Supplier risk continuously re-scored as the threat landscape shifts. A built-in threat library cross-references CVEs, sector advisories and vendor-specific intel - every score has a current evidence chain.
supplier risk only means something if it moves with the threat landscape. Static annual scores are obsolete on arrival - the threats move daily; your supplier register does not. Threat-informed scoring catches exposure as it emerges, often before a supplier discloses it.
The two columns below set the usual annual rating against the alternative. A score taken once and filed is frozen against a threat landscape that moves daily, with the threat intel sitting in another team’s tool and the risk and supplier registers that never quite reconcile.
Threat-informed scoring re-weights supplier risk as the landscape shifts, cross-referencing CVEs, sector advisories and vendor-specific intel - so every score carries a current evidence chain rather than a stale one.
Annual risk ratings frozen against a threat landscape that moves daily. Vendors scored once, filed, forgotten. Threat intel in a different team’s tool. Risk and supplier registers never reconcile.
Supplier risk continuously re-scored as the threat landscape shifts. A threat library cross-references CVEs, sector advisories and vendor-specific intel. Every score has a current evidence chain.
The five capabilities below are what turn a static rating into a living one: threat-informed scoring, a built-in threat library of 1,000+ threats mapped to ATT&CK, authoritative feeds (NVD, CISA KEV, GitHub Advisories, NCSC and vendor PSIRTs) ingested inline, FAIR-aligned quantified risk in pounds, and board-ready reporting built in.
Risk continuously re-weighted against current threat intel - not a static rating.
1,000+ threats and ATT&CK techniques mapped. Refreshed continuously.
NVD, CISA KEV, GitHub Advisories, NCSC and vendor PSIRTs ingested inline, EPSS-prioritised - no separate tool.
Loss expectancy + control effectiveness per supplier. FAIR-aligned, in £.
Board-ready views built in. No PowerPoint export, no version drift.
The figures below describe the model behind every score: 1,000+ threat profiles, five risk dimensions and five scored domains, with every result traceable back to its supporting evidence.
The five stages below take a supplier from catalogue and threat profiling, through quantification (likelihood x impact x control effectiveness, expressed in pounds) and treatment, to continuous re-scoring whenever the threat picture or the evidence changes. The loop never closes - it keeps the score current.
The scoring model is grounded in recognised risk and threat frameworks rather than a house method. The grid below shows the alignment - NIST CSF 2.0, ISO 31000, NCSC CAF v4.0, FAIR for quantification in pounds, MITRE ATT&CK for adversary mapping and the NCSC supply-chain principles for HMG and CNI suppliers.
The model gives you the same supplier at three levels of depth. The three views below run from inherent risk scored on sector, scope and data class, through residual risk net of verified control effectiveness, to contextual risk weighted by current threat intel.
Sector, scope and data-class - scored before any controls.
Inherent risk minus verified control effectiveness.
Residual risk weighted by current threat intel.
We’ll run your top-five suppliers through a threat-aware risk score.