Use case · Enterprise

Supply chain,
beyond your direct vendors.

Modern breaches travel through the supply chain, often through a company you have never contracted with. Map the suppliers your critical systems actually depend on and see how exposed each one is.

How it works

Supply Chain, step by step

Before

Visibility stops at tier one

You know your direct vendors. The companies they depend on are invisible until something breaks.

With GuardianGaze

Map the chain

Rate suppliers and the infrastructure providers behind them, all on the same scale, all continuously.

Result

Concentration risk becomes visible

When forty vendors sit behind one provider, you find out before that provider has a bad week.

Third-party vendor inventory scored by security rating, tier and risk category

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out

The problem

Your suppliers have suppliers

Most organisations have a reasonable view of their direct vendors and almost none of what sits behind them. Your payroll provider uses a hosting company, an identity provider, a payments processor and a dozen SaaS tools. Any one of those failing can stop your payroll, and none of them appear on your vendor list.

The last few years have made the point repeatedly. The compromises that caused the widest damage were not attacks on the eventual victims: they were attacks on something those victims depended on, often something they could not have named. A managed file transfer product. A monitoring agent. A build pipeline. The blast radius follows the provider chain, not the org chart.

This is what makes supply chain risk different from third-party risk rather than a synonym for it. Third-party risk asks whether your vendors are secure. Supply chain risk asks what happens when something two steps away from you fails, and whether you have any idea which of your vendors would go down with it.

Concentration

The risk that only shows up when you look across the portfolio

The finding that surprises people most is not that a particular vendor is weak. It is how many of them share the same dependency.

Rate a portfolio and the pattern emerges: eleven of your forty vendors resolve to the same cloud region, seven use the same email security provider, five sit behind the same CDN. Individually each is a reasonable choice. Collectively they mean a single provider incident takes out a quarter of your supply chain simultaneously, and your continuity plan almost certainly assumes those failures are independent.

Concentration risk is invisible to vendor-by-vendor review because it is not a property of any vendor. It only appears when you look at the portfolio as a graph, which is exactly what a rated portfolio gives you.

How it works

Mapping the provider map from the outside

Fourth-party relationships are discoverable from public infrastructure, because dependencies leave traces. DNS records point at hosting providers and mail platforms. Certificate transparency logs reveal who issued for which domains. HTTP responses identify CDNs and WAFs. Mail authentication records enumerate every third party permitted to send on a domain's behalf, which is often the most revealing single record on any company.

None of this requires access, cooperation or disclosure. It requires reading what is already public, attributing it correctly, and doing it continuously so the map does not go stale the moment a vendor changes provider.

The result is a provider map you can query: which of our vendors depend on this provider, what would a regional outage here take with it, and where is our exposure concentrated enough to be worth a second supplier.

In practice

What to do with the map once you have it

The first action is almost always continuity rather than security. Identify where concentration is high enough that a single provider incident would be an operational event, and decide whether that is acceptable. Sometimes it is, the provider is genuinely more reliable than the alternatives, but it should be a decision rather than an accident.

The second is scoping your contractual requirements to reality. Flow-down clauses requiring vendors to hold their own suppliers to your standards are common and largely unenforced, because nobody checks. A provider map makes them checkable, which is the only thing that makes them meaningful.

The third is incident response. When a widely used product is compromised, and this now happens several times a year, the question is which of your suppliers use it, asked under time pressure. Answering that from a live map takes minutes. Answering it by emailing forty vendors takes a week, and you will get replies from about half.

Scope

What is observable at each tier

TierWhoWhat we can see
First partyYouFull external attack surface, continuously scored
Third partyYour direct vendorsFull external attack surface, no participation needed
Fourth partyYour vendors' providersInfrastructure relationships, hosting, mail, CDN, certificate issuance
ConcentrationAcross the portfolioShared dependencies and single points of failure
“We found three critical suppliers all resolving to the same host. That was not on any spreadsheet.”
CISO · Mid-market financial services group
FAQ

Supply Chain | common questions

What is the difference between third-party and supply chain risk?

Third-party risk is about your direct vendors. Supply chain risk includes what those vendors depend on, fourth parties, and the concentration that appears when many of your vendors share the same provider. The second is invisible to vendor-by-vendor review.

Is this software supply-chain scanning?

No, and the distinction matters. This maps the companies your suppliers rely on, hosting, mail, CDN, cloud, DNS and certificate providers, discovered from public records. It does not analyse software packages, dependency versions or SBOMs, and it does not look inside anybody's code.

Can you really map fourth-party relationships without access?

Infrastructure dependencies leave public traces: DNS, certificate transparency, HTTP response headers and mail authentication records. That covers hosting, mail, CDN and certificate relationships. It does not reveal contractual relationships that leave no infrastructure footprint, and we would not claim otherwise.

How do you find concentration risk?

By looking at the portfolio as a graph rather than a list. Concentration is not a property of any single vendor, so it only appears when the same provider shows up behind many of them at once.

A widely used product just got compromised. How fast can we tell who is affected?

Minutes, from the live provider map, rather than the week it takes to email every supplier and chase the half who do not reply.

Does this need our vendors to cooperate?

No. Everything is derived from public infrastructure, so coverage does not depend on a vendor's willingness or capacity to respond.

How often does the map refresh?

Continuously. A provider map that is refreshed annually is wrong within weeks, because vendors change providers without telling anyone.

Related

Where this connects

Third-party risk →

Continuous ratings for your direct vendors, without questionnaires.

Situational awareness →

Which suppliers are affected when a product is compromised.

Attack surface management →

How assets and relationships are discovered from the outside.

Put your vendors on the board

Start with ten vendors. Expand when the first alert pays for the year.