Third Party Risk Management
Every vendor, supplier and partner with access to your systems or data is an extension of your attack surface. If they get compromised, you get compromised. Some of the most damaging breaches in recent years started not with the target organisation but with a supplier who had access to their environment.
Razorthorn’s third party risk management service gives you an independent, expert assessment of your suppliers’ security posture. We evaluate their controls against recognised benchmarks including CIS, NIST and Cyber Essentials, and review evidence of certifications such as ISO 27001. No automated questionnaires, no tick box exercises. Our consultants conduct thorough assessments including remote and on-site evaluation.
We have been delivering cyber security consultancy since 2007, working with organisations ranging from Fortune 500 companies to mid-market businesses across regulated industries. Our third party assessments support compliance with DORA, NIS2, ISO 27001 and PCI DSS, all of which now include specific requirements around supply chain security.
Talk to us about Third Party Security
Please leave a few contact details and one of our team will get back to you.
What is third party risk management?
Third party risk management is the process of identifying, assessing and managing the security risks that come from your external suppliers, vendors and service providers. Any organisation that has access to your data, connects to your systems or delivers services that your business depends on is a third party, and their security weaknesses can become your problem.
This matters because attackers know that suppliers are often the easier route in. Rather than attacking a well defended organisation directly, they compromise a supplier with weaker controls and use that access to reach the real target. Regulations including DORA, NIS2 and ISO 27001 now explicitly require organisations to assess and manage third party security risk, making it a compliance requirement as well as a security one.
How does Razorthorn assess third party security risk?
1. Scoping and documentation gathering
We work with you to define which third parties to assess and what level of assessment each one needs. We then gather documentation from your suppliers including security policies, procedures, risk management frameworks, technical configuration logs and evidence of controls such as continuous monitoring, vulnerability management, configuration management, access controls and staff training programmes.
2. Assessment and evaluation
Our consultants carry out a thorough assessment of each supplier’s security posture. This includes evaluation against benchmarks such as CIS, NIST and Cyber Essentials, review of certifications like ISO 27001, examination of their vendor management processes and their security operations including SOC activities. Assessments involve interviews with key personnel, review of technical documentation and a combination of remote and on-site meetings conducted over several days.
3. Reporting and recommendations
You receive a detailed report for each assessed supplier with an executive summary, findings categorised by severity (critical, high, medium, low) and practical recommendations for risk mitigation. We follow up with a debrief session to walk through the results and agree next steps. Findings are prioritised so your team knows exactly what to address first.
How does third party risk management support compliance?
Several major regulations and standards now require organisations to assess and manage the security risk in their supply chain. Razorthorn’s third party risk management service directly supports these requirements:
DORA
The Digital Operational Resilience Act requires financial institutions to identify all ICT third party service providers, assess their risk, maintain a register of outsourcing arrangements and conduct regular reviews. Our assessments provide the independent evaluation and documentation that DORA demands.
NIS2
NIS2 requires operators of essential and important services to manage supply chain security risks and ensure their suppliers meet appropriate security standards. Our assessments evaluate your suppliers against recognised frameworks and provide evidence for your NIS2 compliance programme.
ISO 27001
ISO 27001 Annex A includes controls specifically covering supplier relationships (A.5.19 to A.5.23). Our assessments help you meet these requirements by providing documented, structured evaluation of your suppliers’ information security practices. For organisations subject to GDPR, our assessments also cover how suppliers handle personal data and whether appropriate data processing agreements and controls are in place.
PCI DSS
PCI DSS Requirement 12.8 requires organisations to maintain and implement policies for managing service providers with whom cardholder data is shared. Our assessments evaluate whether your payment processing partners and related suppliers meet the necessary security standards.
Frequently asked questions about third party risk management
What is third party risk management?
Third party risk management is the process of identifying, assessing and managing the security risks introduced by your external suppliers, vendors and service providers. It covers any organisation that has access to your data, connects to your systems or delivers services your business depends on.
Why is third party risk management important?
Attackers frequently target suppliers as an easier route into well defended organisations. Regulations including DORA, NIS2, ISO 27001 and PCI DSS now explicitly require organisations to assess and manage third party security risk. Beyond compliance, understanding your suppliers’ security posture is essential for protecting your own data and systems.
What frameworks do you assess against?
We evaluate suppliers against recognised benchmarks including CIS, NIST and Cyber Essentials, and review evidence of certifications such as ISO 27001. The assessment is tailored to your industry and regulatory requirements, so the standards used reflect what matters most for your organisation.
How long does a third party risk assessment take?
It depends on the number of suppliers being assessed and the depth of assessment required. A single supplier assessment typically takes several days including documentation review, remote evaluation and on-site meetings. We agree the scope and timeline during the initial scoping call.
How much does third party risk management cost?
Pricing depends on the number of suppliers, the depth of assessment and whether on-site visits are required. Contact us for a scoping call and we will provide a quote based on your specific requirements.
Do you use automated questionnaires?
No. Our assessments are conducted by experienced security consultants, not automated tools. While questionnaires are part of the documentation gathering process, the actual assessment involves detailed analysis, remote meetings and on-site evaluation. This is how you find the issues that automated tools miss.
Can you assess suppliers who are overseas?
Yes. We assess suppliers regardless of location. Assessments are conducted through a combination of remote review and on-site visits where appropriate. For international suppliers, remote assessment is often the primary method with on-site evaluation available when the risk profile justifies it.
Does this service help with DORA compliance?
Yes. DORA requires financial institutions to identify, assess and monitor ICT third party service providers. Our assessments provide the independent evaluation and documentation that DORA demands. We can also support the creation and maintenance of your ICT third party register.
Can this service be included in a CISO as a Service retainer?
Yes. Third party risk management support is included in the Medium and Large Business CISO as a Service retainer packages. If you need ongoing supplier assessment as part of a broader security programme, CISOaaS may be a more cost effective way to access it.
Looking for related services?
Third Party Risk Management works alongside several of our other services to build a complete security programme:




