[{"data":1,"prerenderedAt":421},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"guide-en-vendor-security-incident-playbook":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":89,"entities":360,"extension":364,"faq":365,"keywords":384,"meta":390,"navigation":391,"ogImage":392,"path":393,"persona":394,"publishedAt":395,"regulation":392,"relatedFeatures":396,"relatedPages":401,"seo":405,"shortTitle":87,"slug":406,"sources":407,"stem":417,"tldr":418,"updatedAt":419,"__hash__":420},"guides_en\u002Fen\u002Fguides\u002Fvendor-security-incident-playbook.md","Vendor Security Incident: A 5-Step Response Playbook | CISAPP","CISAPP",{"type":108,"value":109,"toc":352},"minimark",[110,115,119,127,130,153,157,163,169,175,181,185,188,194,200,206,212,218,303,307,310,316,327,333,343,349],[111,112,114],"h2",{"id":113},"what-do-you-do-in-the-first-hours","What do you do in the first hours?",[116,117,118],"p",{},"A vendor informs you — by email, a public statement, or worse, you find out through the press — that it has suffered a security incident. The minutes and hours that follow determine the actual scale of impact on your organization far more than the initial severity of the incident at the vendor itself.",[116,120,121,122,126],{},"The difficulty is almost never technical at this stage — it's an ",[123,124,125],"strong",{},"information"," problem. Are we affected? What data did we entrust to them? Do they have access to our network? Which business activities depend on them, and is there a fallback? These questions, asked urgently in a crisis meeting, need an answer in minutes, not days — yet that's exactly how long it takes, in an unprepared organization, just to reconstruct who this vendor is and what it has access to.",[116,128,129],{},"This guide lays out a five-step playbook, applicable the moment a third-party incident is announced, designed to turn initial panic into a controlled sequence of actions.",[131,132,133],"key-takeaways",{},[134,135,136,144,147,150],"ul",{},[137,138,139,140,143],"li",{},"The \"which vendor supports which activity\" map has to exist ",[123,141,142],{},"before"," the incident.",[137,145,146],{},"Cutting access is an exemption decision: document it, with justification and a reassessment date.",[137,148,149],{},"Your notification obligations remain yours, even when the incident happened at a third party.",[137,151,152],{},"An incident not converted into tracked corrective actions will recur unchanged.",[111,154,156],{"id":155},"why-does-the-response-often-fail-under-pressure","Why does the response often fail under pressure?",[116,158,159,162],{},[123,160,161],{},"The needed information is scattered across teams."," Procurement knows who signed the contract. IT knows what technical access exists. Security knows — sometimes — what criticality level was assigned to the vendor. Without a single register linking this information, the first step of a vendor incident is an emergency meeting just to figure out who knows what.",[116,164,165,168],{},[123,166,167],{},"There's no pre-established decision process."," Should access be cut immediately? Should you wait for confirmation of scope? Should a backup vendor be activated? Without a playbook defined in advance, these decisions get made under pressure, in the moment, with a high risk of error — overreacting by cutting critical access with no alternative, or underreacting by leaving a compromised access active too long.",[116,170,171,174],{},[123,172,173],{},"Incident tracking gets lost in email threads."," Without a structured register, the record of what was decided, by whom, and when dissolves across email exchanges and instant messages — a major problem if the incident later needs to be documented for a regulator, an insurer, or a client demanding accountability.",[116,176,177,180],{},[123,178,179],{},"Closing the incident doesn't trigger structural action."," Once the incident is contained at the vendor, the organization resumes business as usual without necessarily documenting the lesson learned — the same blind spot stays open for the next incident, because it was never converted into a tracked risk or a corrective measure.",[111,182,184],{"id":183},"what-are-the-five-steps-of-the-playbook","What are the five steps of the playbook?",[116,186,187],{},"This playbook builds on incident management and business continuity principles formalized in ISO 27035 and echoed by the NIS2 and DORA incident-notification requirements.",[116,189,190,193],{},[123,191,192],{},"Step 1 — Qualify exposure in minutes, not hours."," The moment the incident is announced, the absolute priority is identifying: does this vendor have access to our network or our data? Which business