See The Risk Your Suppliers
Carry Into Your Business

A weakness in a vendor becomes your incident, and increasingly your regulatory finding. IrisInfosec builds the third-party risk programme that keeps that from being a surprise: a tiered vendor inventory, real due diligence, continuous monitoring, and the ICT registers and contractual terms DORA and NIS2 now expect.

Tiered

Vendors ranked by criticality, not treated alike.

DORA

ICT third-party register and contractual terms built in.

4th-party

Concentration risk mapped beyond your direct vendors.

Continuous

Monitoring, not a once-a-year questionnaire.

What this covers

Your Perimeter Now Includes Your Suppliers

Most organisations depend on dozens or hundreds of vendors, and an attacker only needs the weakest one. Regulators have noticed: NIS2 makes supply chain security a duty, and DORA sets detailed expectations for how financial entities oversee their ICT providers.

The work is to know who you rely on, how critical each one is, and what would happen if one failed, then to hold the right controls and the right records. We build that, and keep it watching rather than filed away.

In one line

Third-party and supply chain risk management

is the work of identifying, assessing and monitoring the risk your vendors introduce, and controlling it through due diligence, contracts and continuous oversight.

What we build

A Programme That Watches, Not Just Audits

The components that move third-party risk from an annual questionnaire to live
oversight.

Vendor Inventory & Tiering

A complete register of suppliers, ranked by how critical they are, so effort goes where the real exposure is.

Due Diligence & Assessment

Risk-based assessment of each vendor’s security and compliance, sized to their tier rather than one size fits all.

Continuous Monitoring

Ongoing signals on your critical vendors, so a material change in posture surfaces between review cycles.

ICT Third-Party Register

The register of information DORA requires, built and kept current, with the contractual terms it expects.

Concentration & Fourth-Party

Mapping of shared dependencies and your vendors’ vendors, so systemic exposure does not hide one layer down.

Contracts & Exit Planning

The security clauses, right-to-audit terms and exit plans that let you hold vendors to account and leave cleanly.

Where teams fall short

DORA And NIS2 Supply Chain Duties

Most programmes cover the obvious vendor questionnaire. The detail the regulations actually ask for is where gaps appear.

Duty What the regulation expects
ICT register (DORA) A maintained register of information on all ICT third-party arrangements
Contractual terms (DORA) Specific clauses on access, audit, sub-outsourcing and exit
Concentration risk (DORA) Assessment of over-reliance on critical providers
Supply chain security (NIS2) Supplier security considered within your risk management measures
Oversight of criticals Closer, ongoing monitoring of your most important providers

How we work

From Vendor List To Live Oversight

A measured approach that builds a programme your teams can actually run.

01

Inventory

Build a complete, deduplicated register of every vendor and ICT provider you depend on.

02

Tier & Assess

Rank vendors by criticality and run due diligence sized to each tier.

03

Contract & Control

Put the right clauses, registers and controls in place, aligned to DORA and NIS2.

04

Monitor

Stand up continuous monitoring and a cadence of reassessment for critical vendors.

05

Respond & Exit

Playbooks for vendor incidents and exit, so a supplier problem does not become a crisis.

What you receive

The Register And The Records Regulators Ask For

The inventory, the DORA register and the playbooks your teams and your supervisor will both
ask to see.

Vendor Register & Tiering

A maintained inventory with criticality tiers, owners and the assessment status of each supplier.

DORA ICT Register

The register of information in the form DORA requires, ready for your supervisor on request.

Policy, Clauses & Playbooks

A third-party risk policy, model contract clauses, and incident and exit playbooks your teams can use.

Know your suppliers before an incident does

Get A Tiered View Of Your Vendor Risk

Share your vendor landscape and the regulations you fall under. We will tier the risk
and send a prioritised plan, including the DORA register where it applies.

Questions, answered

Third-Party Risk FAQ

Third-party risk management is the process of identifying, assessing and monitoring the risk your vendors and suppliers introduce, then controlling it through due diligence, contracts and ongoing oversight. It matters because a weakness in a supplier can become your breach, and several regulations now hold you accountable for it.

DORA requires EU financial entities to maintain a register of information on all ICT third-party arrangements, apply specific contractual terms, assess concentration risk, and oversee critical providers closely. Many programmes focus only on the financial entity, so the ICT third-party register and the contractual detail are where teams most often fall short.

NIS2 makes supply chain security an explicit duty. Essential and important entities must consider the security of their suppliers and service providers as part of their risk management measures, including the quality of products and the security practices of direct suppliers.

Fourth-party risk is the risk from your suppliers’ own suppliers, the parties you do not contract with directly but still depend on. Concentration on a shared cloud or software provider several layers down can create systemic exposure, which is why mapping beyond your direct vendors matters.

Tier your vendors by criticality and reassess accordingly: critical providers at least annually and on significant change, lower-tier vendors less often. Pair periodic assessment with continuous monitoring so a material change in a supplier’s posture does not wait for the next review cycle.

Related services

Make Supplier Risk Something You Watch, Not Fear

Book a call with an advisor who knows the DORA and NIS2 detail. We
tier your vendor risk and send a prioritised plan, no obligation.