The risk your suppliers bring in
Your hosting providers, the vendors behind your software: their security is already part of yours.
We are not going to rate your suppliers from the outside. We look at the ones already wired into your systems, starting with your hosting providers, then the vendors of the software you use, and we quantify what an attacker could reach by going through them.
Your suppliers are a way in
Since NIS2 and DORA, two European regulations that put your leadership on the hook, you are responsible for your suppliers' security, not only your own. For companies in the financial sector, DORA even requires keeping a register of your IT providers. But a signed questionnaire does not tell you what you lose if the attack comes through one of them.
The suppliers we already see in your systems
Your hosting providers
The infrastructure that hosts your sites and data counts as a provider under DORA. We measure its risk where it actually touches your data.
The vendors of your software
Every piece of software you use comes from a vendor. When one of its flaws sits on a real attack path, that risk becomes yours. We spot it in your environment.
What your suppliers claim about their security
Your suppliers' commitments and certificates enter the calculation as information to check against your reality, not as a box to tick.
No rating, no scanning of your suppliers
We do not scan your suppliers' internal systems and we do not hand them a score. We measure your own risk, through the ones already in your systems.
When a supplier opens several paths
A hosting provider or a software component sitting where several attack chains cross is what we call a pivot vulnerability: fixing it, hardening it or replacing it closes several threats at once. It is the same prioritization logic, extended to what enters through your suppliers.
The risk that comes through your suppliers
A supplier can be a way in. Treat their security as your own.
"For the first time, I can verify our provider's work and present our priorities to the board without translating. Leadership understands where the budget goes, and why."
Patrick Da FonsecaInfrastructure and Security Director, GaranceFrequently asked questions
Do you rate my suppliers, like a rating service?
No. A rating service judges your suppliers from the outside, with no link to your systems. We start from your own systems: what the supplier actually opens as an attack path to your data, quantified in euros.
Is this a supplier compliance tool?
No. We do not bring your suppliers into compliance and we do not tick boxes for them. We take what they declare, check it against your reality, and turn it into quantified risk.
Which suppliers do you actually see?
The ones already wired into your systems: the hosting providers of your sites and data, and the vendors of the software you use. We do not look at suppliers you neither host nor use.
Does NIS2 require quantifying supplier risk in euros?
No. NIS2 calls for measures proportionate to risk across your supply chain, with no figure. Quantifying in euros is required only in the financial sector, by DORA. We make it possible so the decision is defensible.
What happens to a supplier risk once found?
It enters the same prioritization as the rest: an attack path, a possible key flaw, a costed priority. A supplier sitting where several paths cross is treated as a pivot vulnerability.
See which suppliers open a way in
Let's talk about your hosting providers, your software vendors, and what an attacker could reach by going through them.
