
Third-Party and Supply Chain Risk
Your suppliers hold your data and reach your systems. This is how you keep that safe.
Your suppliers hold your data and reach your systems. This is how you keep that safe.
How this is bought: Bought as an assessment first, then a project priced from what the assessment finds. Build an estimate for your case.
Ranking suppliers by the damage a failure at their end would cause.
A short questionnaire for low risk, evidence review for critical suppliers.
Breach notification windows, right to audit, data location and deletion on exit.
Knowing who your suppliers depend on in turn.
Watching for breaches and posture changes at critical suppliers.
We follow the structure and controls these standards describe. We do not claim to be certified against them - where you need a formal certificate, we prepare the evidence and an accredited body performs the audit.
These are the areas clients most often ask us to improve. Your project sets its own targets, measured and agreed with you.