LOADING…
Platform  /  Threat Centre  ·  Module
Threat intelligence · built in

Context-awaresupplier risk.

Don't assess suppliers in a vacuum. Score them against the threat actors actually targeting you — a built-in threat library and a BitSight-equivalent outside-in scanner, fused with your questionnaires.

See the platform
23 threat templates 12 compliance maps Mapped to MITRE ATT&CK
Why it's different

Threat intel built in — not a £30k/yr add-on.

Outside-in supplier scoring without the BitSight / SecurityScorecard bill — and fused with the inside-out evidence the scanners can't see.

CapabilityBitSight / SecurityScorecardE2E Risk Threat Centre
Cost£15k–£60k+ annual, per supplierIncluded in the platform licence
CoverageOutside-in score onlyInside questionnaire + outside-in scan + threat library, fused
ContextA letter grade, limited whyLinked to threat actors, CVEs and breach data
Data residencyUS-tenant SaaSUK Azure region, customer-tenant, air-gap option
Suppliers monitoredPay per monitored vendorUnlimited — no per-supplier tax
What's inside

Score suppliers against real threats.

Threat library

23 pre-built scenarios mapped to MITRE ATT&CK and NCSC threat reports — ransomware crews (Qilin, Akira, BlackCat, Cl0p), state actors (APT29, APT40, Lazarus), insider and supply-chain implant.

Outside-in scanner

Passive scanning of domain hygiene, certificate expiry, exposed admin panels, leaked credentials against breach corpora, and dark-web / ransomware-leak-site mentions.

Matching workflow

Map which suppliers are exposed to which threat actors and CVEs, and which controls are insufficient against them.

12 compliance maps

Auto cross-walk to ISO 27001:2022, NCSC CAF v4, Cyber Essentials+, NIS2, NIST CSF 2.0, GovAssure, DSPT and GDPR Article 32.

Risk-signal fusion

Inside-out questionnaire scores and outside-in scan results combined into a single supplier risk, with drift alerts between assessments.

Drift detection

When a threat template changes, every dependent assessment is flagged for review. Stable hash on every config — silent regressions are impossible.

How it reasons

From a threat to a remediation, automatically.

Supplier Xhandles patient PII for an NHS trust.
Exposed toQilin & Akira ransomware (active in health).
Gap found4 SAQ controls insufficient against that profile.
ActionFlagged for remediation, owner & deadline set.
Mapped & sourced

Grounded in the frameworks that matter.

MITRE ATT&CKNCSC Threat ReportsNIS Sectoral GuidanceISO 27001:2022NCSC CAF v4Cyber Essentials+NIS2NIST CSF 2.0GovAssureDSPT
Threat Centre

Stop scoring suppliers in a vacuum.

See the threats actually aimed at your supply chain — and which controls won't survive contact with them.

See Supplier Assurance