Report an Incident Become a Partner Careers Contact
Book a Demo
Risk & compliance · third-party risk

Your suppliers are
your attack surface.

Most third-party risk programmes produce a spreadsheet of scores nobody acts on. Ours ends somewhere useful: when a supplier is breached, the same analysts already watching your estate go and find out whether it reached you.

Supplier event · tier 1 providerday 0
INTELBreach disclosed by a tier 1 supplierseen
REGAccess they hold: 2 tenants, 1 integrationknown
HUNTSearching your estate for that accessrunning
SCOPENo use of supplier credentials foundruled out
DETECTDetection written for the technique usedbacktested
L3Senior analyst signs the verdictdefault
What this is for

The breach arrives
through somebody you trusted.

Supplier compromise is now one of the most common ways into an organisation, and it is the route your own controls are least able to see.

The uncomfortable part is not that suppliers get breached. It is that the access they hold into your estate usually outlives the relationship that justified it, and almost nobody is watching it. A managed service provider with a standing admin account, a SaaS platform holding a copy of your customer data, an integration built three years ago by somebody who has left.

Meanwhile the assurance process most organisations run against that risk is an annual questionnaire, answered by the supplier, filed by you, and out of date within a month. It satisfies an auditor. It does not tell you that the supplier was compromised last Tuesday.

  • A register of who your suppliers actually are, not who procurement thinks they are.
  • Tiering by the access and data they hold, so effort goes where the risk is.
  • Assessment proportionate to tier, instead of the same questionnaire for everyone.
  • Continuous monitoring between assessments, because that is where the year actually happens.
  • And when something fires, an investigation in your estate rather than a notification.
How the service runs

Six steps,
and we do five of them.

You decide the risk appetite and who is in scope. Everything after that is ours to run, and it runs continuously rather than once a year.

  1. 01

    Build the register

    Who your suppliers are, what each one touches, and which hold access into your estate. Most organisations find this list is longer than the one procurement holds, and that is usually the first useful finding.

  2. 02

    Tier by consequence

    Ranked on the data they hold, the access they have and what breaks if they stop. A payroll provider and a stationery supplier do not get the same treatment, and pretending otherwise is why programmes stall.

  3. 03

    Assess proportionately

    Evidence gathered once and reused where we can, so your critical suppliers get a real assessment and your low-tier ones are not sent a 300-question spreadsheet nobody reads.

  4. 04

    Monitor continuously

    External posture, exposed services, breach disclosures and credential leaks, watched between assessments rather than at renewal. The year is where the risk changes.

  5. 05

    Investigate what fires

    A rating drop or a breach disclosure is triaged by our SOC the same way any other signal is, against the question that matters: does this touch this customer, and how?

  6. 06

    Track it to closed

    Remediation chased, re-checked and evidenced, with reporting your board and your auditor can both use. A finding that stays open is reported as open.

What happens when a supplier is breached

Everyone can tell you
that it happened.

The disclosure is public within hours and every rating platform will flag it. That is not the hard part, and it is not what you are exposed by.

The question that actually matters on the day is narrower and much harder: did it reach us. Answering it means knowing what access that supplier holds in your environment, going and looking for whether it was used, and doing that while the story is still moving.

A third-party risk platform cannot answer it, because it has no visibility inside your estate. A managed SOC usually cannot either, because nobody told it which suppliers matter or what they are connected to. We run both halves, so the supplier register and the detection estate are the same body of knowledge.

How our SOC investigates

We already know what they touch
The register records the accounts, integrations, tenants and data flows each supplier holds. On the day of a disclosure that is a starting point rather than a research project.
We hunt for it in your estate
A targeted hunt against that supplier’s access paths and the indicators from the incident, run by the analysts who already know your environment.
You get a verdict, not a warning
What we found, what was ruled out and what it means for you, with the evidence attached. Average time to an L1 verdict across our SOC is 3m 30s.
Detections go in afterwards
Where the incident shows a technique we can watch for, detection content is written for your estate and backtested, so the next supplier compromised the same way is caught earlier.

If a supplier of yours is compromised and it never touched you, that is worth knowing too, and worth having in writing when your customers ask.

What we watch between assessments

An annual questionnaire
covers about one day a year.

The other three hundred and sixty-four are where a supplier’s posture actually changes, and almost nobody is looking at them.

Breach and incident disclosure
Public disclosures, regulatory filings and credible reporting against every supplier on the register, matched to the ones that hold access to you.
External posture
Internet-facing services, expiring or misissued certificates, exposed admin interfaces and infrastructure appearing where it should not.
Leaked credentials
Supplier-domain credentials surfacing in breach corpora and criminal marketplaces, which is often the first sign of a compromise the supplier has not yet noticed.
Material change
Acquisitions, insolvency signals, sanctions and changes of ownership or hosting country, all of which can change your risk without anybody touching a control.
Concentration
Where the register shows a lot of your critical suppliers depending on one underlying provider, so a single outage or compromise reaches further than the vendor list suggests.
Assessment drift
Certifications lapsing, evidence going stale and answers that no longer match what we can observe from outside.

