Digital Supply Chain Cyber Risk
Third-Party Cyber Risk Assessments
Know exactly where your suppliers expose you.
What this is
Know exactly where your suppliers expose you.
A time-boxed, independent assessment of the suppliers that matter most, benchmarked against recognised frameworks so findings are comparable, defensible and usable in supplier conversations.
What you get
- Critical supplier scope agreed before work begins
- Assessment report with framework mapping and risk ratings
- Prioritised findings with named owners and remediation actions
- Board-ready summary of exposure
Best for
Organisations that need a clear answer on where supplier risk actually sits.
See how an engagement runs →Benchmarked Against
- NIST Cybersecurity Framework (CSF) 2.0
- NIST SP 800-161
- ISO/IEC 27001
- ISO/IEC 27002
- ISO/IEC 27005
- ISO/IEC 27036
- ISO/IEC 27701
- ISO/IEC 42001 (AI management systems)
- ISO 22301 (business continuity)
- NIS2 Directive
- DORA (where applicable)
- UK GDPR & Data Protection Act 2018
- NCSC Cyber Assessment Framework (CAF)
- Cyber Essentials / Cyber Essentials Plus
- CIS Controls
- SOC 2 (Trust Services Criteria)
Talk to us about scoping this service.
A short, no-obligation discovery call to understand your risk profile and where to start.