INITIALISING RISK ENGINE…
The only platform of its kind

End-to-End cyber assurance.One evidence model.

E2ERisk is one of a kind - the only platform that connects supplier assurance, threat intelligence, CAF/GovAssure, Secure by Design, DPIA, resilience and board reporting in one live evidence model. Built for UK public sector, critical national infrastructure and regulated organisations.

205 questions 21 assurance domains Built for UK gov & CNI
We're live

Introducing E2ERisk. Watch the launch.

E2ERisk launch video

Why E2ERisk

There is nothing else like E2ERisk on the market today.

Point tools assess one slice of risk. Spreadsheets record a point in time. Consultants advise. E2ERisk connects the assurance evidence itself - suppliers, threats, controls, DPIAs, resilience, risks and board decisions - in one live platform, purpose-built for UK government, critical national infrastructure and the supply chains that serve them.

Cyber risk is no longer contained in one system, one supplier, one framework or one annual assessment. It moves across supplier estates, cloud services, software dependencies, personal data, operational resilience and board accountability - and most organisations still try to manage that sprawl through separate tools, disconnected spreadsheets and periodic reviews that are out of date the day they are signed off.

E2ERisk brings those layers together. Supplier assurance, threat intelligence, CAF and GovAssure, Secure by Design, DPIA, business resilience and GRC all run on one evidence model - so you assess once, reuse evidence everywhere, track remediation to closure and report risk to the board without rebuilding the picture every time an auditor or regulator asks.

That is what end-to-end means here: not a bigger toolbox, but a single, current view of cyber risk, built for the organisations that carry the most of it.

01

End-to-End, not point-in-time

Onboarding to continuous monitoring in one unbroken loop - not an annual questionnaire that's already stale the day it lands.

02

One platform, many modules

Supplier assurance, threat intelligence, CAF, DPIA, resilience and GRC - one engine, one audit trail, one risk picture.

03

Built for the hardest sector

NCSC CAF, GovAssure, OFFICIAL-SENSITIVE handling and sovereign, customer-tenant deployment for the most sensitive environments. Engineered where the assurance bar is highest.

One platform · modular by design

Seven modules. One platform.

Every module runs on one risk engine, one register, one source of truth - switch them on as you need them.

Most teams end up with a tool per problem - one for supplier risk, another for CAF, a third for DPIAs - and spend their time reconciling between them. E2ERisk takes the opposite approach: seven modules on a single platform, sharing one risk engine and one register, so a finding in one place is visible everywhere it matters. Start with the module that hurts today and switch on the rest as you grow into them.

Module by module

What each module does.

One evidence model, seven first-class modules - each a complete capability in its own right, and stronger together because they all run on the same risk engine, register and supplier graph. Switch on what you need today; evidence captured in one module counts everywhere.

Supplier Assurance

Third-party risk, end to end.

Discover and tier every supplier, then assess them on the 205-question SAQ across 21 security domains - with AI reading the uploaded evidence so your analysts judge rather than transcribe. Suppliers respond through a self-serve portal, and continuous outside-in monitoring keeps watch between assessments.

  • 205-question SAQ across 21 domains, AI-assisted
  • Self-serve supplier portal - the platform does the chasing
  • Continuous outside-in monitoring, not a point-in-time snapshot
Explore Supplier Assurance →
 Supplier portfolioLive
248SUPPLIERS
12CRITICAL
94%ASSESSED
SAQ v3021 domainsAI evidence reviewOutside-in
Threat Centre

Threats matched to your suppliers.

Curated, deduplicated feeds from the authoritative sources, prioritised by EPSS and CISA KEV so you act on what is actually being exploited - then matched to the suppliers each threat exposes. Fused with a nine-surface outside-in rating into one signal you can act on.

  • Eight or more live feeds, EPSS and KEV prioritised
  • ATT&CK-mapped threat-to-supplier matching
  • Nine-surface outside-in rating, one A-F grade
Explore Threat Centre →
 Threat matchLive
Edge-service exploit (T1190)3 exposed
Infostealer credentialsEPSS 0.91
B+Outside-in rating across
nine security surfaces
CAF Assessment

NCSC CAF v4.0, assessed natively.

Work the Cyber Assessment Framework at indicator-of-good-practice depth, recording a defensible contributing-outcome judgement and rationale for each. Evidence is captured once and inherited across outcomes, so the GovAssure Stage 1-4 pack assembles from your live position rather than a pre-deadline scramble.

  • CAF v4.0 native, at indicator-of-good-practice depth
  • Evidence captured once, inherited across outcomes
  • GovAssure Stage 1-4 pack, assembled continuously
Explore CAF Assessment →
 CAF objectivesLive
A · Managing security riskAchieved
B · Protecting against attackPartial
C · Detecting eventsAchieved
D · Minimising impactNot yet
Secure by Design

Security gated across delivery.

Every Secure by Design principle is tracked across the delivery phases the tracker is built around - Discovery, Alpha, Private Beta and Live - answered, evidenced and signed off at each gate, with risk-balanced decisions recorded. The result is an append-only evidence trail that holds up to accreditation, not a tracker filled in the week before go-live.

  • A gate at every delivery phase
  • Yes / No / N-A control responses, evidence-backed
  • Append-only, tamper-evident audit trail
Explore Secure by Design →
 Delivery phasesPrivate Beta
DiscoveryAlphaPrivate BetaLive
HIGHConfidence profile,
evidenced at each gate
DPO Centre

Privacy risk, connected to what creates it.

