Companies of every size and industry must evaluate the security risks introduced by third-party apps and services. Getting compromised by an outsider is bad, but getting compromised through a vendor can be much worse due to their access to company data and use within closed networks. This talk will provide a primer for getting started on third-party vendor review and risk management, including tips to improve your organization's data and security posture. Attendees will learn how to classify the sensitivity of data, how to do this work within a team, what risk acceptance is and how it works, and what resources may be available to you within your company.