Use case · Enterprise

Situational awareness,
when minutes matter.

A named CVE drops. Your team needs to know which companies in the portfolio are exposed, right now, not after a week of emails. Check the whole portfolio for it in one view.

How it works

Situational Awareness, step by step

Before

A week of emails

Contacting every vendor individually and waiting for answers you cannot verify.

With GuardianGaze

Query the portfolio

Check every rated company for the exposure at once, from observations already collected.

Result

Act on the first day

Prioritise the vendors that are actually exposed instead of treating all of them as equally urgent.

Third-party vendor inventory scored by security rating, tier and risk category

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out

The scenario

A widely used product is compromised on a Friday afternoon

This now happens several times a year. A managed file transfer tool, a monitoring agent, a remote access product, a build dependency. Within hours the advisory is public, exploitation is under way, and every security team on earth is asking the same question: are we affected, and which of our suppliers are.

Answering the first half is usually possible. Answering the second half is where it falls apart. The conventional method is to email every supplier and ask, which produces replies from perhaps half of them, over several days, of varying candour, by which point the window in which the answer was useful has closed.

The teams who handle these events well are not faster at reading advisories. They already had the map.

How it works

Querying a live provider map instead of sending emails

Infrastructure relationships are visible from outside. DNS points at hosting providers and mail platforms. Certificate transparency shows who issued for which domains. HTTP responses identify CDNs and edge providers. Mail authentication records enumerate every third party permitted to send on a domain's behalf.

Maintained continuously across your portfolio, that becomes a queryable map rather than a research project. When an advisory lands, the question 'which of our suppliers use this' is a lookup that takes minutes, and the answer covers suppliers who would not have replied to an email at all.

The same applies to your own estate. The reason organisations struggle to answer whether they run an affected product is usually not that the question is hard: it is that nobody has a complete inventory of what is internet-facing, so the answer is assembled by asking around.

Beyond the advisory

Signals that arrive before an advisory does

Not everything announces itself. Corporate credentials appearing in breach data is often the first observable sign of a compromise somewhere in the chain, and it frequently precedes any public disclosure by weeks.

Domain registrations impersonating your brand or a supplier's tend to cluster ahead of campaigns rather than after them. Registration is preparation; the phishing follows. Watching for lookalike registrations gives you a window to act while it is still cheap, a takedown before a campaign is a different exercise from a takedown during one.

A supplier's rating dropping sharply is itself a signal worth reading. Posture rarely degrades for no reason, and a sudden change in a critical vendor's external surface is sometimes the earliest externally visible consequence of an incident they have not yet disclosed.

Operating it

Making it useful rather than another feed

The failure mode is obvious and common: another alert stream, watched enthusiastically for a fortnight and muted by the second month. Situational awareness only works if the signal-to-noise ratio survives contact with a busy team.

So the discipline is scoping to what you would actually act on. Alert on material rating changes at critical suppliers, credentials attributable to your domains, and impersonation infrastructure, not on every observation. Route by severity, and accept that a quiet channel producing three genuinely important things a quarter beats a busy one nobody opens.

And rehearse the lookup before you need it. The value of a provider map is realised under time pressure on a Friday afternoon, which is not the moment to discover that nobody knows how to query it.

Response

Answering 'are we affected' with and without a map

QuestionEmail the suppliersQuery the map
Which suppliers use this product?3–7 days, ~50% responseMinutes, full coverage
Do we run it ourselves?Ask around internallyCheck the asset inventory
Which of those are critical?Cross-reference by handAlready tiered in the portfolio
Has anything changed since?Ask againContinuous, alerts on change

Coverage is the real difference. Suppliers who would never reply to an email are still on the map.

“When the last big CVE landed we had our exposure list inside an hour.”
CISO · Mid-market financial services group
FAQ

Situational Awareness | common questions

How fast can we tell which suppliers are affected by a new advisory?

Minutes, from the live provider map. The alternative, emailing every supplier, takes days and gets replies from roughly half of them.

How are supplier dependencies discovered?

From public infrastructure: DNS, certificate transparency, HTTP response headers and mail authentication records. That covers hosting, mail, CDN and certificate relationships without any cooperation from the supplier.

Can you warn us before an advisory is published?

Sometimes. Credentials appearing in breach data and lookalike domain registrations both tend to precede public disclosure, and a sharp drop in a supplier's rating occasionally surfaces before they announce anything. None of that is guaranteed early warning, and we would not present it as such.

Will this just be another alert feed we mute?

Only if it is scoped badly. Alert on material change at critical suppliers, credentials attributable to your domains, and impersonation infrastructure, not on every observation. A quiet channel producing three important things a quarter is worth more than a busy one nobody opens.

Does it cover our own estate as well as suppliers?

Yes. The same discovery runs against your own domains, which is usually how organisations find out they cannot currently answer whether they run an affected product.

What should we do before an incident?

Rehearse the lookup. A provider map earns its value under time pressure, which is the wrong moment to discover nobody knows how to query it.

Related

Where this connects

Supply chain monitoring →

Building the provider map the query runs against.

Dark web monitoring →

Credential exposure that often precedes disclosure.

Domain takedown →

Acting on impersonation infrastructure before a campaign runs.

Put your vendors on the board

Start with ten vendors. Expand when the first alert pays for the year.