Anything that moves materially is triaged rather than emailed. What reaches you is something we think you need to act on, with the reasoning attached.

Why organisations start

Nobody does this
because it seemed sensible.

Four things start a supply chain programme, and they want different first steps. Tell us which one you are and the scoping conversation is shorter.

Regulation

DORA, NIS2 or a sector rulebook

Supplier oversight is now explicit in law for financial services and for essential and important entities. Both require a register, tiering, evidence and a process that demonstrably runs, not a policy that says it should.

First step: the register and the evidence trail.

Customers

A large customer is asking

Your own buyers are running the same programme on you, and their questionnaires now ask what you do about your suppliers. Answering that credibly is increasingly a condition of the contract.

First step: something you can put in front of them.

Incident

It already happened

A supplier was compromised, somebody asked whether it reached you, and the honest answer took three weeks to assemble. That question is the one this service is built to answer in hours.

First step: what access each supplier actually holds.

Scale

The list got away from you

Growth, acquisition or a few years of SaaS sprawl, and nobody can say with confidence who has access to what. Common, and usually discovered during one of the other three.

First step: find out who the suppliers really are.

What you are actually buying

A managed service,
not a licence and a login.

There is a lot of software in this market and most of it gets sold to people who then discover they have bought a job rather than a service.

The tooling underneath is a specialist platform, operated by us as part of the service. You do not license it, administer it or learn it, and you are not the one chasing a supplier for the fourth time about an expired certificate. If you would rather run your own platform and have us work inside it, that is also fine and fairly common.

Behind it is an operation we have run since 2019: security operations centres in three countries manned around the clock, senior analysts accountable for every customer-facing decision, and triage procedures written by our own people. Your supplier register sits inside that operation. That is why a supplier breach here produces an investigation rather than an email.

What we will not do is sell you a dashboard of supplier scores and call it a risk programme.

What comes out of it

Evidence somebody
can actually use.

Reporting is a deliverable here rather than a by-product, because most of the value of this programme is proving to somebody else that you run it.

A live supplier register
Tiered, current, and showing what each supplier touches. The thing most organisations discover they never had.
Assessment records
What was asked, what was evidenced and what was accepted, with the reasoning kept. An auditor asking why a supplier was approved gets an answer rather than a shrug.
Continuous monitoring history
What changed for each supplier and when, so a rating is a trend you can defend rather than a number on the day somebody looked.
Incident write-ups
Where a supplier event was investigated, what we hunted for and what was found or ruled out in your estate.
Board reporting
Concentration, tiering and open findings in a form you can put in front of a board or a customer without rewriting it first.
Framework evidence
The supplier-management controls in ISO 27001, NIS2, DORA and most customer security questionnaires are answered by the artefacts above rather than by a separate exercise.
Questions

Third-party risk, answered.

What is third-party risk management?

The practice of knowing which suppliers can hurt you, how much, and whether anything has changed. It covers building a supplier register, tiering by consequence, assessing proportionately, monitoring continuously, and acting when something moves. The assessment half is common. The acting half is where most programmes stop.

How is this different from a vendor risk platform?

A platform produces findings and hands them to you. This is a managed service: we operate the tooling, run the assessments, chase the remediation, and investigate what fires. The difference shows up on the day a supplier is breached, when a platform tells you it happened and we tell you whether it reached you.

A supplier of ours has just been breached. What do you actually do?

We look at what access that supplier holds in your estate, hunt for whether it was used against the indicators from the incident, and come back with a verdict and the evidence. That is a SOC investigation, not a notification, and it is the part a risk platform on its own cannot do.

Do we need to buy the software?

No. The platform is operated by us as part of the service, so you are not licensing it, administering it or learning it. If you already run your own tooling and would rather we worked inside it, we can do that instead.

How many suppliers can you cover?

Continuous monitoring scales across the whole register, so breadth is rarely the constraint. Assessment depth is tiered, because assessing every supplier to the same standard is how programmes stall. The split between the two is agreed with you during scoping.

Will this satisfy our auditors?

It produces the artefacts they ask for: a current register, tiering rationale, assessment records with evidence, monitoring history and open findings. The supplier-management controls in ISO 27001, NIS2 and DORA are largely answered by those. We are not a certification body and do not audit you.

Do you have to run our SOC as well?

No. The service stands on its own. But the part that separates it - hunting in your estate when a supplier is compromised - needs visibility of that estate, so it is materially stronger where we also run detection and response. We will tell you plainly which half you are buying.

How quickly can this start?

Building the register is the first piece of work and the pace depends on how well documented your supply chain already is. Continuous monitoring can be live across a known supplier list quickly; tiering and assessment are the parts that take real time, and we scope them before anything is signed.

Where to start

Start with the register
and see who actually has access.

The first piece of work is finding out who your suppliers really are and what they touch. That list is almost always longer than the one procurement holds, and it is useful on its own.