Cookies Privacy
I accept Cookies Policy We use cookies to understand how you use our website and to improve your experience. By continuing to use this website, you accept our Link is copied!

Third-Party Cyber Risk Management

Third-party cyber-risk management helps organisations identify which suppliers can materially affect security or resilience and apply proportionate controls throughout the relationship lifecycle. The service supports procurement, risk, legal, security and business owners that need consistent supplier decisions instead of one-size-fits-all questionnaires.

What you gain from this engagement?

It exists to move you from regulatory uncertainty to decisions with clear owners, budget and evidence.

  • Create a reliable inventory and risk tiering of suppliers.
  • Focus due diligence on material access, data and service dependencies.
  • Translate assessment findings into contracts and remediation actions.
  • Monitor changes, incidents and concentration risk over time.
  • Strengthen termination, transition and exit readiness.

Assessment scope and outputs

The exact boundaries are settled before the engagement begins. Depending on the objective, environment and authorised access, the engagement may cover:

  • Supplier inventory, ownership and criticality criteria.
  • Pre-contract cybersecurity due diligence.
  • Data, access, hosting, subcontractor and operational dependencies.
  • Contract clauses, notification, audit and evidence rights.
  • Risk acceptance and remediation governance.
  • Ongoing monitoring and reassessment triggers.
  • Concentration, geographic and fourth-party considerations.
  • Offboarding, access removal, data return and exit planning.

How the engagement works?

Define governance, tiering, evidence standards, decision rights and integration with procurement.

1. Design the programme:

Assess business criticality, data sensitivity, technical access and substitutability.

2. Classify suppliers:

Use targeted evidence and validation rather than relying only on self-declared questionnaires.

3. Perform proportionate due diligence:

Assign remediation, exceptions, clauses and acceptance decisions.

4. Agree treatment and contracts:

Set reassessment triggers, incident coordination and termination controls.

5. Monitor and exit safely:

Your deliverables

Reports serve decision-makers and implementation teams alike. Depending on scope, they may include:

  • Third-party cyber-risk policy and operating model.
  • Supplier inventory and risk-tiering method.
  • Due-diligence questionnaires and evidence standards.
  • Assessment reports and decision records.
  • Security contract-clause library.
  • Remediation, exception and monitoring tracker.
  • Concentration and exit-risk observations.

Governance and quality control

CTG confirms the decision to be supported, the evidence threshold, responsible stakeholders and the distinction between advisory work, implementation, legal interpretation and independent assurance. Findings are linked to owners, dependencies and measurable next actions.

When organisations engage us?

  • Supplier assessments are inconsistent or duplicated.
  • Critical providers have broad access or process sensitive data.
  • NIS2, DORA or customer requirements increase supply-chain scrutiny.
  • Procurement lacks clear approval and exception rules.
  • The organisation depends heavily on a small number of ICT providers.
  • Exit plans and access removal are not tested.

Standards, timing and service boundaries

The engagement may draw on ISO/IEC 27036, NIST Cybersecurity Supply Chain Risk Management guidance, NIS2 and DORA requirements where applicable. Naming a framework indicates our approach; it does not constitute certification, accreditation or a regulatory decision.

 

Duration is agreed after scoping and depends on environment size, available evidence and stakeholder availability.

 

A supplier assessment is a point-in-time risk decision based on available evidence. It does not guarantee that the supplier is secure or continuously compliant. Legal review is required for contractual language, regulatory interpretation and cross-border issues.

Discuss Third-Party Cyber Risk Management with CTG. We start with a scoping conversation to fix the objective, limits, evidence, delivery model and deliverables ahead of any proposal.

Related services

Frequently asked questions

What does Third-Party Cyber Risk Management cover?

The exact boundaries are settled before the engagement begins. Typical areas include supplier inventory, ownership and criticality criteria, Pre-contract cybersecurity due diligence, Data, access, hosting, subcontractor and operational dependencies, and Contract clauses, notification, audit and evidence rights. Scope limits, access needs, client responsibilities and acceptance criteria are captured in the proposal.

What will we receive at the end of the engagement?

Deliverables depend on the agreed objective and may include third-party cyber-risk policy and operating model, Supplier inventory and risk-tiering method, Due-diligence questionnaires and evidence standards, and Assessment reports and decision records. Findings are traceable to evidence, impact, priority and the person responsible for acting.

What evidence should we prepare?

CTG normally requests the policies, registers, governance records, technical evidence and previous assessments relevant to the agreed scope. The evidence request is tailored so that the customer does not collect material that will not be used.

Does this service provide legal advice or certification?

No. CTG provides cybersecurity assessment and implementation support within the agreed scope. Formal legal interpretation, statutory assurance and accredited certification remain separate.

How long does the engagement take?

Duration is agreed after scoping and depends on environment size, available evidence and stakeholder availability.

How does this relate to DORA Operational Resilience Programme?

The two cover connected yet different problems. Scoping identifies whether Third-Party Cyber Risk Management, DORA Operational Resilience Programme, or a coordinated programme is the smallest useful approach without duplicating work.

What are the principal limitations?

A supplier assessment is a point-in-time risk decision based on available evidence. It does not guarantee that the supplier is secure or continuously compliant. Legal review is required for contractual language, regulatory interpretation and cross-border issues.