How We Work
A clear path from first conversation to sustained assurance.
Scoped deliverables, fixed timelines and ongoing visibility — so cyber risk decisions keep pace with your supplier relationships.
Process
Our process, stage by stage
Each stage has a defined purpose and a defined output. You always know what happens next and what you will be holding at the end of it.
Step 01 — Discover
a short conversation to understand your supplier landscape, priorities and immediate risk questions.
We map who your critical third parties are, what data and processes they touch, and which risk questions are currently unanswered. Nothing is scoped or priced until that picture is clear.
Example deliverables
- Shared view of critical suppliers and dependencies
- Agreed risk questions the engagement must answer
- Recommended starting point and scope options
Step 02 — Assess
scope and deliver the right assessment, benchmark or review for the situation, with clear deliverables and a fixed timeline.
Assessments are time-boxed and benchmarked against recognised frameworks, so findings are comparable, defensible and directly usable in supplier conversations and board reporting.
Example deliverables
- Assessment or maturity benchmarking report with framework mapping
- Prioritised findings with risk ratings and owners
- Board-ready summary of exposure and recommended actions
Step 03 — Build
where needed, design and implement the governance, monitoring or bespoke solution that closes the gap.
We do not leave you with a list of findings to implement alone. Where a gap needs a control, a process or a tool, we design and build it alongside your team so ownership stays in-house.
Example deliverables
- Governance, procurement and control documentation
- Scoring models, dashboards or workflow automation
- Handover and capability transfer to named owners
Step 04 — Sustain
maintain visibility through continuous monitoring, reporting and advisory support as the relationship continues.
Supplier risk changes between reviews. Continuous monitoring through the M516 Platform keeps exposure and compliance gaps visible as they emerge, with reporting cadence agreed up front.
Example deliverables
- Continuous external exposure and compliance monitoring
- Agreed reporting cadence for risk and audit committees
- Ongoing advisory access as the supplier base changes
Engagement models
- Discovery Call
- a short, no-obligation conversation to understand your organisation’s or your strategic partners’ risk profile and where to start.
- Best for: organisations not yet sure where their supplier risk sits.
- Scoped Assessment
- a time-boxed assessment against your organisation, one supplier, one framework, or one business area.
- Best for: a specific supplier, framework or business area under scrutiny.
- Programme Delivery
- hands-on support building governance, compliance, monitoring or bespoke solutions into how your organisation already works.
- Best for: organisations that need capability built, not just findings reported.
- Managed Monitoring
- ongoing continuous monitoring, reporting and advisory support once the initial programme is in place, delivered through the M516 Platform.
- Best for: maintaining continuous readiness once a programme is in place.
Benchmarking
Assessed against recognised frameworks
Findings are mapped to established standards so they are comparable year on year and defensible in front of auditors, customers and boards.
Benchmarked Against
- NIST Cybersecurity Framework (CSF) 2.0
- NIST SP 800-161
- ISO/IEC 27001
- ISO/IEC 27002
- ISO/IEC 27005
- ISO/IEC 27036
- ISO/IEC 27701
- ISO/IEC 42001 (AI management systems)
- ISO 22301 (business continuity)
- NIS2 Directive
- DORA (where applicable)
- UK GDPR & Data Protection Act 2018
- NCSC Cyber Assessment Framework (CAF)
- Cyber Essentials / Cyber Essentials Plus
- CIS Controls
- SOC 2 (Trust Services Criteria)
Start with a conversation about your supplier landscape.
A short, no-obligation discovery call to understand your risk profile and where to start.