activities depend on it, and at what criticality level? This answer must be available immediately — it should never depend on an emergency search through scattered files.",[116,195,196,199],{},[123,197,198],{},"Step 2 — Decide and document a containment measure."," Depending on the nature of the incident and the criticality of the service, a decision must be made: temporary access suspension, enhanced monitoring, or maintaining the status quo if cutting access would cause more damage than the incident itself. This decision must be formalized, justified, and paired with an explicit reassessment date — the very principle of a controlled exemption.",[116,201,202,205],{},[123,203,204],{},"Step 3 — Activate the crisis cell if impact warrants it."," For incidents affecting a critical activity or involving sensitive data, a dedicated crisis management structure (defined roles, coordinated internal and external communication, documented procedures) must be activated without delay — improvising at this stage costs both time and credibility.",[116,207,208,211],{},[123,209,210],{},"Step 4 — Track the incident with delay indicators, not just a status."," Managing a vendor incident should rely on precise KPIs: time-to-detect, time-to-contain, time-to-close. Beyond immediate management, these indicators also feed regulatory notification obligations when the incident is significant.",[116,213,214,217],{},[123,215,216],{},"Step 5 — Turn closure into structural action."," A vendor incident closed without root-cause analysis or follow-up action is a missed opportunity. Closure should systematically translate into a reassessment of the vendor's criticality or score, and into creating a documented risk if a structural weakness (no fallback, excessive concentration) was revealed.",[219,220,222],"comparison-table",{"caption":221},"Notification deadlines by incident qualification",[223,224,225,244],"table",{},[226,227,228],"thead",{},[229,230,231,235,238,241],"tr",{},[232,233,234],"th",{},"Framework",[232,236,237],{},"Trigger",[232,239,240],{},"First deadline",[232,242,243],{},"Following deadlines",[245,246,247,262,276,290],"tbody",{},[229,248,249,253,256,259],{},[250,251,252],"td",{},"NIS2, Article 23",[250,254,255],{},"Significant incident",[250,257,258],{},"Early warning within 24 h",[250,260,261],{},"Notification within 72 h, final report within one month",[229,263,264,267,270,273],{},[250,265,266],{},"GDPR, Article 33",[250,268,269],{},"Personal data breach",[250,271,272],{},"Notification to the authority within 72 h",[250,274,275],{},"Information to individuals where risk is high (Art. 34)",[229,277,278,281,284,287],{},[250,279,280],{},"GDPR, Article 33(2)",[250,282,283],{},"Breach detected by the processor",[250,285,286],{},"Alert the controller without undue delay",[250,288,289],{},"Support the controller's case file",[229,291,292,294,297,300],{},[250,293,42],{},[250,295,296],{},"Major ICT incident",[250,298,299],{},"Initial notification to competent authorities",[250,301,302],{},"Intermediate and final reports",[111,304,306],{"id":305},"how-does-cisapp-equip-this-playbook","How does CISAPP equip this playbook?",[116,308,309],{},"CISAPP structures each of these five steps in a single register, instead of disjointed tools activated under pressure.",[116,311,312,315],{},[123,313,314],{},"Immediate qualification via the unified register."," Because every vendor is natively linked to the business activities it supports and its documented criticality level, the question \"are we affected, and to what extent?\" gets answered in a few clicks in the vendor record — not after a reconstruction meeting.",[116,317,318,321,322,326],{},[123,319,320],{},"Controlled exemptions to document the containment decision."," The Exemptions module (",[323,324,325],"code",{},"\u002Fgovernance\u002Fexemptions",") lets you formally record a temporary gap-acceptance decision — for example, keeping access under enhanced monitoring rather than cutting it — with a mandatory expiration date and scheduled reassessment, ensuring the emergency decision never becomes a forgotten exception.",[116,328,329,332],{},[123,330,331],{},"A structured crisis management setup."," For major incidents, the Crisis Management module offers a centralized setup, dedicated crisis cells per incident, a procedures guide, and a contact directory — roles and communication are prepared ahead of time, not improvised on the day.",[116,334,335,338,339,342],{},[123,336,337],{},"An incident register with native KPIs and cross-organization propagation."," The incident register (",[323,340,341],{},"\u002Fincidents",") natively tracks detection, containment, and closure delays, with a timeline and documented actions. The