General session image of Knowledge Forum D

Assess service providers, minimise risks

Auditing external service providers in the field of information security: assessing risks, reviewing requirements, ensuring security.

Topic

Governance, Riskmanagement and Compliance

When & Where

calendar_month

Thu, 10/29/2026 11:30 AM - 11:45 AM

location_on

Forum D, Booth 7-742

Download session as iCaldownload_for_offline

Details

  • Format:

    Management lecture

  • Language:

    German

Session description

Speakers: Sandra Decosas and Mika Wiemken

You know your own IT – but how well do you know the security of your service providers? Increasingly, attackers are no longer gaining access via a company’s own perimeter, but through suppliers, IT providers and other third parties. A single compromised service provider is enough to bring business operations to a halt, expose data or cause financial loss – often resulting in a liability issue that falls on the contracting company.
We examine the topic of service provider and supply chain risks from three perspectives: real-life incidents where damage scenarios have arisen due to service providers; a concise overview of the regulatory framework (including NIS-2 and DORA) without delving into legal detail; and a selection of typical vul ...