Skip to content
NUEXUS Technologies
Cybersecurity Consulting
Third-Party Risk

Third-Party & Supply Chain Risk

Assure the suppliers you depend on, and get certification-ready as somebody else's supplier.

Overview

Supply chain risk runs in two directions and most organisations only manage one. Looking outward, you need to know which suppliers can reach your data and whether their controls hold. Looking inward, your own customers increasingly make cyber certification a condition of doing business with you. We work both directions, including preparation for Saudi Aramco's third-party cybersecurity certification, which is now a precondition for contracting with Aramco at all.

What you get

Included in this service

01

Vendor risk assessment

A tiered supplier inventory with assessments proportionate to the access and data each vendor actually holds.

02

Aramco SACS-210 vendor readiness

Preparation against the current Third Party Cybersecurity Standard so you can face the authorised audit firm with evidence in order.

03

Evidence pack assembly

We assemble the policy, control and evidence set an assessor will ask for, and identify what genuinely needs building first.

04

Ongoing supplier assurance

A repeatable review cycle so supplier assurance is a running process rather than an annual scramble.

What you walk away with
01Tiered supplier inventory with risk ratings
02Vendor assessment questionnaires and reviewed responses
03Gap assessment against the applicable third-party standard
04Evidence pack prepared for assessor review
05Prioritised remediation plan with owners
06Recurring supplier assurance process and calendar
How we engage

A clear path from problem to outcome

The same disciplined cycle every time, so you always know what is happening next.

01
01

Scope

We identify which standard applies to you, and which of your suppliers matter based on data access and business criticality.

02
02

Assess

We assess your controls, or your suppliers' controls, against the applicable standard and record the gaps.

03
03

Remediate

We help close the gaps that block certification or that carry genuine risk, in priority order.

04
04

Prepare for assessment

We assemble the evidence pack and prepare your team for the questions an authorised assessor will ask.

Questions

Frequently asked questions

The things teams ask us most about Third-Party Risk.

Keep exploring

More Cybersecurity capabilities

Build it right.
Secure it for good.

Tell us what you're building or securing. We'll bring the engineers, the security team and the trainers, plus a clear, costed plan to get you there.

AI-powered cybersecurity 24/7 expert support Trusted across industries

Join our newsletter

Be up to date with everything about NUEXUS

By subscribing you agree with our Privacy Policy