A curated threat library, a built-in outside-in attack-surface scanner and automated matching - so an emerging threat maps straight onto the suppliers it puts at risk.
A threat feed tells you what is happening. The Threat Centre tells you who it happens to.
Most threat intelligence arrives as a firehose - thousands of advisories and CVEs a week, disconnected from your actual suppliers. By the time someone has worked out whether a new exploit touches a vendor you depend on, the window of exposure has already been open for days.
The Threat Centre links every threat to the suppliers it exposes. A curated, ATT&CK-mapped library and an agent-free outside-in scan are fused with your inside-out questionnaire answers, so a new exploit resolves instantly into a named, criticality-ranked list of affected suppliers - and each match becomes a tracked remediation action that feeds straight into the supplier's risk score and your board reporting.
Most threat feeds are a firehose, disconnected from the suppliers you actually depend on - so the work of deciding what matters falls to people who do not have the hours for it, and exposure windows stay open while they catch up. The Threat Centre links every threat to the suppliers it exposes, so relevance is decided for you rather than left to manual triage.
23 threat templates, each mapped to MITRE ATT&CK techniques - maintained, not a raw feed.
An outside-in external attack-surface scan - TLS, DNS, headers, exposure - with no agent and no supplier effort.
Each new threat is matched to the exact suppliers it exposes - blast radius in seconds, not a manual trawl.
Inside-out SAQ answers, outside-in scan results and live threats combined into one supplier risk signal.
A matched threat becomes a tracked remediation action on the supplier - with an owner and a due date.
Every threat and control maps to CAF, ISO 27001, Cyber Essentials and NIST - evidence, not noise.
The Threat Centre does not just pile on more feeds. It draws on curated, deduplicated streams from the authoritative sources, enriched with exploit-prediction scoring - so the signal you see is weighted towards what is actually being exploited in the wild, not everything that has ever been published.
Every CVE carries an EPSS exploit-prediction score and a known-exploited flag - so you triage what is actually being weaponised, not the whole CVSS pile.
Each threat gets a generated plain-English brief, and you search the library in natural language - “actively-exploited edge-device CVEs”.
Dark-web infostealer credentials, ransomware-leak mentions and IP blocklist hits per supplier - the live external signals that complete the picture your assessment builds.
This is the moment that matters: a new exploit lands, and instead of a week of manual triage it resolves into the named suppliers it actually exposes, ranked by criticality. The view below shows a single ATT&CK technique matched to three suppliers in a portfolio, each with the outside-in signal that flagged it.
Every supplier is scanned from the outside in - no agent to deploy, no effort asked of the supplier - and scored across nine security surfaces into a single grade. That rating sits alongside your assessment answers and can be published on a shareable trust page, so the outside-in view and the inside-out evidence tell one story.
The trouble with most threat intelligence is not volume, it is relevance. Thousands of advisories arrive each week with no link to your actual suppliers, so deciding what matters falls to people who do not have the hours for it, and exposure windows stay open while they catch up.
The flow is the same every time: a threat is ingested and mapped to ATT&CK, the outside-in scan and your assessment answers locate the exposed suppliers, the match is ranked by criticality, and the result is a remediation action with an owner - not another advisory nobody reads.
Outside-in rating tools give you a grade; raw feeds give you noise. Neither tells you which of your suppliers to act on first. The comparison below shows what changes when threat intelligence, the outside-in scan and your assessment data are fused into one signal.
| Capability | E2ERisk | Outside-in rating tools | Raw threat feed |
|---|---|---|---|
| Outside-in attack surface | Built in, no agent | Core product | Not included |
| Curated threat library | 23 templates, ATT&CK-mapped | Limited | Unstructured firehose |
| Matched to YOUR suppliers | Automatic blast radius | Per-vendor score only | Manual |
| Fused with inside-out SAQ | One combined signal | Outside-in only | No assessment data |
| Remediation workflow | Action, owner, due date | Score, no workflow | None |
| UK public-sector fit | CAF & CE mapped | US-centric ratings | Generic |
The result is intelligence you can act on: a score is a starting point, but a named, ranked, owned remediation action is what actually reduces exposure.
A single threat technique touches several frameworks at once. The exploited edge service that ATT&CK calls T1190 is a CAF secure-configuration concern, an ISO 27001 vulnerability-management control and a NIST continuous-monitoring expectation - so one matched threat produces evidence against all of them.
The point of the Threat Centre is what it produces: deduplicated intelligence from the feeds that matter, an outside-in grade across nine surfaces, exploit-prediction signal on every CVE, and a shareable supplier rating - all fused with the assessment you already hold.
Three things come out of the module, each usable the day it is switched on: an agent-free outside-in scan of every supplier, a maintained threat library that matches itself to your portfolio, and a remediation flow that turns each match into tracked, owned action.
An external scan of every supplier - TLS, DNS, headers and exposure - with no agent to deploy.
A maintained, ATT&CK-mapped library that automatically matches each threat to the suppliers it exposes.
Every match becomes a tracked remediation action on the supplier, with an owner, a due date and an audit trail.
A 30-minute walkthrough on your suppliers - live outside-in scan and threat matching, no slides.