Assessing the cyber risk your critical suppliers and vendors carry into your organisation, before it becomes your incident.
Organisations increasingly invest heavily in their own security while paying far less attention to the vendors and suppliers connected to their systems and data. A breach at a critical supplier can become your breach, your customer notification, and your regulatory exposure, regardless of how well your own infrastructure was defended. Most vendor onboarding processes assess this only through a self-reported questionnaire, which reflects what a supplier believes about its own security, not an independent assessment of it.
An independent cyber risk assessment of a named critical supplier or vendor, covering exposed infrastructure, prior breach history, and security posture indicators visible from outside their organisation, to inform your own risk decision.
External attack surface and exposed infrastructure assessment
Prior breach and security incident history
Dark web exposure connected to the supplier's infrastructure or staff
Security posture indicators visible without requiring supplier cooperation
A clear risk rating to inform onboarding or continued reliance
External reconnaissance of the supplier's digital footprint, breach and incident history research, and dark web exposure screening, conducted independently of the supplier's own security self-assessment, with every finding verified by a named analyst before it is reported.
No. The assessment is built from externally observable information, so it does not depend on a supplier's willingness to participate or the accuracy of their self-reported questionnaire.
Yes, and where third-party risk needs managing across your full supplier base rather than one at a time, our Third-Party Risk Management as a Service programme is typically the better fit.
Findings are reported factually so you can decide how to proceed, whether that is requiring remediation, adjusting contractual security terms, or reconsidering the relationship.
Yes, through our Supply Chain Intelligence Monitoring subscription, which keeps this picture current across your defined supplier list.
This service focuses specifically on cyber security posture. Where general financial and corporate risk also needs assessing, our Corporate Intelligence capability's Vendor Intelligence Report covers that ground and can be scoped alongside this one.
Every enquiry is reviewed by an analyst and routed to a scoping call, a fixed fee is confirmed in writing before any work begins.