Supply chain,
beyond your direct vendors.
Modern breaches travel through the supply chain, often through a company you have never contracted with. Map the suppliers your critical systems actually depend on and see how exposed each one is.
Supply Chain, step by step
Visibility stops at tier one
You know your direct vendors. The companies they depend on are invisible until something breaks.
Map the chain
Rate suppliers and the infrastructure providers behind them, all on the same scale, all continuously.
Concentration risk becomes visible
When forty vendors sit behind one provider, you find out before that provider has a bad week.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Your suppliers have suppliers
Most organisations have a reasonable view of their direct vendors and almost none of what sits behind them. Your payroll provider uses a hosting company, an identity provider, a payments processor and a dozen SaaS tools. Any one of those failing can stop your payroll, and none of them appear on your vendor list.
The last few years have made the point repeatedly. The compromises that caused the widest damage were not attacks on the eventual victims: they were attacks on something those victims depended on, often something they could not have named. A managed file transfer product. A monitoring agent. A build pipeline. The blast radius follows the provider chain, not the org chart.
This is what makes supply chain risk different from third-party risk rather than a synonym for it. Third-party risk asks whether your vendors are secure. Supply chain risk asks what happens when something two steps away from you fails, and whether you have any idea which of your vendors would go down with it.
The risk that only shows up when you look across the portfolio
The finding that surprises people most is not that a particular vendor is weak. It is how many of them share the same dependency.
Rate a portfolio and the pattern emerges: eleven of your forty vendors resolve to the same cloud region, seven use the same email security provider, five sit behind the same CDN. Individually each is a reasonable choice. Collectively they mean a single provider incident takes out a quarter of your supply chain simultaneously, and your continuity plan almost certainly assumes those failures are independent.
Concentration risk is invisible to vendor-by-vendor review because it is not a property of any vendor. It only appears when you look at the portfolio as a graph, which is exactly what a rated portfolio gives you.
Mapping the provider map from the outside
Fourth-party relationships are discoverable from public infrastructure, because dependencies leave traces. DNS records point at hosting providers and mail platforms. Certificate transparency logs reveal who issued for which domains. HTTP responses identify CDNs and WAFs. Mail authentication records enumerate every third party permitted to send on a domain's behalf, which is often the most revealing single record on any company.
None of this requires access, cooperation or disclosure. It requires reading what is already public, attributing it correctly, and doing it continuously so the map does not go stale the moment a vendor changes provider.
The result is a provider map you can query: which of our vendors depend on this provider, what would a regional outage here take with it, and where is our exposure concentrated enough to be worth a second supplier.
What to do with the map once you have it
The first action is almost always continuity rather than security. Identify where concentration is high enough that a single provider incident would be an operational event, and decide whether that is acceptable. Sometimes it is, the provider is genuinely more reliable than the alternatives, but it should be a decision rather than an accident.
The second is scoping your contractual requirements to reality. Flow-down clauses requiring vendors to hold their own suppliers to your standards are common and largely unenforced, because nobody checks. A provider map makes them checkable, which is the only thing that makes them meaningful.
The third is incident response. When a widely used product is compromised, and this now happens several times a year, the question is which of your suppliers use it, asked under time pressure. Answering that from a live map takes minutes. Answering it by emailing forty vendors takes a week, and you will get replies from about half.
What is observable at each tier
| Tier | Who | What we can see |
|---|---|---|
| First party | You | Full external attack surface, continuously scored |
| Third party | Your direct vendors | Full external attack surface, no participation needed |
| Fourth party | Your vendors' providers | Infrastructure relationships, hosting, mail, CDN, certificate issuance |
| Concentration | Across the portfolio | Shared dependencies and single points of failure |
“We found three critical suppliers all resolving to the same host. That was not on any spreadsheet.”
Supply Chain | common questions
What is the difference between third-party and supply chain risk?
Third-party risk is about your direct vendors. Supply chain risk includes what those vendors depend on, fourth parties, and the concentration that appears when many of your vendors share the same provider. The second is invisible to vendor-by-vendor review.
Is this software supply-chain scanning?
No, and the distinction matters. This maps the companies your suppliers rely on, hosting, mail, CDN, cloud, DNS and certificate providers, discovered from public records. It does not analyse software packages, dependency versions or SBOMs, and it does not look inside anybody's code.
Can you really map fourth-party relationships without access?
Infrastructure dependencies leave public traces: DNS, certificate transparency, HTTP response headers and mail authentication records. That covers hosting, mail, CDN and certificate relationships. It does not reveal contractual relationships that leave no infrastructure footprint, and we would not claim otherwise.
How do you find concentration risk?
By looking at the portfolio as a graph rather than a list. Concentration is not a property of any single vendor, so it only appears when the same provider shows up behind many of them at once.
A widely used product just got compromised. How fast can we tell who is affected?
Minutes, from the live provider map, rather than the week it takes to email every supplier and chase the half who do not reply.
Does this need our vendors to cooperate?
No. Everything is derived from public infrastructure, so coverage does not depend on a vendor's willingness or capacity to respond.
How often does the map refresh?
Continuously. A provider map that is refreshed annually is wrong within weeks, because vendors change providers without telling anyone.
Where this connects
Third-party risk →
Continuous ratings for your direct vendors, without questionnaires.
Situational awareness →
Which suppliers are affected when a product is compromised.
Attack surface management →
How assets and relationships are discovered from the outside.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.