Third-Party Risk Assessment
Systematic evaluation of supplier and partner cyber risk before it becomes your incident.
Your security posture is only as strong as your weakest supplier. Mitigence conducts structured third-party risk assessments — combining questionnaire review, evidence validation, and targeted technical spot-checks — to give you an accurate picture of supply chain exposure.
Engagement Phases
Vendor Scoping & Tiering
2–3 daysClassify vendors by data access, system integration depth, and criticality to assign appropriate assessment depth.
Questionnaire & Evidence Review
4–6 daysIssue and review standardised security questionnaires (based on SIG, CAIQ, or custom frameworks) and supporting evidence.
Technical Spot-Check
2–4 daysPerform targeted technical validation: OSINT, exposed surface analysis, certificate hygiene, and breach history review.
Risk Scoring & Analysis
2–3 daysScore each vendor against a consistent risk matrix and identify high-priority remediation or contractual actions.
Reporting & Recommendations
1–2 daysDeliver a prioritised vendor risk register with recommended contractual, technical, and monitoring actions.
What You Receive
- Vendor inventory and tiering classification
- Completed assessment evidence packs per vendor
- Risk-scored vendor register
- High-priority findings with recommended actions
- Third-party risk programme recommendations
- Executive summary for board-level reporting
Ready to scope this engagement?
Tell us about your environment and objectives — we'll map the approach to your context.