Third-Party Risk
Your security posture extends beyond the systems you directly control.
Modern operations run on other people's systems. Suppliers hold your data, integrations hold credentials into your environment, and platforms your team adopted without a procurement process hold more than anyone has counted.
Third-party risk work is about making that exposure visible and proportionate: knowing which relationships could actually hurt, and assessing those seriously rather than assessing all of them lightly.
A questionnaire everyone passes measures nothing
The common failure mode is a single questionnaire sent to every supplier regardless of what they can reach. It generates effort on both sides, everyone answers reassuringly, and the output does not distinguish between a design tool and a provider holding customer records.
Classification has to come first. What a vendor can access determines how much scrutiny the relationship deserves — and for most organizations a small number of relationships carry nearly all the exposure.
How this is put together.
Conceptual view. Review cadence is agreed per engagement — continuous vendor monitoring is not implied.
What this covers
SCOPE OF SERVICEAssessment and advisory support. Continuous or automated vendor monitoring is not implied — review cadence is agreed per engagement.
How the programme runs
- 01INVENTORYEstablish which third parties exist, including unofficial ones.
- 02CLASSIFYSort by access and by what a compromise would mean.
- 03ASSESSReview the relationships that carry real exposure.
- 04PRIORITIZEFocus remediation where it changes the risk picture.
- 05TRACKFollow issues through to closure.
- 06REVIEWReassess on an agreed cadence and on material change.
When Does Vendor Risk Become Your Risk?
Output leadership can act on.
Which of these apply depends on engagement scope.
Where current practice differs from the requirements that apply to you.
Which controls address which requirements, and where nothing does.
What the gaps mean in terms of risk, not just non-conformity.
What needs to exist in writing, and what it needs to say.
Whether you could demonstrate a control operates, if asked.
Sequenced work, with dependencies made explicit.
A version of the findings that a board or exec team can act on.
Adjacent parts of the programme.
Questions we get asked before an engagement.
Fewer, more thoroughly. Most organizations find that a small number of relationships carry the bulk of the exposure, and depth on those beats a shallow pass across everything.
Not by default, and we would not imply otherwise. Assessment is point-in-time unless a review cadence is explicitly agreed. Anyone offering genuine continuous monitoring is describing a different product with different limitations.
That is itself a finding, and a useful one. Where a supplier will not provide assurance, the question becomes whether the access they hold is proportionate to the visibility you are given — which is a commercial decision informed by a security view.
We can advise on the security expectations worth including, but contract drafting and legal terms are matters for legal counsel. We stay on the security side of that line.
Discuss Third-Party Risk
Start with the suppliers that hold your data or reach your systems. That list is usually shorter, and more alarming, than expected.
