Resources
Practical guides to vendor risk and supply chain security
Methods, checklists and field lessons for building a third-party risk programme: due diligence, questionnaires, concentration risk, vendor incidents, fourth parties.
These guides are written for the teams actually running a third-party risk programme: CISOs, risk managers, DPOs and compliance leads. Each one starts from a concrete problem, offers a workable method and cites its sources.
Fourth-party risk
Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.
Read moreQuestionnaire fatigue
Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.
Read moreSupply chain attack
How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.
Read moreConcentration & SPOF
How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.
Read moreDue diligence
How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.
Read moreIncident playbook
What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.
Read more
FAQ
If your programme is new, start with vendor cyber due diligence, then security questionnaire fatigue. If it is already running, the concentration risk and fourth-party guides cover the most common blind spots.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours