Cybersecurity governance and leadership

Third-party risk (TPRM)

Management of supplier and third-party risk across the entire lifecycle.

What it involves

What we do

Your suppliers are part of your attack surface and of your regulatory obligations. We design and run the third-party risk programme: classification, assessment, contract clauses, monitoring and exit.

What's included

  • Supplier inventory and classification by criticality
  • Assessment questionnaires and evidence review
  • Contractual security and continuity clauses
  • Register of information on ICT providers (DORA)
  • Continuous monitoring and exit plans
  • Due diligence in corporate transactions

Who it's for

  • Financial entities subject to DORA
  • Essential and important entities under NIS2
  • Organisations with a complex technology supply chain

Deliverables

  • TPRM programme
  • Supplier and risk register
  • Assessment reports per supplier

Reference frameworks and standards

DORANIS2ISO 27036ISO 27001ENS

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does Third-party risk (TPRM) fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.