Article 35 screening triggers when processing looks high-risk, and every DPIA links to the suppliers, assets and ROPA entries behind it - scored on a likelihood-by-severity matrix, with built-in DPO sign-off. A regulator request becomes an export, not a project.

  • UK GDPR Article 35 screening built in
  • Linked to suppliers, assets and your ROPA
  • DPO sign-off, ICO-ready record
Explore DPO Centre →
 DPIA registerLive
Casework ModernisationHigh residual
Citizen Portal analyticsMitigating
Article 35 screenedROPA-linkedDPO sign-off
Business Resilience

Tested recovery, not a binder on a shelf.

Business impact analysis sets RTO, RPO and impact tolerance per critical service; an interactive dependency graph maps the suppliers and systems each one relies on; and exercises from tabletop to full failover are tracked to closure - all rolled into a live Prevent, Absorb, Recover posture.

  • BIA - RTO, RPO and impact tolerance per service
  • Dependency graph with an auto-derived risk score
  • Exercises from tabletop to failover, scored
Explore Business Resilience →
 Resilience postureLive
84PREVENT
72ABSORB
90RECOVER
81Resilience readiness,
recalculated as evidence changes
GRC

The governance core that ties it together.

Every finding - a supplier gap, a CAF outcome, a DPIA risk, a failed recovery test or a matched threat - becomes a tracked risk on one register, scored by one calibrated engine, with treatment plans, owners and due dates. Board-ready packs assemble from live evidence, governed by role-based access and dual control.

  • One calibrated risk engine, one register
  • Treatment plans, owners and KRIs
  • Board packs, RBAC and dual control
Explore GRC →
 Risk registerLive
37OPEN
5OVERDUE
128CLOSED
One risk engineTreatment plansRBAC + dual control
One platform, your way

Take the platform, or just the parts you need.

It is one platform on one evidence model - but you are never forced to take all of it. Every module stands on its own, is licensed on its own, and fits alongside the tools you already run.

Each module works standalone

Run Supplier Assurance, CAF or any single module on its own - the others simply make it stronger when you add them.

Licensed separately, added as you grow

Start with the module that hurts today and switch the rest on when you are ready - no all-or-nothing commitment.

Integrates with your stack

Open APIs connect it to your existing GRC, ITSM and SaaS tools, so it sits alongside the COTS products you already run - not a rip-and-replace.

Why we built it

Built by people who have lived the pain.

E2ERisk comes from E2E Security Consulting - cyber security professionals who have spent years inside UK public sector and critical national infrastructure assurance, running GovAssure and CAF assessments, chasing supplier evidence and writing the board reports themselves. We built the platform because we kept hitting the same walls you do: annual questionnaires that are stale the day they land, evidence scattered across spreadsheets and inboxes, and a stack of frameworks that all ask for the same facts in a different shape. Every module is the tool we wished we had on the inside.

NCSC CAF & GovAssureSecure by DesignSupplier assurance at scaleOFFICIAL-SENSITIVE deliveryUK public sector & CNI
Risk intelligence

See your entire risk landscape, live.

Every supplier, sub-processor and dependency as a connected graph - colour-coded by severity, updated continuously. The cyber risk command centre your board assumes you already have.

A list of suppliers tells you who you buy from; it does not tell you where your risk is concentrated or how far a single compromise could spread. The live graph below turns the estate into something you can actually reason about - severity at a glance, concentration made visible, and the ability to trace an incident through the parties connected to it.

Critical Single-source providers with crown-jewel access.
High Expired evidence or material control gaps.
Medium Assessment in progress, remediation underway.
Low Fully assured, evidence in date.

Click any node to drill into a supplier's controls, evidence and open actions - and trace a breach two, three, four parties deep.

LIVE · 48 entities
CriticalHighMediumLow
Executive reporting

The board-level answer, on demand.

Exposure, evidence and posture - quantified and current, the moment they ask. No two-week scramble.

 board-overview · E2ERiskLive
Critical suppliers
0
▲ 2 vs last quarter
Overdue evidence
0
14 being chased
High-risk vendors
0
under active review
Compliance posture
0
▲ 6% trending up
Compliance trend · 12 months
Assessment completed · Vendor #12 2m
Supplier review initiated · Vendor #47 8m
Evidence expiring · 3 vendors 15m
Remediation closed · Vendor #08 1h
How it works

Four steps. Always running.

Assurance stops being an annual scramble and becomes a continuous, automated loop - onboarding, assessment, monitoring and remediation running as one cycle rather than a once-a-year project that is stale the day it lands.

1

Discover

Import or auto-enrich every vendor, sub-processor and dependency.

2

Assess

Tier by criticality, send the right questionnaire, score against frameworks.

3

Collect

Suppliers upload evidence through a secure portal - chased automatically.

4

Monitor

Evidence validity, control drift and new risk tracked the moment they change.

Built for the hardest sector

Where the assurance bar is highest.

Engineered for OFFICIAL-SENSITIVE from day one - UK data residency, customer-tenant deployment, customer-managed keys, air-gap-ready and source escrow.

UK Central GovernmentNHS & HealthCritical National InfrastructureCivil NuclearMOD-adjacentLocal AuthoritiesRegulated Commercial
Frameworks & assurance

Map once. Report against everything.

Controls and evidence map to the frameworks your auditors and regulators care about. Framework mapping & assurance evidence - not a certification claim.

ISO 27001NIST CSFCyber EssentialsNCSC CAFGovAssureNIS2 / DORAUK GDPR
Take control

The only platform of its kind.
See why.

Give your security, risk and assurance teams continuous, defensible visibility over suppliers, controls, evidence and resilience - and give your board the answer it keeps asking for.