R/03Report Type

Third-Party
Risk Reviews

Understanding How External Relationships Influence Cybersecurity

Modern organisations rely on software providers, cloud platforms, suppliers and external services.

Third-party relationships can influence cybersecurity, governance and operational resilience in ways that are not always immediately visible from inside the organisation.

Third-Party Risk Reviews examine these relationships through independent, evidence-led analysis. The objective is not to pass or fail suppliers. It is to understand how external dependencies contribute to organisational cybersecurity.

02Purpose

Why Organisations Request Third-Party Risk Reviews

Independent analysis helps organisations understand how third-party relationships influence cybersecurity, governance and operational resilience.

Some organisations want to understand the concentration of their external dependencies. Others are reviewing a specific supplier relationship or preparing for a significant change in how they use external services.

A Third-Party Risk Review provides an independent perspective that sits alongside the organisation's own supplier assessments and risk management processes.

03Scope

What the Review Examines

Every review is scoped according to the organisation's needs. Depending on the agreed focus, reviews may examine areas including the following.

  • Supplier relationships
  • Cloud services and SaaS platforms
  • Software providers and vendors
  • External dependencies
  • Access and integration points
  • Contractual and governance considerations
  • Operational resilience
  • Concentration of dependency
  • Change management relating to third parties
  • Relationships between third-party observations and broader risk
04Process

How the Review Is Conducted

Every Third-Party Risk Review follows the Cyber Analysis Methodology.

Observations are gathered systematically and the available evidence is examined carefully. Relationships between suppliers, governance, operational practices and organisational responsibilities are then considered together.

The emphasis is placed on understanding how third-party relationships connect to the broader cybersecurity picture rather than evaluating suppliers in isolation.

05Output

What You Can Expect

Reviews are written in clear, accessible language. Depending on the agreed scope, they may include the following.

  • Observations relating to third-party relationships
  • Supporting evidence
  • Implications for cybersecurity and governance
  • Governance considerations
  • Areas requiring discussion
  • Questions for organisational consideration
  • Opportunities for further review
06Boundaries

What the Review Does Not Provide

A Third-Party Risk Review is not any of the following.

It is an independent analytical review intended to improve organisational understanding.

A penetration test

A vulnerability assessment

A compliance audit

A managed security service

A guarantee that third-party incidents will not occur

07Independence

Independence

Cyber Analysis does not sell security software.

Cyber Analysis does not recommend vendors.

Cyber Analysis does not receive payment to influence analytical conclusions.

Every review is produced independently using the same evidence-led methodology.

08Context

Every Supplier Relationship Is Different

Different organisations rely on different suppliers, platforms and services. The same third-party relationship may carry different implications depending on how it is integrated, governed and used.

Every Third-Party Risk Review reflects the organisation being examined and the specific relationships it wishes to understand.

Every supplier relationship is different.

Every review reflects those differences.

The methodology remains the same.

Every review begins with structured observation.

Every conclusion is expected to follow from the evidence.