Skip to content
Talk to a Security Expert
CONSULTING / VENDOR & SUPPLY CHAIN

Third-Party Risk

Your security posture extends beyond the systems you directly control.

Modern operations run on other people's systems. Suppliers hold your data, integrations hold credentials into your environment, and platforms your team adopted without a procurement process hold more than anyone has counted.

Third-party risk work is about making that exposure visible and proportionate: knowing which relationships could actually hurt, and assessing those seriously rather than assessing all of them lightly.

// WHY IT MATTERS

A questionnaire everyone passes measures nothing

The common failure mode is a single questionnaire sent to every supplier regardless of what they can reach. It generates effort on both sides, everyone answers reassuringly, and the output does not distinguish between a design tool and a provider holding customer records.

Classification has to come first. What a vendor can access determines how much scrutiny the relationship deserves — and for most organizations a small number of relationships carry nearly all the exposure.

// STRUCTURE

How this is put together.

YOUR ORGVENDOR AVENDOR BCLOUDSAASPARTNERSUPPLIER
ASSESSCLASSIFYREVIEWPRIORITIZEMONITOR

Conceptual view. Review cadence is agreed per engagement — continuous vendor monitoring is not implied.

// WHAT THIS COVERS

What this covers

// METHODOLOGY

How the programme runs

  1. 01INVENTORYEstablish which third parties exist, including unofficial ones.
  2. 02CLASSIFYSort by access and by what a compromise would mean.
  3. 03ASSESSReview the relationships that carry real exposure.
  4. 04PRIORITIZEFocus remediation where it changes the risk picture.
  5. 05TRACKFollow issues through to closure.
  6. 06REVIEWReassess on an agreed cadence and on material change.
// WHEN THIS APPLIES

When Does Vendor Risk Become Your Risk?

01SITUATIONA critical vendor is being onboardedA supplier is about to be given access to systems or data that matter.
02SITUATIONVendor count grew quietlySaaS accumulated team by team, and no single view of that exposure exists.
03SITUATIONA supplier had an incidentSomething happened at a third party and you need to establish your own exposure.
04SITUATIONCustomers are asking about your chainYour buyers now assess your suppliers as part of assessing you.
// WHAT YOU RECEIVE

Output leadership can act on.

Which of these apply depends on engagement scope.

GAP ASSESSMENT

Where current practice differs from the requirements that apply to you.

CONTROL MAPPING

Which controls address which requirements, and where nothing does.

RISK OBSERVATIONS

What the gaps mean in terms of risk, not just non-conformity.

POLICY / DOCUMENTATION GUIDANCE

What needs to exist in writing, and what it needs to say.

EVIDENCE READINESS

Whether you could demonstrate a control operates, if asked.

REMEDIATION ROADMAP

Sequenced work, with dependencies made explicit.

MANAGEMENT-LEVEL INSIGHTS

A version of the findings that a board or exec team can act on.

// FREQUENTLY ASKED

Questions we get asked before an engagement.

Discuss Third-Party Risk

Start with the suppliers that hold your data or reach your systems. That list is usually shorter, and more alarming, than expected.