Third Party Cyber Risk Management for Procurement Professionals Training Course
| Course code | SD-CS-051 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Procurement teams increasingly make award, renewal and sourcing decisions that introduce cyber exposure long before a supplier connects to systems or handles data. Security questionnaires, supplier assurances and contract clauses are often treated as administrative steps, leaving procurement professionals unable to distinguish a material control gap from an acceptable exception. This course equips participants to challenge supplier evidence, align cyber requirements to the purchase being made, and document risk-based decisions that can withstand review by information security, legal, audit and senior management.
Participants learn how to segment suppliers by inherent cyber risk; define proportionate due-diligence requirements; interpret responses to security questionnaires; evaluate evidence such as ISO 27001 certificates, SOC 2 reports, penetration-test summaries and incident-response procedures; and score findings using a repeatable risk methodology. The course covers security requirements in RFPs, supplier selection criteria, data-processing and subcontractor controls, remediation plans, contractual obligations, monitoring triggers and offboarding considerations. Participants practise converting technical cyber concerns into commercial requirements, approval papers and supplier negotiation positions.
Teaching combines instructor-led analysis with procurement-led casework, supplier-document reviews, scoring workshops and contract-clause exercises. Working in teams, participants assess a simulated high-risk supplier for a cloud-enabled procurement, identify evidence gaps, build a risk register and agree a treatment plan with escalation thresholds. Each participant leaves with a reusable third-party cyber-risk assessment pack containing a supplier segmentation model, due-diligence checklist, scoring matrix, issue log, contract requirements schedule and 90-day implementation plan.
The course is designed for experienced procurement, sourcing, vendor-management and contract-management professionals who work with IT, data-processing, cloud, operational technology or business-critical suppliers. It is equally valuable for procurement leaders seeking a consistent, defensible approach to cyber-risk decisions across categories and regions.
Course objectives
By the end of this course, participants will be able to:
- Segment suppliers using an inherent-risk model based on data access, system connectivity, service criticality and subcontracting exposure
- Draft cyber-security requirements for RFPs, supplier questionnaires and evaluation scorecards
- Interpret ISO 27001 certificates, SOC 2 reports, penetration-test summaries and control evidence for procurement decisions
- Score supplier control gaps using likelihood, impact, residual-risk and risk-acceptance criteria
- Build a third-party cyber-risk register with owners, remediation actions, deadlines and escalation thresholds
- Negotiate contractual controls covering incident notification, audit rights, data handling, subcontractors and exit support
- Create proportionate supplier remediation plans and monitor closure through governance checkpoints
- Present a risk-based supplier award or renewal recommendation to security, legal and executive stakeholders
Benefits of attending
For you
- Gain the confidence to challenge vague supplier security claims without needing to be a cyber-security specialist
- Build a portfolio-ready third-party risk assessment pack that can be adapted for live procurement categories
- Strengthen credibility with information security and legal teams by using their evidence and risk language accurately
- Make defensible award and renewal recommendations where commercial value must be balanced against residual cyber risk
- Prepare for senior procurement, supplier-risk and technology-sourcing roles with accountability for critical vendors
For your organisation
- Introduce consistent cyber-risk segmentation before suppliers enter costly tender, award or onboarding stages
- Reduce reliance on blanket questionnaires by matching due diligence effort to data, connectivity and service criticality
- Improve supplier selection decisions through evidence-based scoring rather than unverified security assertions
- Create stronger contractual leverage for incident reporting, remediation, subcontractor control and audit access
- Provide audit-ready records of accepted risks, mitigation owners, approval routes and supplier follow-up actions
Target competencies
Who should attend
- Procurement Managers — who set sourcing controls and approve supplier award recommendations
- Strategic Sourcing Specialists — who run RFPs for technology, cloud, data and business-critical services
- Vendor Management Professionals — who oversee supplier performance, renewals and remediation commitments
- Contract Managers — who negotiate enforceable security, data-protection and audit provisions
- Category Managers — who buy complex services and need proportionate cyber due diligence by spend category
- Procurement Risk and Governance Leads — who design assurance workflows and escalation routes across procurement
Requirements and prerequisites
Participants should have practical experience of sourcing, supplier onboarding, tender evaluation, contract management or vendor governance. They should understand core procurement concepts such as RFPs, evaluation criteria, supplier due diligence, contract schedules and approval gates. Familiarity with basic cyber terms—confidentiality, integrity, availability, access control, incident response, encryption and data classification—is expected; participants do not need to be security engineers. No coding, penetration-testing experience, security certification or prior use of a third-party risk platform is required. A laptop with spreadsheet and document-editing capability is needed for workshops and template development.
