Use case · Enterprise

Third-party risk,
without the spreadsheet ritual.

Replace annual questionnaires with continuous, evidence-based ratings of every vendor you depend on. Score every supplier and partner from their live public attack surface, and get told when one slips.

How it works

Third-Party Risk, step by step

Before

Questionnaires age like milk

A vendor's answers were true the day they typed them. Their score today is anyone's guess.

With GuardianGaze

Continuous observation

Every vendor rated from their live public attack surface, refreshed automatically, evidence attached.

Result

Alerts before incidents

A critical vendor's score drops and you know before their own security team does, and before it becomes your breach.

Third-party vendor inventory scored by security rating, tier and risk category

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out

The problem

Why vendor questionnaires stopped working

Third-party risk management still runs, at most organisations, on a document. A vendor receives two hundred questions, someone in their sales team fills it in with help from someone in their security team, it comes back six weeks later, and it is filed. The next time anybody looks at it is the following year.

There are three problems with that, and none of them are fixable by writing a better questionnaire. The answers are self-reported, so they describe what the vendor believes about itself. They are a snapshot, so they describe a moment that has already passed. And they are unverifiable, so a confident answer and an accurate answer are indistinguishable to the person reading it.

Meanwhile the thing you are actually worried about, a vendor's security posture degrading between reviews, happens continuously. Certificates lapse. A subdomain gets stood up for a campaign and never taken down. An acquisition brings in infrastructure nobody has inventoried. A CVE lands against something they run. None of that waits for your review cycle, and none of it appears on a questionnaire filed in March.

The alternative

Continuous external ratings, from evidence rather than assertion

Security ratings invert the model. Instead of asking a vendor what their security looks like, you observe what they publish to the public internet, the same vantage point an attacker has, and score it. Domains, subdomains, exposed services, TLS configuration, mail authentication, cloud posture, breach-exposed credentials, brand impersonation.

The practical consequence is that you can rate a vendor without their participation. No NDA, no questionnaire, no scheduling, no waiting on their security team to have capacity. You supply a domain and a rating comes back. That changes third-party risk management from a process you run on your largest twenty vendors to one you can run on all of them.

It also changes the cadence. A rating that refreshes continuously tells you when something moves, which is the actual question. Nobody genuinely wants to know a vendor's posture in March. They want to know the week it gets worse.

What it does not do

Ratings and questionnaires answer different questions

External ratings observe what is externally observable. That covers a great deal (it is, after all, the same surface an attacker starts from) but it does not cover everything, and any vendor telling you otherwise is selling.

What an outside-in rating cannot see: internal network segmentation, whether backups are tested, how privileged access is governed, what their incident response plan says, whether staff receive security training, how data is handled once it is inside their environment. Those are real controls and they matter, and a questionnaire or an audit report is the right instrument for them.

So the useful model is not replacement: it is triage. Rate everything continuously, and spend your limited questionnaire and audit capacity on the vendors where the rating says something is wrong, or where the data they hold means you need assurance beyond what the outside shows. Most third-party risk programmes are capacity-bound rather than intent-bound; ratings are what let you allocate the capacity you have.

Getting started

What a vendor risk programme looks like in the first quarter

Start with the vendors whose failure would actually hurt you. Not the longest list: the shortest one where a compromise reaches your data, your customers, or your ability to operate. For most organisations that is between ten and forty companies, and it is rarely the same list as the one procurement maintains.

Rate them, then read the outliers rather than the average. A portfolio-wide score is a board metric; the operational value is in the specific findings: the vendor with expired TLS on a payment subdomain, the one whose SPF record permits the whole internet to send as them, the one with credentials in recent breach data.

Then set the alert threshold and leave it running. The programme becomes valuable at the point where a score drops and somebody is told, without anybody having scheduled a review. That is the difference between third-party risk management as an annual compliance exercise and as a control that actually works.

Comparison

Questionnaires vs continuous ratings

Security questionnaireExternal security rating
SourceVendor's own descriptionObserved public evidence
FrequencyAnnual, at bestContinuous
Vendor effortWeeks of their timeNone, no participation needed
Time to first answer4–8 weeksWithin 24 hours
VerifiableNoYes, evidence attached to every finding
Covers internal controlsYesNo
Scales to 200 vendorsNot realisticallyYes

The two are complements. Ratings tell you where to spend questionnaire capacity, not how to avoid needing it.

“Our vendor review went from a quarterly spreadsheet ritual to a live dashboard.”
CISO · Mid-market financial services group
FAQ

Third-Party Risk | common questions

Do we need the vendor's permission to rate them?

No. Assessment observes only what an organisation publishes to the public internet, the same vantage point any visitor or attacker has. Nothing is exploited and no system is accessed, which is what makes vendor and supply-chain review workable without a questionnaire round.

How long does a first rating take?

Within 24 hours of supplying a domain. There is nothing for the vendor to install and nothing for them to approve.

Does this replace our questionnaires?

No, and we would not claim it does. Ratings cover what is externally observable; questionnaires and audit reports cover internal controls like segmentation, backup testing and access governance. Ratings tell you where to spend your limited questionnaire capacity.

What if a vendor disputes a finding?

Every finding carries the evidence it was derived from, so a dispute is a factual conversation rather than an argument about methodology. If the evidence is wrong or stale, the finding goes.

How many vendors can we monitor?

Pricing scales with the number of monitored companies rather than per seat, so the whole risk team uses it. Most programmes start with ten to forty critical vendors and widen once the alerting proves itself.

What happens when a vendor's score drops?

You are alerted, with the specific findings that moved it. That is the whole point of continuous monitoring. The value is not the score itself but being told the week it changes rather than at the next annual review.

Related

Where this connects

Provider concentration →

Fourth parties and shared-provider concentration risk across the whole portfolio.

Vendor onboarding →

Rate a supplier before the contract is signed, not after.

How scoring works →

The deterministic model behind every rating, and how to refute a finding.

Put your vendors on the board

Start with ten vendors. Expand when the first alert pays for the year.