A weakness in a vendor becomes your incident, and increasingly your regulatory finding. IrisInfosec builds the third-party risk programme that keeps that from being a surprise: a tiered vendor inventory, real due diligence, continuous monitoring, and the ICT registers and contractual terms DORA and NIS2 now expect.
Most organisations depend on dozens or hundreds of vendors, and an attacker only needs the weakest one. Regulators have noticed: NIS2 makes supply chain security a duty, and DORA sets detailed expectations for how financial entities oversee their ICT providers.
The work is to know who you rely on, how critical each one is, and what would happen if one failed, then to hold the right controls and the right records. We build that, and keep it watching rather than filed away.
Third-party and supply chain risk management
is the work of identifying, assessing and monitoring the risk your vendors introduce, and controlling it through due diligence, contracts and continuous oversight.
What we build
The components that move third-party risk from an annual questionnaire to live
oversight.
A complete register of suppliers, ranked by how critical they are, so effort goes where the real exposure is.
Risk-based assessment of each vendor’s security and compliance, sized to their tier rather than one size fits all.
Ongoing signals on your critical vendors, so a material change in posture surfaces between review cycles.
The register of information DORA requires, built and kept current, with the contractual terms it expects.
Mapping of shared dependencies and your vendors’ vendors, so systemic exposure does not hide one layer down.
The security clauses, right-to-audit terms and exit plans that let you hold vendors to account and leave cleanly.
Where teams fall short
Most programmes cover the obvious vendor questionnaire. The detail the regulations actually ask for is where gaps appear.
| Duty | What the regulation expects | |
|---|---|---|
| ICT register (DORA) | A maintained register of information on all ICT third-party arrangements | |
| Contractual terms (DORA) | Specific clauses on access, audit, sub-outsourcing and exit | |
| Concentration risk (DORA) | Assessment of over-reliance on critical providers | |
| Supply chain security (NIS2) | Supplier security considered within your risk management measures | |
| Oversight of criticals | Closer, ongoing monitoring of your most important providers |
How we work
A measured approach that builds a programme your teams can actually run.
Build a complete, deduplicated register of every vendor and ICT provider you depend on.
Rank vendors by criticality and run due diligence sized to each tier.
Put the right clauses, registers and controls in place, aligned to DORA and NIS2.
Stand up continuous monitoring and a cadence of reassessment for critical vendors.
Playbooks for vendor incidents and exit, so a supplier problem does not become a crisis.
What you receive
The inventory, the DORA register and the playbooks your teams and your supervisor will both
ask to see.
A maintained inventory with criticality tiers, owners and the assessment status of each supplier.
The register of information in the form DORA requires, ready for your supervisor on request.
A third-party risk policy, model contract clauses, and incident and exit playbooks your teams can use.
Know your suppliers before an incident does
Share your vendor landscape and the regulations you fall under. We will tier the risk
and send a prioritised plan, including the DORA register where it applies.
Questions, answered
Related services