI Evidence Analysis Tools for TPRM. Here’s What We Found.

We researched four AI evidence-parsing tools against four criteria that security teams often overlook. None nailed all four.

[Read more](/blog/ai-evidence-analysis-tools-for-tprm)

[Cassy van Eeden](/team/cassy-van-eeden)

September 21, 2026

Third-Party Risk Management

#### How to Map Vendor Tiers to Inherent Risk

Map vendors to inherent risk using five observable criteria — data access, continuity, regulatory, strategic, and security.

[Read more](/blog/vendor-tiering-mapping-to-inherent-risk)

[Cassy van Eeden](/team/cassy-van-eeden)

September 20, 2026

Third-Party Risk Management

#### The Best Vendor Performance Management Tools and Software (2026)

Compare the best vendor performance management tools for 2026. SLAs, KPIs, and how performance data connects to vendor security monitoring.

[Read more](/blog/vendor-performance-management-tools)

[Cassy van Eeden](/team/cassy-van-eeden)

September 20, 2026

Third-Party Risk Management

#### The 12 Best Third-Party Risk Management Software Solutions (2026)

Compare the 12 best TPRM tools of 2026, including UpGuard, SecurityScorecard, Bitsight, OneTrust and Panorays.

[Read more](/blog/best-third-party-risk-management-software-solutions)

[Cassy van Eeden](/team/cassy-van-eeden)

September 22, 2026

Third-Party Risk Management

#### Is a SOC 2 Report Enough to Assess a Cloud Vendor?

A SOC 2 report answers some questions about a cloud vendor. It was never built to answer the cloud-specific ones.

[Read more](/blog/soc-2-cloud-vendors)

[Cassy van Eeden](/team/cassy-van-eeden)

August 25, 2026

Third-Party Risk Management

#### The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment

A completed CAIQ isn't verified evidence. See what manual CCM mapping actually costs a team, and how AI-assisted review changes it.

[Read more](/blog/manual-vs-ai-assisted-vendor-assessment)

[Cassy van Eeden](/team/cassy-van-eeden)

August 13, 2026

Third-Party Risk Management

#### The Vendor Assurance Confidence Gap: Why It’s Widest With Your Most Critical Vendors

Vendor assurance efforts are rising while confidence in them is falling. This gap is widest with the vendors that matter most. Here’s why.

[Read more](/blog/vendor-assurance-confidence-gap)

[Cassy van Eeden](/team/cassy-van-eeden)

August 25, 2026

Third-Party Risk Management

#### Best TPRM Software for Higher Education: What to Look For

Learn how to evaluate higher education TPRM software, including HECVAT workflows, vendor monitoring, remediation, audit readiness, and reporting.

[Read more](/blog/best-tprm-software-higher-education)

[Cassy van Eeden](/team/cassy-van-eeden)

August 31, 2026

Third-Party Risk Management

#### Higher Education TPRM in 2026: New Research Maps the Vendor Visibility Gap

Explore UpGuard’s latest research into higher education third-party risk, including supplier concentration and systemic vendor exposure.

[Read more](/blog/higher-education-tprm-2026)

[Cassy van Eeden](/team/cassy-van-eeden)

August 10, 2026

Third-Party Risk Management

#### Cyber TPRM vs Compliance TPRM: Which is right for you?

Cyber TPRM and compliance TPRM answer different questions and serve different buyers. Learn how to tell them apart and decide which is best for you.

[Read more](/blog/cyber-tprm-vs-compliance-tprm)

[Edward Kost](/team/edward-kost)

April 16, 2026

Third-Party Risk Management

#### 6 Ways to Make Your Risk Assessments Land With Stakeholders

A misunderstood report may as well be blank. Here are 6 ways to communicate findings so they land with any stakeholder, from InfoSec to the C-suite.

[Read more](/blog/make-risk-assessments-land-with-stakeholders)

[Shane Moosa](/team/shane-moosa)

October 3, 2025

Third-Party Risk Management

#### TPCRM Framework: Building Digital Trust for Modern Enterprises

TPCRM fosters digital trust in modern ecosystems. Learn how to manage vendor risks, secure data, and ensure compliance in one framework.

[Read more](/blog/tpcrm)

[Edward Kost](/team/edward-kost)

June 15, 2025

Third-Party Risk Management

#### 47% of Breaches Involve Vendors: Is Your TPRM Ready?

Traditional TPRM is struggling as vendor breaches hit 47%. Uncover insights from the 2025 Ponemon Report to learn how you can future-proof your TPRM.

[Read more](/blog/the-state-of-third-party-access-in-cybersecurity)

[Edward Kost](/team/edward-kost)

May 27, 2025

Third-Party Risk Management

#### What to Do When a Vendor Fails a Security Audit

UpGuard's playbook for failed security playbooks: dissect findings, assess exposure, request a written CAP, and remediate or terminate.

[Read more](/blog/failed-vendor-audits)

[Cassy van Eeden](/team/cassy-van-eeden)

September 23, 2026

Third-Party Risk Management

#### The Risk of Third-Party AI Trained on User Data

Analyzing privacy policies can tell us which companies are using AI and training their models with your data.

[Read more](/blog/third-party-risk-ai-models-trained-on-user-data)

[Greg Pollock](/team/greg-pollock)

August 25, 2026

1 / 10

[Next](?8a72e3cf_page=2)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
