TPRMaaS
Third-party risk management
Your suppliers are part of your attack surface, and since ZInfV-1 they are also part of your legal responsibility. We inventory them, rate them, and keep watching — because a supplier that was safe at signature may not be safe next quarter.
The route in is rarely the front door
Most organisations can list their suppliers. Very few can say which of them holds their data, which has remote access to their network, and what happens to either if that supplier is breached. Supply-chain security is now an explicit requirement of Slovenian law, and it is the requirement organisations are least prepared for, because the work is administrative rather than technical.
What you get
- A complete inventory of third parties, including the ones nobody remembered
- A risk rating per supplier, based on what they hold and what access they have
- Due diligence: security posture, certifications, breach history, ownership
- Contract language that gives you notification rights and an audit right
- Continuous monitoring, with an alert when a supplier's exposure changes
HOW IT WORKS
From first call to steady state
-
Identification
Every relationship that touches your data or your network, assembled from contracts, invoices and access lists rather than from memory.
-
Risk assessment
Rated by what would happen to you if they were breached tomorrow, which is not the same as how large they are.
-
Due diligence
Verification rather than a returned questionnaire: certifications checked, breach history looked up, claims tested.
-
Contractual controls
Notification windows, audit rights, security obligations and exit terms written into the agreement while you still have leverage.
-
Monitoring and review
Ongoing, with a scheduled reassessment and an incident plan agreed with the suppliers that matter most.
WHAT THIS ANSWERS
The obligations this covers
This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.
- 96 days left NIS2 / ZInfV-1 Up to €10 M or 2% of turnover
- 444 days left AI Act Up to €35 M or 7% of turnover
- In force now DORA Up to 2% of global turnover
- Contract requirement ISO/IEC 27001 Lost tenders
Who this is for. Every essential or important entity under ZInfV-1, every financial entity under DORA, and anyone who outsources anything that touches customer data.
THE REST OF IT
Delivered by the same team
Start with a conversation, not a quote
Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.