incoming-incidents feature additionally lets you log an incident whose origin is declared by a vendor itself — traceability covers the full chain, not just the incident as seen from the inside.",[116,344,345,348],{},[123,346,347],{},"A closure step that triggers structural analysis."," Every incident can be directly linked to a new or existing risk in the risk register, with a treatment measure, an owner, and a deadline — and the vendor's criticality reassessment can be relaunched in one click from its record, closing the loop between the incident and continuous improvement.",[116,350,351],{},"An incident at a vendor is rarely 100% avoidable — but the difference between an organization that suffers and one that leads comes down entirely to the speed and structure of the response in the first hours. CISAPP turns this playbook into an equipped reflex rather than improvisation under pressure.",{"title":353,"searchDepth":354,"depth":354,"links":355},"",2,[356,357,358,359],{"id":113,"depth":354,"text":114},{"id":155,"depth":354,"text":156},{"id":183,"depth":354,"text":184},{"id":305,"depth":354,"text":306},[361,362,363],"Vendor SPOF","Sub-processor","Essential entity","md",[366,369,372,375,378,381],{"q":367,"a":368},"What's the first action when a vendor discloses a security incident?","Immediately identify which business activities and which data depend on that vendor, before even knowing the technical detail of the incident. Without this pre-existing map, the first hour is lost searching for information instead of acting.",{"q":370,"a":371},"Should you cut a vendor's access as soon as an incident is announced?","It depends on the criticality of the service and the nature of the incident. It's a controlled exemption decision: cutting access protects you, but can interrupt an essential activity. The decision must be documented with justification and a reassessment date.",{"q":373,"a":374},"Does NIS2 impose a notification deadline for vendor incidents?","NIS2 requires covered entities to notify significant incidents to the competent authority, with an early warning within 24 hours and a detailed report within 72 hours — an incident at a vendor that impacts the entity can fall within that scope.",{"q":376,"a":377},"How does CISAPP structure the response to a vendor incident?","Through an incident register linked to affected vendors and activities, native detection and containment KPIs, a controlled exemption mechanism, and a direct link to the risk register to convert the incident into tracked corrective actions.",{"q":379,"a":380},"Which notification deadlines apply, and to what?","Under NIS2: early warning within 24 hours, notification within 72 hours, final report within one month for a significant incident. Under the GDPR: notification to the supervisory authority within 72 hours for a personal data breach, and information to the individuals without undue delay where the risk is high.",{"q":382,"a":383},"What should you request from the vendor during the incident?","A dated timeline, the technical scope affected, the data and customers involved, the containment measures already taken, and a single point of contact. Those elements feed your own notification file, for which you remain responsible.",[385,386,387,388,389],"vendor security incident","vendor incident playbook","third-party incident response","vendor crisis management","subprocessor incident notification",{},true,null,"\u002Fen\u002Fguides\u002Fvendor-security-incident-playbook","entreprise","2026-07-11",[397,398,399,400],"Incidents","Exemptions","Crisis management","Risks",[402,403,404],"gestion-risque-fournisseur","cybersecurite-supply-chain","nis2",{"title":105,"description":89},"vendor-security-incident-playbook",[408,413],{"label":409,"url":410,"publisher":411,"date":412},"Directive (EU) 2022\u002F2555 (NIS2), Article 23 — significant incident reporting","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2022\u002F2555\u002Foj","EUR-Lex","2022-12-14",{"label":414,"url":415,"publisher":411,"date":416},"Regulation (EU) 2016\u002F679 (GDPR), Articles 33 and 34 — breach notification","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2016\u002F679\u002Foj","2016-04-27","en\u002Fguides\u002Fvendor-security-incident-playbook","When a vendor discloses an incident, the first hours decide the impact. The playbook has five steps: qualify the exposure (which activities, which data), contain through traceable decisions, document the timeline, meet your own notification obligations — 24 h\u002F72 h under NIS2, 72 hours for a personal data breach — then convert the incident into corrective actions.","2026-08-16","Pqwaraz4iFKAoQry1HFa9bRmV1lJ6y13N7Wn0nc2N3I",1791391139576]