Governance, Risk & Compliance

Third-Party Cyber Risk Management

Manage security exposure across suppliers, cloud providers and critical partners.

Engagement focus

A tiered vendor-risk programme covering due diligence, contracting, monitoring and exit requirements.

A tiered vendor-risk programme covering due diligence, contracting, monitoring and exit requirements.

Typical deliverables

  • Vendor tiering model
  • Assessment questionnaires
  • Security clauses
  • Ongoing monitoring process

Intended outcomes

  • Supply-chain visibility
  • Risk-based reviews
  • Stronger contracts
Typical deliverables

What an engagement may produce.

  • ✓ Vendor tiering model
  • ✓ Assessment questionnaires
  • ✓ Security clauses
  • ✓ Ongoing monitoring process
Intended outcomes

What the work is designed to improve.

  • ✓ Supply-chain visibility
  • ✓ Risk-based reviews
  • ✓ Stronger contracts
Plan the right scope

Connect the requirement to business context.

We will help clarify the objective, dependencies, authorised activity and useful evidence.

Start a conversation