Third-Party Risk Assessment
Your vendors are your attack surface. One MSP push update encrypted 1,500 businesses β we help you not be one of them.
What we cover
- Vendor inventory: everyone with access, data, or code in your environment
- Access review: what each vendor can actually reach
- Security requirements and contractual review support
- Breach-history and exposure check per critical vendor
- Software supply chain exposure (dependencies, build systems)
- Ongoing monitoring plan for critical third parties
How we test
Map every third party with access or code in your environment, tiered by blast radius.
Per critical vendor: access scope, security posture, breach history, and dependency risk.
Least-privilege fixes for vendor access, offboarding stale integrations, tightening requirements.
A lightweight ongoing check cadence for the vendors that matter most.
What you get
- Tiered vendor inventory with blast-radius ratings
- Access-privilege fixes you can action immediately
- Security requirements template for contracts
- Ongoing monitoring plan for critical vendors
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote β no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix β included in the price, not an add-on.
See the full engagement process β and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
We already send vendor questionnaires β how is this different?
Questionnaires capture what vendors claim. This assessment looks at what they can actually touch in your environment and what happens when they are breached β the questions questionnaires do not answer.
Does this cover our software dependencies too?
Yes, as part of the blast-radius view: code, access, and data all count. For a deep technical pass on build pipelines, our supply chain assessment is the companion service.
How many vendors should we assess?
Start with the critical tier β typically ten to twenty. The point is depth where blast radius is largest, not checkbox coverage of hundreds.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation β a researcher replies.
Start the conversation β