The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Governance and compliance
Your supplier is part of your attack surface.
A vendor that accesses your network, your systems, or your data is part of your attack surface, with an aggravating factor: you do not administer their environment. This engagement puts that risk under management: we map who touches what, classify by actual criticality, and assess the ones that matter.
The mapping cross-references contracts, granted access, and spend, because the official list is never complete: almost every company discovers a third party here that nobody had on record. Classification comes from what each vendor actually accesses, not from contract value, and the assessment questionnaire is proportional to each one's risk.
From there, the depth is your choice: stop at the classified inventory, assess the critical vendors with a review of the security clauses in their contracts, or turn it all into a program, with new vendors entering assessed, critical vendors reassessed on a calendar, and indicators reaching the committee.
To start, we need the contracts, the list of granted access, and a channel to whoever manages each vendor, because part of the evidence comes from them. You receive the inventory showing what each one accesses, the assessment of the critical vendors, and the plan in the order that reduces exposure fastest, plus the process built so the next vendor comes in assessed.
The stages and deliverables below describe the Assess the critical ones modality. The other modalities appear when you request the proposal.
Supplier mapping
We find out who they are and what each one actually reaches, cross referencing contracts, granted access and spend. Almost every company discovers someone here that nobody had on record.
Assessing the critical ones
We apply the questionnaire proportional to each one's risk, check the evidence received and classify what needs treatment.
Contract review
We read the security clauses of the contracts in force and point out what is missing, what is written but has never been enforced, and what must go into the next contract. Legal negotiates; we say what the clause needs to cover.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.