Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Managed Security

Third-party risk management, tiered by what a vendor can reach.

Third party risk management services fail in a predictable way: every supplier gets the same 200-question spreadsheet, nobody reads the answers, and the small analytics tool with a live API token into your production database is assessed with the same rigour as the office stationery account.

Risk is not proportional to invoice value. It is proportional to what the vendor can reach (your data, your network, your customers, your ability to operate) and to how quickly you would notice if they were compromised. Tiering on that basis is what makes the programme sustainable, because it concentrates the effort where it changes something.

We build the register, tier the population, run proportionate diligence, get the security terms into the contract while you still have leverage, and monitor what matters after signature. Where a vendor needs formal examination, that is a third-party vendor audit; where their exposure appears publicly, dark web monitoring catches it.

Why you need it

01 / 06

Why supplier risk needs its own programme.

01

Their incident is your incident.

When a supplier is breached, your data is exposed, your service is down and your customers ask you about it. The contract may allocate liability; it does not restore the data or answer the phone. Your regulator holds you responsible for the processing you outsourced.

02

Nobody knows how many vendors there are.

Procurement knows about the ones with purchase orders. The SaaS tools bought on departmental cards, the contractors with VPN access, the code libraries in your build and the sub-processors your processors use are all third-party risk, and they are almost never on the register.

03

The leverage exists once, before signature.

Security requirements, audit rights, breach notification timelines, sub-processor approval and data-return terms are straightforward to negotiate before a contract is signed and nearly impossible to add afterwards. Diligence that arrives after procurement has committed is theatre.

04

Assessment is a snapshot; risk is continuous.

A questionnaire answered at onboarding describes one day two years ago. Vendors get breached, get acquired, change sub-processors and let certifications lapse, and none of that generates a notification unless someone is watching.

Instrument

02 / 06

Ten suppliers, placed by reach and dependence.

The square a vendor lands in decides the diligence it gets, not the size of its invoice.

What we deliver

03 / 06

What the programme covers.

01

Vendor discovery and register

Building the actual population from procurement, expenses, single sign-on logs, network egress, DNS and interviews, because the register you already have is the vendors someone remembered. Each entry records data accessed, access method, business criticality and the internal owner.

02

Risk tiering

Every supplier classified by what it can reach and how badly you depend on it. Tiering is the control that makes the programme work: critical vendors get real examination, low-tier vendors get a light check, and the effort lands where it is justified.

03

Proportionate due diligence

Assessment sized to the tier, from a short attestation for low-risk suppliers to full questionnaire review, evidence inspection, certification and report validation, and technical assessment for the vendors holding your crown jewels. Existing SOC 2 reports and ISO 27001:2022 certificates are read properly, including the scope and the exceptions.

04

Contractual security requirements

A standard security schedule and data processing agreement, plus negotiation support: breach notification within a defined period, audit and assessment rights, sub-processor approval and notification, encryption and access requirements, and data return and deletion at exit.

05

Continuous monitoring

External security posture monitoring, breach and exposure alerting for critical suppliers, certification expiry tracking, and periodic reassessment on a cadence set by tier rather than by anniversary date.

06

Fourth-party and concentration risk

Mapping the sub-processors your suppliers depend on, and identifying where multiple critical vendors share a single underlying provider, the concentration that turns one outage into an enterprise-wide one.

How we run it

04 / 06

Six steps to a programme that runs.

  1. 01

    Identify third-party relationships

    Cataloguing every vendor, partner and service provider that touches your data, your network or your operations, assembled from finance and identity data rather than from memory, which is why the count usually surprises people.

    Weeks 1-3
  2. 02

    Assess risk levels

    Tiering by data access, network access, business criticality, regulatory exposure and substitutability. The tiering model is documented so that new vendors are classified consistently rather than by whoever onboards them.

