R/03Report Type

Third-Party
Risk Reviews

Understanding How External Relationships Influence Cybersecurity

Modern organisations rely on software providers, cloud platforms, suppliers and external services.

Third-party relationships can influence cybersecurity, governance and operational resilience in ways that are not always immediately visible from inside the organisation.

Cyber Analysis produces independent Third-Party Risk Reviews to help organisations understand these relationships through evidence-led analysis. The objective is not to pass or fail suppliers. It is to support organisational understanding of how external dependencies contribute to cybersecurity.

02Purpose

Why Organisations Request Third-Party Risk Reviews

Independent analysis helps organisations understand how third-party relationships influence cybersecurity, governance and operational resilience.

Some organisations want to understand the concentration of their external dependencies. Others are reviewing a specific supplier relationship or preparing for a significant change in how they use external services.

A Third-Party Risk Review provides an independent perspective that sits alongside the organisation's own supplier assessments and risk management processes.

03Scope

What the Review Examines

Cyber Analysis undertakes every investigation independently. Every investigation is different and the review scope is agreed before work begins. Depending on the agreed focus, reviews may examine areas including the following.

  • Supplier relationships
  • Cloud services and SaaS platforms
  • Software providers and vendors
  • External dependencies
  • Access and integration points
  • Contractual and governance considerations
  • Operational resilience
  • Concentration of dependency
  • Change management relating to third parties
  • Relationships between third-party observations and broader risk
04Process

How the Review Is Conducted

Every Cyber Analysis Third-Party Risk Review follows the Cyber Analysis Methodology.

Observations are gathered systematically and the available evidence is examined carefully. Relationships between suppliers, governance, operational practices and organisational responsibilities are then considered together.

The emphasis is placed on understanding how third-party relationships connect to the broader cybersecurity picture rather than evaluating suppliers in isolation.

05Output

What You Can Expect

Every Cyber Analysis report is written in clear, accessible language. Depending on the agreed scope, reviews may include the following.

  • Observations relating to third-party relationships
  • Supporting evidence
  • Implications for cybersecurity and governance
  • Governance considerations
  • Areas requiring discussion
  • Questions for organisational consideration
  • Opportunities for further review
06Boundaries

What the Review Does Not Provide

A Third-Party Risk Review is not any of the following.

It is an independent analytical review intended to improve organisational understanding.

A penetration test

A vulnerability assessment

A compliance audit

A managed security service

A guarantee that third-party incidents will not occur

07Independence

Independence

Cyber Analysis does not sell security software.

Cyber Analysis does not recommend vendors.

Cyber Analysis does not receive payment to influence analytical conclusions.

Every Cyber Analysis report is produced independently using the same evidence-led methodology regardless of organisation, technology, vendor or outcome.

08Context

Every Supplier Relationship Is Different

Different organisations rely on different suppliers, platforms and services. The same third-party relationship may carry different implications depending on how it is integrated, governed and used.

Every Third-Party Risk Review reflects the organisation being examined and the specific relationships it wishes to understand.

Every supplier relationship is different.

Every review reflects those differences.

The methodology remains the same.

Every review begins with structured observation.

Every conclusion is expected to follow from the evidence.