Context

As a Business Information Security Officer, part of my portfolio included oversight of a critical third-party vendor that handled regulated data. The vendor carried roughly 30 aged high and medium-severity security findings that represented ongoing, unresolved risk to the business.

The challenge

The backlog had built up across several review cycles. Some findings were genuinely being remediated, some were sitting in risk acceptance that no one had revisited, and some were effectively resolved but never closed out. As a single count it looked worse than it was, and that was the problem: real risk was hidden among items that were already handled, so nobody could tell where to actually push. A number you cannot act on is not much better than no number at all.

What I did

Outcome

The backlog dropped from roughly 30 aged high and medium-severity findings to fewer than 10, with each remaining item either actively remediated or knowingly and appropriately accepted. More importantly, the number finally meant something, because everything behind it had an owner and a status.

What it demonstrates

Vendor security assessment, third-party risk triage, and driving vendor remediation to closure while governing the residual accepted risk, in an environment where the vendor handled regulated data.