The company
A 1,200-person Canadian distributor, eighteen sites, whose operations depend on a chain of logistics suppliers and a dozen business SaaS products. The cyber operations team is three people, oriented towards detection and response, with no dedicated GRC function.
The security rhythm is built around two annual events: a penetration test and a vendor questionnaire campaign. It is a serious setup, run by capable people, and it suited an attack surface that changed once a year. It now changes every week.
The problem: eleven blind months a year
The trigger is external. A breach at a logistics supplier halts shipments for several days. A few weeks later the insurer asks a direct question at renewal: how do you monitor your third parties? The honest answer — an annual questionnaire — is no longer enough.
The annual penetration test gives a sharp photograph, one day a year. Between two tests, a forgotten subdomain or an exposed admin panel can live for eleven months without anyone knowing. The problem is not the quality of the test, it is its frequency against a surface that changes constantly.
On the threat side, roughly 2,000 signals a day arrive with no sector filter. Nobody reads them, and that is rational: triaging two thousand items a day with three people is not a job, it is a punishment. The feed exists, it is paid for, and it serves no purpose.
On the supplier side, the annual questionnaire gets a 60% return rate, answers of uneven quality, and no way to verify any of it. The team is filing declarations, not risks.
What gets put in place
The attack surface, every day
Continuous discovery and scoring of external exposure, graded A to F across five scanning modules, with more than 500 finding types. Twenty-three unknown assets appear in the first month — including a staging environment left publicly reachable after a 2023 migration, with a copy of production data in it. No annual test had seen it, because it was not in the scope handed to the provider.
Threats, filtered down to what concerns them
Threat intelligence is cross-referenced with the country, the sector and the stack actually in place, then scored against existing defences. The 2,000 daily signals become five to ten ranked actions. Watchlists on CVEs, threat actors and domains complete the setup: the team is notified when something concerns it, and silent the rest of the time.
Declared posture against observed reality
For each third party, the posture declared in the questionnaire is set against the posture observed by external scan, on a scope the supplier validated. Nine significant gaps surface across sixty suppliers. None is a lie: in most cases, the person who filled in the questionnaire had no idea what their organisation exposed.
One queue of work
Exposures, relevant threats and supplier gaps converge in the Action Center, with owners and due dates. The team stops arbitrating between three consoles to work out what to do first.
What it yields
Time to discover an exposure drops from eleven months to under twenty-four hours. Twenty-three unknown assets come back under management, and the staging environment is closed the week it is found.
Nine supplier conversations are triggered by factual gaps rather than impressions, which changes the tone of annual reviews entirely: you no longer ask a supplier whether they do things properly, you show them what their scope exposes and ask what they intend to do about it.
The insurer gets a documented answer on third-party monitoring, with exportable history. The intelligence feed finally serves a purpose: it gets read, because it fits in about ten lines.
What it does not fix
The annual penetration test is not removed, and it should not be: a continuous external scan and a manual test are not looking for the same thing. The first finds what is exposed, the second finds what is exploitable by chaining several weaknesses. What changes is that the test no longer spends its first days discovering forgotten assets — it starts where the scan stops.
Figures representative of real deployments. Organisations composite and anonymised.