Third-Party & Vendor Risk

Your security is only as strong as the vendors you trust with your data. We assess the third parties you rely on and help you build a vendor risk program that's right-sized for your organization.

Why it matters

Many of today's breaches start with a vendor — a software provider, a managed service provider, or a contractor with access to your systems. Yet most organizations sign vendor contracts without ever looking closely at the vendor's security.

A vendor risk program doesn't have to be heavy. It needs to know which vendors matter most, ask the right questions of them, review the answers with an experienced eye, and make sure your contracts protect you.

Is this right for you?

This service is a good fit if:

  • You rely on vendors to store or process sensitive customer data
  • A framework, regulator, or customer requires third-party risk management
  • You need someone to review a vendor's SOC 2 report or security questionnaire
  • You're selecting a new critical vendor and want a security review before signing
  • You need to answer security questionnaires from your own customers

What's included

Vendor inventory and tiering

Identify your vendors and rank them by the data and access they have, so effort goes where it matters.

Security questionnaire design

A right-sized questionnaire for each vendor tier — no 300-question spreadsheets for low-risk vendors.

Due diligence reviews

Expert review of vendor questionnaires, SOC 2 reports, ISO certificates, and other evidence, with findings in plain language.

Contract security requirements

Recommended security, breach notification, and data protection language to discuss with your legal counsel.

Program and process build

Policy, workflow, and templates for onboarding, periodic review, and offboarding of vendors.

Answering your customers' questionnaires

Help completing the security questionnaires your own customers send you — accurately and consistently.

What you receive

  • Tiered vendor inventory
  • Vendor risk assessment reports with clear recommendations
  • Tiered questionnaire templates
  • Third-party risk management policy and procedure
  • Reusable security questionnaire answer library (if requested)

How it works

  1. 1

    Review

    Inventory vendors and understand what data and access each one has.

  2. 2

    Evaluate

    Tier vendors by risk and assess the critical ones in depth.

  3. 3

    Recommend

    Report findings and recommend actions, from contract terms to compensating controls.

  4. 4

    Enhance

    Put a repeatable program in place so new vendors are reviewed consistently.

Common questions

Can you review just one vendor?

Yes. Many clients start with a single review of a critical vendor before deciding whether they need a full program.

Can you help us answer questionnaires our customers send us?

Yes. We answer and review security questionnaires regularly and can help you build a reusable answer library so future questionnaires take hours, not weeks.

Do you write contract language?

We recommend security requirements and explain the risk behind them. Your attorney should finalize any contract language — we are happy to work alongside them.

Let's scope your project

Share a few details and we'll follow up within one business day to talk through your goals and put together a fixed-scope quote.

Request a scoped quote