ciso.diy

Third-party risk — the providers who run your estate

Verizon’s 2026 DBIR puts third-party involvement in 48% of breaches, up 60% year on year. Regulators have stopped treating this as generic vendor risk and started naming relationships: the DFS third-party service provider letter on MFA for provider access, HIPAA’s annual business-associate verification, DORA’s critical ICT third parties, NIS2 Article 21(2)(d). The party with delegated admin over your estate is not one row in a register.

What practitioners need to know

Lifted verbatim from the kits below, each attributed to the product that says it.

  • Your MSP is not a vendor, it is your administrative plane — RMM on every endpoint, delegated admin, the credential vault, the backups, the network gear, often the registrar. A vendor questionnaire treats that as one row.

    — MSP & MSSP Assessment Kit
  • 75% of MSPs were breached in the past year and 54% more than once (2026 survey of 350 providers); Verizon’s 2026 DBIR puts third-party involvement in 48% of breaches, up 60% year on year.

    — MSP & MSSP Assessment Kit
  • The custody cliff: most mid-market firms cannot log into their own firewall, restore their own backups or recover their domain without the provider. The assessment names how many holdings sit past it and prices pulling each one back.

    — MSP & MSSP Assessment Kit
  • Refusal to evidence a control is itself the finding. A provider who will not show MFA enforcement, backup immutability or their own IR plan has answered the question.

    — MSP & MSSP Assessment Kit
  • Regulators now name the relationship specifically — the DFS third-party service provider letter (Oct 2025) on MFA for provider access, HIPAA’s annual BA verification, the UK Act’s RMSP duties, DORA’s critical ICT third parties, NIS2 Article 21(2)(d).

    — MSP & MSSP Assessment Kit
  • In the ESA dry run, 93% of firms failed data-quality checks — and the failures were mechanical, not conceptual: missing LEIs, critical functions with no exit reference, contracts not linked to functions, subcontractor chains that stop halfway.

    — Vendor Risk Operations Kit
  • The Register of Information builder carries ten automatic quality checks aimed at exactly those failures. It tells you which rows would be rejected before a supervisor does.

    — Vendor Risk Operations Kit
  • It is a working model, not the xBRL-CSV submission template, and it files nothing. The column map to the ESA technical package is a planned v1.1.

    — Vendor Risk Operations Kit
  • The annual review produces a computed indicated decision that must then be recorded as an actual decision with conditions — a review that ends in a filed document rather than a decision is the most common failure in this discipline.

    — Vendor Risk Operations Kit
  • A 150-question bank across 15 domains — original content, not a re-typed SIG — with Q20 and Q60 as tested subsets of the same bank rather than separate documents that drift apart.

    — TPRM Program Kit

Kits that cover it

5 products, cheapest first.

Vendor Risk Featured

MSP & MSSP Assessment Kit

Your MSP is your administrative plane. Assess what they hold, how they reach you, what they can evidence, what the contract says and whether you could leave — with a scenario that proves you can act the night they are breached.

ZIP 3 licences
From $99.00 View →
Vendor Risk Featured

Vendor Risk Operations Kit

The programme is designed — this is how you run it, vendor by vendor, and what you hand the examiner. The dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder with ten quality checks aimed at the failures supervisors actually flag.

ZIP 2 licences
From $149.00 View →
Vendor Risk Featured

TPRM Program Kit

Tier your vendors in an afternoon, then run the programme — a seven-factor tiering model everything else computes from, a 150-question bank across 15 domains (with an AI-vendor domain) mapped to CSF 2.0 / ISO 27001 / SOC 2, 20 contract clauses with a fallback ladder, an ERR-01-compatible risk register, monitoring cadence, and fourth-party concentration scoring.

ZIP 3 licences
From $199.00 View →
Security Program Pillars Featured

Pillar 06 Companion — The Enterprise Risk Register

Seed to sale for risk: from the engagement that found it to the purchase order that closes it. Offensive scoping, a coverage matrix that knows what has gone stale, treatment as a budgeted project, and priced solutions with the ROI attached.

PDF ZIP 3 licences
From $299.00 View →
Vendor Risk Featured

Enterprise Questionnaire Response Kit

14-tab operational efficiency toolkit for responding to security questionnaires — 400+ pre-written answers mapped to CAIQ v4, SIG, VSA, and HECVAT, AI governance supplements, deal pipeline tracking, and a trust portal content planner.

Excel Word 3 licences
From $299.00 View →

Bundles

6 bundles cover this alongside adjacent work — always below the sum of the parts.

Bundles Featured

Infrastructure Providers Pack

The two parties that run your estate for you — the MSP with delegated admin, and the facility where the data physically sits. Same assessment discipline applied to both. 15% off buying separately.

ZIP 2 products
From $168.00 View →
Bundles Featured

Provider Risk Pack

The vendor programme, and a deep assessment of the vendor that holds your admin rights. Run every supplier properly, then run your MSP properly — because one row in a register does not cover the party with delegated admin on your tenant. 14% off buying separately.

ZIP 2 products
From $211.00 View →
Bundles

Healthcare Provider Risk

The billing company holds your cardholder data and your PHI, and the MSP holds the admin rights over both. Assess the payment side and the provider that runs it. 15% off buying separately.

ZIP 2 products
From $253.00 View →
Bundles

Vendor Risk Complete

The TPRM Program Kit + the Vendor Risk Operations Kit — design the programme, then actually run it. Tiering, questionnaires and clauses on one side; dossiers, scorecards, exit tests and the Register of Information on the other.

ZIP 2 products
From $296.00 View →
Bundles

Both Sides of the MSP

The duties a UK managed service provider owes, and the assessment its customers are about to run on it. Read your own regime and your customers’ checklist in one purchase. 14% off buying separately.

ZIP 2 products
From $593.00 View →
Bundles Featured

Defense Supplier Pack

The CMMC self-assessment and SPRS score you are certifying to, the provider holding your admin rights, and the federal incident clock underneath both. What a DIB contractor is actually accountable for while Phase 2 is suspended. 19% off buying separately.

Excel Word ZIP 3 products
From $598.00 View →

Other regimes: EU AI Act · HIPAA · DORA & NIS2 · PCI DSS · Critical infrastructure · Post-quantum

Working to a date? The compliance calendar. Not legal advice.