Context
As a Business Information Security Officer, part of my portfolio included oversight of a critical third-party vendor that handled regulated data. The vendor carried roughly 30 aged high and medium-severity security findings that represented ongoing, unresolved risk to the business.
The challenge
The backlog had built up across several review cycles. Some findings were genuinely being remediated, some were sitting in risk acceptance that no one had revisited, and some were effectively resolved but never closed out. As a single count it looked worse than it was, and that was the problem: real risk was hidden among items that were already handled, so nobody could tell where to actually push. A number you cannot act on is not much better than no number at all.
What I did
- Triaged the full backlog. I worked through every finding to separate true open risk from items that were already remediated, duplicated, or appropriately accepted, so the list reflected reality rather than history.
- Drove remediation with the vendor. I owned driving the items that mattered to closure while the vendor executed the fixes, tracking each to a documented resolution with evidence rather than a verbal assurance.
- Reset the risk acceptances. Each accepted finding was given a current owner, a documented justification, and a review date, so residual risk was a deliberate, revisited decision rather than a forgotten one.
- Reported the posture into leadership. I made the reduction and the remaining accepted risk visible to leadership, so the improvement was clear and the risk that stayed was knowingly owned.
Outcome
The backlog dropped from roughly 30 aged high and medium-severity findings to fewer than 10, with each remaining item either actively remediated or knowingly and appropriately accepted. More importantly, the number finally meant something, because everything behind it had an owner and a status.
What it demonstrates
Vendor security assessment, third-party risk triage, and driving vendor remediation to closure while governing the residual accepted risk, in an environment where the vendor handled regulated data.