    Weeks 3-4
  3. 03

    Implement due diligence

    Assessment proportionate to tier, executed before contract signature so that findings can still change the terms. Critical suppliers get evidence review and, where warranted, technical assessment.

    Ongoing, before onboarding
  4. 04

    Establish contracts and service levels

    Security schedules, data processing agreements and service levels that specify breach notification, audit rights, sub-processor governance, and what happens to your data at termination.

    At contract
  5. 05

    Monitor and review performance

    Reassessment on a tier-driven cadence, continuous external monitoring for critical suppliers, certification expiry tracking, and a defined trigger (an incident, an acquisition, a scope change) that forces an out-of-cycle review.

    Ongoing
  6. 06

    Manage and mitigate risk

    Findings tracked to closure with a named owner and a date, compensating controls where a vendor will not or cannot remediate, exit plans for critical dependencies, and an accepted-risk register that a decision-maker has actually signed.

    Ongoing

Key benefits

05 / 06

What changes after.

You know who holds your data

A live register showing every supplier, what they access, who owns the relationship and when they were last assessed, which is also the first thing a regulator asks for after an incident.

Diligence lands where it matters

Tiering concentrates real examination on the vendors that could hurt you, so the programme stops being a spreadsheet exercise that everyone routes around.

Contracts carry the terms you need

Notification windows, audit rights and data-return obligations agreed while you still have negotiating leverage, rather than requested during an incident.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Assessment frameworks

  • SIG Lite / SIG Core
  • CAIQ
  • ISO 27001:2022 Annex A.5.19-A.5.23
  • NIST SP 800-161

Evidence validation

  • SOC 2 Type II report review
  • ISO 27001:2022 certificate and scope verification
  • Penetration test report review

External monitoring

  • Shodan
  • Censys
  • Certificate Transparency logs
  • urlscan.io

Exposure alerting

  • Have I Been Pwned (domain search)
  • Ransomware leak-site monitoring
  • CVE and advisory tracking

Register and workflow

  • Risk register and tiering model
  • Contract security schedule library
  • Reassessment calendar

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about vendor risk.

How many of our vendors actually need assessing?
Far fewer than the total, which is the point of tiering. In a typical population, a small minority, usually well under a fifth, can reach regulated data, hold privileged network access or would stop your operation if they went down. Those get real examination. The rest get a proportionate check that takes minutes. Programmes that try to assess everyone equally assess no one properly.
A vendor sent us their SOC 2 report. Is that sufficient?
It is good evidence and much better than a self-completed questionnaire, provided someone reads it properly. Check the scope: which systems and which trust services criteria it actually covers, since it frequently excludes the product you are buying. Check the period, because a Type II covering a window that ended fourteen months ago says little about today. And read the exceptions and the complementary user entity controls, which is where the obligations transferred back to you are listed.
What do we do when a critical vendor refuses to be assessed?
Establish whether the refusal is absolute or a negotiation. Large providers often will not complete bespoke questionnaires but publish extensive audit reports and compliance documentation that answer the same questions. Where a vendor genuinely will not engage, the options are compensating controls on your side (limiting the data they hold, restricting their access, monitoring their activity) or documenting the accepted risk with a named executive owner. Both are legitimate; pretending the assessment happened is not.
How often should vendors be reassessed?
By tier, not by anniversary. Critical suppliers annually with continuous external monitoring in between; medium-tier every two years; low-tier on a light attestation cycle or on change. More important than the cadence are the triggers: a security incident at the vendor, an acquisition, a material change in the service or the data involved, or an expired certification should each force an immediate review regardless of when the last one happened.
Does this cover sub-processors we have no contract with?
It covers them through your direct supplier, which is the only leverage you have. The contractual mechanism is sub-processor disclosure, approval rights and flow-down of your security requirements, so that your vendor is obliged to impose equivalent terms downstream. We also map the concentration explicitly, because several critical suppliers sitting on one underlying cloud region or one payment processor is a single point of failure that no individual vendor assessment reveals.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.