Training methodology
The five days combine focused instructor-led teaching with procurement scenarios drawn from cloud, software, managed-service and data-processing contracts. Participants review realistic supplier questionnaires, certificates, SOC reports, incident clauses and remediation evidence rather than abstract control descriptions. Small groups conduct a supplier assessment, compare scoring decisions and defend their recommendation in a simulated award board. Individual work converts the methods into category-specific templates and a 90-day application plan, with instructor feedback on risk logic, escalation wording and the practical usability of each deliverable.
Course outline
Day 1: Cyber risk in the procurement lifecycle
- Third-party attack paths across cloud, SaaS, managed service and data-processing suppliers
- Procurement accountability within the three-lines risk model
- Inherent risk factors: data sensitivity, connectivity, criticality and supplier dependency
- Supplier segmentation tiers and proportionate assurance requirements
- Mapping cyber checkpoints to source-to-contract and procure-to-pay stages
- Cyber risk appetite, tolerance statements and approval authorities
- Stakeholder roles for procurement, security, legal, privacy and business ownership
Workshop: Participants map a sample procurement lifecycle and produce a supplier-tiering decision for six vendor profiles.
Day 2: Due diligence and evidence evaluation
- Designing risk-based security questionnaires using the Shared Assessments SIG
- Using NIST Cybersecurity Framework 2.0 to organise supplier control questions
- Interpreting ISO/IEC 27001 certification scope, statement of applicability and surveillance status
- Reading SOC 2 Type II reports, complementary user entity controls and exceptions
- Assessing penetration-test summaries, vulnerability management evidence and remediation claims
- Validating cloud security attestations, data-flow diagrams and shared-responsibility boundaries
- Identifying evidence gaps, contradictions and unsupported supplier assertions
Workshop: Participants review a supplier evidence pack and produce an evidence-gap log with follow-up questions and priority ratings.
Day 3: Risk assessment, scoring and decision making
- Building a third-party risk register with clear risk statements and affected assets
- Likelihood and impact scoring for confidentiality, integrity, availability and regulatory exposure
- Control-effectiveness assessment and residual-risk calculation
- Risk treatment options: accept, mitigate, transfer, avoid and defer
- Defining remediation milestones, evidence requirements and accountable owners
- Establishing escalation thresholds for award, renewal and go-live decisions
- Preparing risk-acceptance papers for delegated approval authorities
Workshop: Participants score a high-risk cloud supplier, build a residual-risk register and draft an award recommendation for a risk committee.
Day 4: Security requirements and contract controls
- Translating risk assessments into mandatory, weighted and desirable RFP requirements
- Writing security schedules aligned to data classification and service criticality
- Incident-notification timeframes, communication obligations and forensic cooperation clauses
- Audit rights, assurance reporting and access to independent assessment evidence
- Subprocessor approval, supply-chain flow-down and location-control provisions
- Business continuity, disaster recovery, resilience testing and service restoration commitments
- Exit management, secure data return, deletion certification and transition assistance
Workshop: Participants redline a supplier contract schedule and produce a negotiated cyber-control position for a managed-service engagement.
Day 5: Ongoing monitoring and operating model implementation
- Configuring supplier records, assessments and issues in OneTrust Third-Party Risk Management
- Monitoring triggers for material changes, incidents, acquisitions and service-scope expansion
- Supplier remediation governance, action tracking and overdue-issue escalation
- Cyber performance indicators and supplier risk dashboards for procurement leadership
- Renewal reviews and reassessment cadence by supplier risk tier
- Offboarding controls for access removal, data destruction and retained-record verification
- Designing a procurement cyber-risk operating model and 90-day rollout plan
Workshop: Participants assemble their complete third-party cyber-risk assessment pack and present a 90-day implementation plan to a simulated procurement leadership panel.
Tools & standards covered
OneTrust Third-Party Risk Management, Shared Assessments SIG, NIST Cybersecurity Framework 2.0, ISO/IEC 27001
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Cyber Security Governance for Government and Public Sector Teams Training Course
Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while work…
Okta Identity Engine Access Management Security Training Course
Okta administrators and identity security teams are often expected to strengthen access controls without creating sign-in friction, breaking…
IBM QRadar SIEM Administration and Offence Investigation Training Course
IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires mor…
Advanced Cyber Threat Hunting and Incident Response Training Course
Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…