Skip to content
FortaRisks
All pillars

The real posture of your vendors, not their questionnaire

An external attack-surface view of every partner, turned into a continuous risk score. Know the moment a posture degrades, group vendors your way, and share a report, or send a questionnaire, only when you need more detail.

7 days

To first alert

0 to 100

Vendor score, A+ to F

100+

Findings per vendor

The annual questionnaire is already out of date.

A once-a-year form does not tell you when a vendor is actually exposed or breached.

Value you can see

Outcomes your team will feel.

  • 7 days to first alert

    Know a vendor's real posture in a week.

  • No questionnaire needed

    Assess from the outside, no cooperation required.

  • A score you can defend

    Every finding behind the grade, point by point.

Key capabilities

  • External attack surface, scored

    An outside-in, EASM-style view of every partner, no cooperation needed, turned into a clear 0 to 100 risk score with A+ to F grades.

  • Continuous posture, not a yearly form

    Attack surface, CTI, breach exposure and framework drift watched per vendor every day, OT/ICS vendors included.

  • Degradation and change alerts

    The moment a vendor's posture slips, a new exposed port, an expired cert, leaked credentials, a breach, you get an alert to harden your supply chain before it reaches you.

  • Group vendors your way

    Organize third parties by type, criticality, business unit and more, so you focus on the ones that matter most.

  • Share reports for remediation

    Export a vendor's report and hand it to them, turning your assessment into their improvement, with no extra licence for them.

  • Questionnaires on demand

    When a posture degrades and you need depth, send a targeted questionnaire for the detail external scanning cannot see, not a yearly blanket survey.

From vendor drift to an action you can take.

A vendor's score change becomes an action in your feed, not a line lost in a spreadsheet.

Three real-world scenarios. Three measurable outcomes.

  • Case 1

    Finance (DORA, OSFI B-13)

    A Canadian bank with 1,200 employees, 60 critical ICT suppliers (cloud, SaaS, managed services). DORA audit imminent. Before FortaRisks: DORA questionnaires sent in March, 60% return rate, variable quality, usable in September. With FortaRisks TPRM: 60 suppliers onboarded in 5 days. Initial score for 100% of third parties in under 7 days. Continuous detection of TLS degradation, newly exposed ports, critical CVEs on Internet-facing services. DORA report generated in 1 day, continuous evaluation evidence exportable.

  • Case 2

    Healthcare (Loi 25, targeted ransomware)

    A Quebec clinic group, 800 employees, 25 suppliers handling personal health information (PHI). Historic ransomware target. Before FortaRisks: no continuous visibility on supplier posture, reliance on their Loi 25 declaration. With FortaRisks TPRM: continuous observation of 25 critical suppliers. Automatic detection of a supplier whose subdomain was hijacked via subdomain takeover (unconfigured Webflow), 48 hours after the event. Action: access suspended in 24 hours, contractual negotiation activated.

  • Case 3

    Manufacturing OT

    A 1,500-employee manufacturer, 12 sites, 80 suppliers including 15 OT suppliers (automation, sensors, supervision). Before FortaRisks: zero visibility on the OT surface exposed by suppliers (accidentally exposed Modbus / S7 on the Internet). With FortaRisks TPRM: native OT/ICS scanner applied to the 15 OT suppliers. Detection of a sensor supplier's Siemens S7 accessible on the Internet via NAT misconfiguration. Notification to the supplier. Correction in 72 hours. No incident.

What's included

Scoring & depth

  • 0 to 100 score, A+ to F grades
  • 1,468 SCF controls mapped
  • 15 industrial ports
  • 100+ finding types per vendor
  • First alert within 7 days

Frameworks

  • DORA
  • OSFI B-13
  • Quebec Law 25
  • Vendor Due Diligence
  • SOC 2
  • ISO 27001

TPRM is not a silo. The other 4 pillars feed it.

Continuous TPRM only has value because the other 4 pillars exist. That's what distinguishes it from a standalone TPRM product (BitSight, SecurityScorecard) or a TPRM module added to a GRC (OneTrust). Each pillar feeds a different dimension of third-party observation.

  • EASM → TPRM

    The 100+ EASM finding types are applied to each third party's perimeter. The native OT/ICS scanner is applied to industrial suppliers. The subdomain takeover detection engine on 83 services is applied to third-party exposed assets. No additional ingestion cost.

  • CTI → TPRM

    The 50+ aggregated CTI sources and 1,500+ tracked actors are filtered by third-party industry sector. If BlackBasta targets the healthcare sector and one of your healthcare suppliers has an exposed critical CVE, you see it immediately, before the attack.

  • Posture → TPRM

    The 1,468 SCF controls mapped across 30 frameworks serve as a reference for alignment drift. If a third party declares SOC 2, FortaRisks observes external signs of that alignment (TLS, MTA-STS, security headers) and alerts on drift vs declaration.

  • AI Risk Engine → TPRM

    The third-party score contributes to your organization's overall risk score. Cross-pillar prioritization takes your third parties into account: a critical CVE on one of your critical third parties is prioritized over a medium CVE on one of your unexposed direct assets.

See your real risk in a 30-minute demo.

A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.

Frequently asked questions

How is this different from an external score like BitSight or SecurityScorecard?

Those give you a grade from a closed methodology. FortaRisks exposes every finding behind a vendor's score, by dimension, so the vendor can dispute it point by point and you can defend your decision with technical proof.

Do vendors have to cooperate for the initial assessment?

No. The initial assessment is based only on what is observable from the internet. Vendors can later add internal evidence such as SOC 2 reports, but it is not required.

Does the OT/ICS scanner apply to vendors?

Yes. Categorize a vendor as OT or industrial at onboarding and the native OT/ICS scanner is included in their continuous surface scan, read-only with adapted rate limiting.

What happens when a vendor disputes its score?

You can export the full score breakdown as a PDF. If the vendor remediates, the next scan detects it and the score updates within 24 hours, with no manual negotiation.