Third-Party Risk Assessment

Your vendors are your attack surface. One MSP push update encrypted 1,500 businesses β€” we help you not be one of them.

Why this matters: Attackers stopped attacking targets and started attacking their suppliers: one firewall vendor’s compromised update exposed 74 banks; one MSP tool pushed ransomware to 1,500 downstream businesses. We have documented these campaigns in depth β€” this service turns that research into a structured review of who has access to your environment and what they can really do with it.

What we cover

  • Vendor inventory: everyone with access, data, or code in your environment
  • Access review: what each vendor can actually reach
  • Security requirements and contractual review support
  • Breach-history and exposure check per critical vendor
  • Software supply chain exposure (dependencies, build systems)
  • Ongoing monitoring plan for critical third parties

How we test

1Inventory & tiering

Map every third party with access or code in your environment, tiered by blast radius.

2Assess

Per critical vendor: access scope, security posture, breach history, and dependency risk.

3Reduce

Least-privilege fixes for vendor access, offboarding stale integrations, tightening requirements.

4Monitor

A lightweight ongoing check cadence for the vendors that matter most.

What you get

  • Tiered vendor inventory with blast-radius ratings
  • Access-privilege fixes you can action immediately
  • Security requirements template for contracts
  • Ongoing monitoring plan for critical vendors

The engagement at a glance

πŸ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote β€” no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

πŸ” Retest included

A verification pass over everything you fix β€” included in the price, not an add-on.

See the full engagement process β†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

We already send vendor questionnaires β€” how is this different?

Questionnaires capture what vendors claim. This assessment looks at what they can actually touch in your environment and what happens when they are breached β€” the questions questionnaires do not answer.

Does this cover our software dependencies too?

Yes, as part of the blast-radius view: code, access, and data all count. For a deep technical pass on build pipelines, our supply chain assessment is the companion service.

How many vendors should we assess?

Start with the critical tier β€” typically ten to twenty. The point is depth where blast radius is largest, not checkbox coverage of hundreds.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement β€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation β€” a researcher replies.

Start the conversation β†’