Risk & Compliance2–3 weeks

Third-Party Risk Assessment

Systematic evaluation of supplier and partner cyber risk before it becomes your incident.

Your security posture is only as strong as your weakest supplier. Mitigence conducts structured third-party risk assessments — combining questionnaire review, evidence validation, and targeted technical spot-checks — to give you an accurate picture of supply chain exposure.

RiskComplianceSupply ChainGRC

Engagement Phases

1

Vendor Scoping & Tiering

2–3 days

Classify vendors by data access, system integration depth, and criticality to assign appropriate assessment depth.

2

Questionnaire & Evidence Review

4–6 days

Issue and review standardised security questionnaires (based on SIG, CAIQ, or custom frameworks) and supporting evidence.

3

Technical Spot-Check

2–4 days

Perform targeted technical validation: OSINT, exposed surface analysis, certificate hygiene, and breach history review.

4

Risk Scoring & Analysis

2–3 days

Score each vendor against a consistent risk matrix and identify high-priority remediation or contractual actions.

5

Reporting & Recommendations

1–2 days

Deliver a prioritised vendor risk register with recommended contractual, technical, and monitoring actions.

What You Receive

  • Vendor inventory and tiering classification
  • Completed assessment evidence packs per vendor
  • Risk-scored vendor register
  • High-priority findings with recommended actions
  • Third-party risk programme recommendations
  • Executive summary for board-level reporting

Ready to scope this engagement?

Tell us about your environment and objectives — we'll map the approach to your context.

Schedule a call →