Every large company has some version of a vendor risk program by now. A vendor list. Risk tiers. Questionnaires and certifications. Insurance requirements. A workflow for approving exceptions when something falls short. Building and running all of that costs real time and real money. Unfortunately, none of it tells you what your actual exposure is.
That’s the argument in “The Missing Measure in Third-Party Information Risk,” a paper from HITRUST founder and executive chairman Daniel Nutkis. It’s the first of a three-part series on how companies govern vendor risk. I spoke with Marc Solomon, HITRUST’s chief marketing officer, about the thinking behind it. The industry has built a lot of machinery for tracking vendor activity, but it hasn’t built a common way to measure what’s left over once all that tracking is done.
Plenty of Data, No Consistent Measure
The reality is that two companies can hold the same type of report and be sitting on very different risk.
Solomon described HITRUST’s own research on SOC 2 reports. The firm reviewed more than 100 of them and found wide gaps in what different assessors were willing to sign off on. “It was over 100 SOC 2s… 74 percent did not require multi-factor authentication,” Solomon told me.
An insurance certificate has a similar gap. Having one on file tells you a policy exists. It doesn’t tell you whether that policy covers the loss you’re worried about. Multiply that across a few hundred vendors. Different people reviewed them at different times against different rules. You’re left with a stack of paperwork, not a number you can use.
There’s a coverage problem underneath all of this, too. Most teams don’t have the staff to review every vendor. So they focus on the biggest or loudest relationships and let the rest go mostly unchecked. That’s a reasonable trade-off given limited resources. But nobody ends up knowing how much risk is sitting in the vendors that never made the list.
Why a Common Number Is Harder Than It Sounds
The obvious fix is to build a score. Take all that scattered evidence and boil it down into one number people can compare. HITRUST is taking that approach by developing the Information Risk Index, or IRIDEX.
When I spoke with Solomon, he compared it with a metric most people already understand: consumer credit, and FICO in particular. “There’s nothing in information risk that has that,” he told me. “If anything, it’s so fragmented — that’s the problem.”
That’s basically the FICO story, too. FICO existed for years as one score among several, nothing special. Then Fannie Mae and Freddie Mac began requiring it for mortgages. That’s what forced the market to standardize, Solomon said. A good approach rarely spreads just because it’s good. Usually, it takes someone with real leverage in the market to force everyone onto the same yardstick.
That’s a bigger job than simply publishing a score, though. HITRUST says the index isn’t meant to replace the evidence risk teams already collect. “We’re not saying we’re replacing these; we’re supplementing what’s out there,” Solomon said. The index sits on top of questionnaires, certs, and audit reports. It’s meant to turn all of that into one number you can compare across vendors. Eventually, across companies too.
What Changes If This Gets Fixed
If this works, it changes what a risk team can do day to day. A team could ask whether a vendor’s leftover risk fits inside the company’s tolerance, instead of just confirming the review got done. It also changes the conversation with a vendor that doesn’t have a cert yet. A company could score what the vendor already has, then work out how to work together while the vendor closes the gap. Insurance can cover the interim risk, so the deal doesn’t just stall.
It also makes some comparisons possible that are impossible today. Teams could line vendors up on a common scale, something certs were never built to do. They could also check their own risk thresholds against peers. Right now, “high risk” doesn’t mean the same thing at one company as it does at another.
None of this solves third-party risk by itself. Vendors are still going to get breached, and contracts are still going to have gaps nobody notices until it’s too late. But a company that can’t measure its own exposure consistently is going to have a hard time managing it, insuring it, or explaining it to a board.
- Third-Party Risk Programs Have Plenty of Data and No Way to Measure It - August 24, 2026
- The Attack That Turns Your AI Agent Into A Weapon Against You - August 20, 2026
- Sophos Fusion Aims To Replace Security Tool Sprawl With One AI System - August 10, 2026