CyberTrustWorks — One Platform. Total Trust.
Supply-chain assurance

Third-Party Cyber Risk

Identify, prioritise and govern cyber risk introduced by suppliers, processors and technology partners.

Business priority

A complete view of critical supplier exposure

Business priority

Consistent decisions backed by evidence

Discuss your requirements

Free consultation

Talk to a security specialist

Tell us where you need support. We reply within one business day.

Our third-party risk programme combines due diligence, risk-tiering, contract controls and continuous review so effort is focused on vendors that can genuinely affect your business.

The engagement begins with business context, not a checklist. Our specialists work with leadership, technology and operational owners to understand what must be protected, where the most credible exposure exists and which improvements will make a measurable difference. Recommendations account for existing investments, delivery capacity and regulatory commitments.

Where we focus first

Turn complex exposure into clear decisions

Vendor inventory and risk tiering

We establish current exposure, responsible owners and the next defensible action.

Security assessments and evidence review

We establish current exposure, responsible owners and the next defensible action.

Contract and data-processing security clauses

We establish current exposure, responsible owners and the next defensible action.

What we cover

Capabilities built around your risk

Every workstream combines evidence review, stakeholder interviews and hands-on validation. This creates a reliable view of both control design and how controls perform in day-to-day operations.

Vendor inventory and risk tiering

We examine vendor inventory and risk tiering in the context of your technology, business processes and threat exposure. Findings are validated with owners and converted into prioritised actions with clear accountability.

Security assessments and evidence review

We examine security assessments and evidence review in the context of your technology, business processes and threat exposure. Findings are validated with owners and converted into prioritised actions with clear accountability.

Contract and data-processing security clauses

We examine contract and data-processing security clauses in the context of your technology, business processes and threat exposure. Findings are validated with owners and converted into prioritised actions with clear accountability.

Critical supplier deep dives

We examine critical supplier deep dives in the context of your technology, business processes and threat exposure. Findings are validated with owners and converted into prioritised actions with clear accountability.

Continuous monitoring and reassessment

We examine continuous monitoring and reassessment in the context of your technology, business processes and threat exposure. Findings are validated with owners and converted into prioritised actions with clear accountability.

Concentration and fourth-party risk analysis

We examine concentration and fourth-party risk analysis in the context of your technology, business processes and threat exposure. Findings are validated with owners and converted into prioritised actions with clear accountability.

How we deliver

A clear path from risk to control

01

Inventory

Identify suppliers, data access, business dependency and inherent risk.

You receive documented decisions, named owners and evidence of progress at this stage.

02

Assess

Apply proportionate due diligence and validate evidence for critical relationships.

You receive documented decisions, named owners and evidence of progress at this stage.

03

Monitor

Track issues, changes and renewal decisions through an owned governance cycle.

You receive documented decisions, named owners and evidence of progress at this stage.

What you receive

Clear evidence, not just advice

Engagement deliverables

  • Supplier inventory and tiering methodology
  • Risk-based assessment questionnaires
  • Evidence-review and findings reports
  • Contractual security requirement library
  • Exception, remediation and reassessment workflow

Best suited for

  • Businesses dependent on critical SaaS and processors
  • Procurement teams needing proportionate assurance
  • Regulated organisations governing supply-chain risk

What changes

Practical business outcomes

  • A complete view of critical supplier exposure
  • Consistent decisions backed by evidence
  • Faster onboarding for lower-risk vendors
  • Clear remediation and acceptance records

How success is measured

We agree practical measures at the start of the engagement, then track risk reduction, control adoption, evidence quality and accountable closure. Leadership receives a concise view of progress, residual exposure and decisions requiring support.