OneTrust Acquires Shared Assessments

May 6, 2021 | News

SOURCE: OneTrust

Shared Assessments, a global membership organization focused on third party risk management tools, best practices, professional certifications and findings, is now part of OneTrust, a fast-growing data privacy, compliance and governance enterprise platform backed by several top VCs. Terms of the deal were not disclosed.

“The Shared Assessment and OneTrust partnership will transform third-party risk governance and will be a game-changer in the global marketplace and the industry,” said Alpa Inamdar, Global Head of Third Party Governance Advisory, BNY Mellon.

Recent global events such as the COVID-19 pandemic and Solar Winds exposure have exacerbated the challenges of managing third-party risk, and the invalidation of the EU-US Privacy Shield (Schrems II) is forcing organizations to reevaluate thousands of third-party data transfers.

Forrester research notes that “The number of third parties requiring vetting, monitoring, and mitigation far exceed the capacity of most TPRM teams, so they only focus on those considered ‘critical.’”

“We believe standardization is the future of the third-party risk management market,” said Kabir Barday, CEO, OneTrust. “The Shared Assessments SIG is already one of the most widely used standards in the world, and together we can further invest in the SIG’s technology, global reach, and adoption so we can make it the ubiquitous global standard. We also recognize it is critical Shared Assessments continues to operate with a wide variety of industry players and is guided by their standards board and advisory committees.”

OneTrust intends to sustain Shared Assessments’ status and role as a respected, member-driven industry organization, noting that the organization’s integrity is vital to its emerging role as a global standard for third-party risk.

The acquisition enables Shared Assessments to continue to scale the availability and adoption of its tools and risk management resources, including its Standardized Information Gathering Questionnaire (SIG), which is used by more than 15,000 companies globally. Expansions of the SIG under consideration include:

– Global reach: Making the SIG globally available in languages around the globe

– International alignment: Aligning the SIG more deeply with international frameworks

– Real-time updates: Adapting in real-time based on industry news and events (e.g. COVID, Schrems II)

– Adjacent risk domains: Advance its adoption across multiple risk areas, including ESG

– Technology enhancements: Build an advanced next gen technology platform to make it easier for organizations to adopt and apply the SIG in their programs

The annual Shared Assessments Summit, thought leadership, professional certifications programs and other initiatives will also see investment. Shared Assessments will continue to build its programs, partnerships, and standards supported by its steering committees, advisory boards, licensee partnerships, and member agreements. It plans to continue operating as an open and vendor-neutral industry organization.

“Catherine A. Allen, Shared Assessments founder and interim CEO, said: “Our joint vision of collaborative efforts within the industry will benefit third party risk management as a whole, and enable Shared Assessments to stay at the forefront of the industry and global adoption of standardization.”

 

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more