Professional Services
Increasingly, organisations rely on third parties in order to meet their business goals. These third parties can play various roles in the supply chain such as providing products, managing assets or delivering Software as a Service solutions.
It is therefore critical that organisations regularly review their risk profile as associated with the use of these external parties, who handle customer information, financials, Personally Identifiable Information (PII), and Protected Health Information (PHI). Key to this is to identify, assess, mitigate, and continuously monitor third party information security risk in line with the enterprise-wide risk framework.
Enterprise risk frameworks that encompass third party information security risk, and overall best practice in line with internal policy and international standards such as ISO31000 and ISO27005, are important in complying with the regulatory requirements and overall management of third party information security risk.
The Kaon Security team have the capability to assist organisations with a comprehensive Third Party Cyber Risk Assessment service.
Assists the organisation to build their third party risk profile
Develop mitigations for third party information security risks
Integrates third party information security risk into enterprise risk
Helps to identify information security gaps in the third party’s environment
Third party risk assessment workshop
Third party cyber risk assessment process (draft)
3 completed third party cyber risk assessments
Report highlighting gaps and recommendations for improvement
Working with suppliers and partners can create new risks. Here are some of the most common questions we hear about Third Party Cyber Risk Management, with clear answers to guide you.
Third Party Cyber Risk Management is the process of identifying, assessing, and reducing the cyber security supply chain risks posed by external suppliers, vendors, contractors, and service providers. Any organisation that connects to your systems, handles your data, or supports your operations can introduce vulnerabilities that need to be understood and managed.
A significant number of cyber incidents and data breaches stem from weaknesses in the supply chain. Even with strong internal security, a vulnerable supplier can be an entry point for attackers. Managing these risks helps you:
Our service provides a clear view of supplier-related risks and how to address them. This typically includes:
We use a governance-focused approach, considering:
Assessments may include documentation reviews, stakeholder interviews, and evaluation against frameworks such as ISO 27001, ISO 27036, and NIST.
Yes. We categorise your suppliers by risk and criticality, helping you focus on those who present the highest risk to your organisation. This targeted approach ensures resources are used efficiently while maintaining appropriate oversight across your supply chain.
Yes. We deliver a clear, structured risk register that documents key supplier risks, their potential business impact, and recommended actions for mitigation, monitoring, or further review. This becomes a practical tool for managing ongoing supplier oversight.
Supplier risk management is required under many frameworks and regulations, including:
Our process aligns with these standards, helping you demonstrate due diligence and meet audit, regulatory, and contractual expectations.
We assess suppliers and service providers such as: