CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

TPRMaaS

Third-party risk management

Your suppliers are part of your attack surface, and since ZInfV-1 they are also part of your legal responsibility. We inventory them, rate them, and keep watching — because a supplier that was safe at signature may not be safe next quarter.

The route in is rarely the front door

Most organisations can list their suppliers. Very few can say which of them holds their data, which has remote access to their network, and what happens to either if that supplier is breached. Supply-chain security is now an explicit requirement of Slovenian law, and it is the requirement organisations are least prepared for, because the work is administrative rather than technical.

What you get

  • A complete inventory of third parties, including the ones nobody remembered
  • A risk rating per supplier, based on what they hold and what access they have
  • Due diligence: security posture, certifications, breach history, ownership
  • Contract language that gives you notification rights and an audit right
  • Continuous monitoring, with an alert when a supplier's exposure changes

HOW IT WORKS

From first call to steady state

  1. Identification

    Every relationship that touches your data or your network, assembled from contracts, invoices and access lists rather than from memory.

  2. Risk assessment

    Rated by what would happen to you if they were breached tomorrow, which is not the same as how large they are.

  3. Due diligence

    Verification rather than a returned questionnaire: certifications checked, breach history looked up, claims tested.

  4. Contractual controls

    Notification windows, audit rights, security obligations and exit terms written into the agreement while you still have leverage.

  5. Monitoring and review

    Ongoing, with a scheduled reassessment and an incident plan agreed with the suppliers that matter most.

WHAT THIS ANSWERS

The obligations this covers

This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.

Who this is for. Every essential or important entity under ZInfV-1, every financial entity under DORA, and anyone who outsources anything that touches customer data.

Start with a conversation, not a quote

Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.

Get in touch +386 51 249 533