SPOILER ALERT: The Future of Vendor Risk Management Doesn’t Involve Asking Vendors to Complete the HECVAT

Thursday, May 02, 2024 | 10:00AM–10:45AM CT | Exhibit Hall, First Floor
Session Type: Poster Session
Delivery Format: Poster
Traditional vendor risk management involves requesting and collecting HECVAT questionnaires, a cumbersome process filled with friction for both higher education institutions and vendors. Our session explores a visionary concept: vendors voluntarily sharing HECVAT data to transform how we manage vendor risks. It's a collaborative effort among higher education institutions. This shift envisions a future where companies don't request HECVAT from vendors; vendors willingly share data, fostering collaboration. This approach emphasizes higher education institutions uniting as a community. The session features insights from EDUCAUSE cybersecurity practitioners and industry leader Whistic. It discusses how institutions can encourage vendors to contribute HECVAT data, emphasizing collective action. Attendees will learn the benefits, including transparency, efficiency, and accuracy, in risk assessment. Real-world examples illustrate its impact. We'll also review a 2023 industry report on vendor risk management trends and delve into technical and privacy/security aspects. Join us to envision a future where vendor risk management thrives on collaboration. Discover how this approach can enhance risk assessment and create a more secure vendor ecosystem through collective vision and teamwork.

Presenters

  • Nathan Christensen

    Third Party Risk AE, Whistic

Resources & Downloads

  • SPOILER ALERT The Future of Vendor Risk Management Doesnt Involve Asking Vendors to Complete the

    Updated on 8/1/2026