# Banks Strengthen Third-Party Cybersecurity Controls

Banking-sector discussion highlighted persistent gaps in third-party risk management: business owners may seek exceptions to security policies, and banks may lack consistent supplier information to assess risk at scale. Participants recommended prioritizing suppliers based on access to critical systems and sensitive data, applying least privilege and ongoing monitoring, and obtaining evidence such as security attestations, software bills of materials (SBOMs), and penetration-test results. They also cautioned that multicloud can improve availability resilience without necessarily improving security.

- Procurement teams can use supplier access and data sensitivity to prioritize due diligence and ongoing oversight.
- Vendor evaluations and contract discussions can address least-privilege access, continuous monitoring, and evidence of security testing and software-component transparency.
- Companies selling to banks may benefit from preparing current security attestations, SBOMs, and penetration-test evidence for procurement reviews.
- Multicloud proposals should distinguish availability benefits from security controls; using multiple cloud providers alone does not establish stronger security.

**Jurisdictions:** international
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 07, 2026

### Vendors
- Salesforce ()
- Amazon Web Services (AWS) ()
- Google Cloud Platform (GCP) ()
- BlackFog ()
- JPMorgan Chase ()

### Key Quotes
> The LoB will exert business influence to flout policy and demand risk acceptance instead of compensating controls. Because those cost money, which they never budgeted for Vendor X. And then the risk sits on the register forever, handed down from one LoB generation to the next.
> — Commenter (unnamed)

### Sources
- [Cybersecurity and Third-Party Risk in Banking](https://www.reddit.com/r/cybersecurity/comments/1wzisio/cybersecurity_and_thirdparty_risk_in_banking) - reddit-cybersecurity