Third-Party & Supply Chain Risk
Assure the suppliers you depend on, and get certification-ready as somebody else's supplier.
Supply chain risk runs in two directions and most organisations only manage one. Looking outward, you need to know which suppliers can reach your data and whether their controls hold. Looking inward, your own customers increasingly make cyber certification a condition of doing business with you. We work both directions, including preparation for Saudi Aramco's third-party cybersecurity certification, which is now a precondition for contracting with Aramco at all.
Included in this service
Vendor risk assessment
A tiered supplier inventory with assessments proportionate to the access and data each vendor actually holds.
Aramco SACS-210 vendor readiness
Preparation against the current Third Party Cybersecurity Standard so you can face the authorised audit firm with evidence in order.
Evidence pack assembly
We assemble the policy, control and evidence set an assessor will ask for, and identify what genuinely needs building first.
Ongoing supplier assurance
A repeatable review cycle so supplier assurance is a running process rather than an annual scramble.
A clear path from problem to outcome
The same disciplined cycle every time, so you always know what is happening next.
Scope
We identify which standard applies to you, and which of your suppliers matter based on data access and business criticality.
Assess
We assess your controls, or your suppliers' controls, against the applicable standard and record the gaps.
Remediate
We help close the gaps that block certification or that carry genuine risk, in priority order.
Prepare for assessment
We assemble the evidence pack and prepare your team for the questions an authorised assessor will ask.
Frequently asked questions
The things teams ask us most about Third-Party Risk.
More Cybersecurity capabilities
Penetration Testing
Find the gaps before attackers do, with real, hands-on penetration testing.
Red Team Operations
Goal-based adversary simulation that tests people, process and technology together.
Purple Team Exercises
Red and blue working side by side to validate detections and close gaps fast.
Build it right.
Secure it for good.
Tell us what you're building or securing. We'll bring the engineers, the security team and the trainers, plus a clear, costed plan to get you there.
Join our newsletter
Be up to date with everything about NUEXUS
By subscribing you agree with our Privacy Policy
