SUPPLIER RISK HEATMAP

Supplier cyber maturity, breach history and inherent risk are assessed at onboarding and rarely revisited, so risk ratings go stale. The supplier you cleared two years ago may now be your weakest point.

Actors

  • Third-Party Risk Manager
  • Procurement Lead
  • CISO

Systems / Vendors

  • TPRM (SecurityScorecard / BitSight)
  • GRC platform
  • Contract register

Business Question

"Which of our suppliers carry the most cyber risk today, not at the point we onboarded them?"

What SPoG Does

  • Rates supplier cyber maturity, breach history and inherent risk.
  • Keeps a live heatmap across the supplier base.
  • Prioritises the highest-risk vendors for action.

Outcome Metrics

1

Supplier risk heatmap

−30%

Unassessed vendor risk

6–10 wks

To first outcomes