Third-Party Risk
What have we imported, and does the vendor's rating match how their accounts actually behave here? The only domain measuring risk that arrived from outside. Commercial risk ratings describe what a supplier looks like from the outside; observed behaviour describes what that supplier's identities and applications actually do inside your environment. The product is the disagreement between the two.
Where the boundary sits.
Four positions come out of the fusion, and only one of them ends up in an incident report. Good rating with risky observed behaviour means the supplier is fine and the integration is the problem. Poor rating with minimal access is tolerable, small blast radius. Poor rating with broad standing access is the one that hurts. Good rating with broad access is complacency. Ratings providers cannot see inside the environment and governance platforms do not correlate; that gap is what this domain covers. The boundary against Assurance & Compliance is deliberate: assurance asks whether our own controls work, this asks what we have imported.
The signals read, and the work prescribed against them.
The summary of each is on the surface. Open one for the specific dimensions behind it.
SignalsWhat IO reads for this domain6 signal and evidence families, correlated deterministically rather than inferred.
- Ingested commercial risk ratings, coverage and freshness
- Divergence between a supplier's rating and their observed behaviour here
- Third-party identities holding access they have not used
- Access still live past the contracted period
- Regulated data reaching third-party applications
- Concentration of dependency on a single supplier
PlaybooksWhat IO prescribes4 representative playbooks, each gated on prerequisites and maturity.
- Revoke standing access for third-party identities that are not using it
- Cut off access that outlived the contract
- Close the divergence where a well-rated supplier behaves badly inside the estate
- Reduce the exposure on the suppliers carrying the most concentration
SeatsWho lands here first3 seats read this domain before anyone else does.
- Governance, risk and compliance
- CISO
- COO
What has to move for this to have worked.
Rating coverage and freshness across the supplier base
Unused third-party access revoked, and whether it stayed revoked
Access live past contract end, and regulated data reaching third-party applications
Sessions that feed this domain.
We deliver these as part of IO Enablement Services.
Invisible Attack Surface
The estate you did not buy: suppliers, integrations and delegated access that behave like part of your network.
Observed behaviour, reported culture and completed learning held as one position, and re-measured on the behaviour, not the completion record.
Detections that arrive from tooling rather than a colleague's message, and where the identity pressure is actually landing.
Which AI tools are really in use, what data reaches them, and whether the written guardrails are the ones in force.
See it before you talk to anyone.
Two quarters of recorded activity across sixteen seats. One click, no install.