1. Help centre
  2. Your services
  3. Supply Chain Risk
  • Welcome to HackRisk
  • Getting started
  • Reading your dashboard
  • Sophia, your AI assistant
  • Dark Web Scan
  • Vulnerability Scan
  • Recon Scan
  • Supply Chain Risk
  • Security Awareness & Phishing
  • Managing your account

Supply Chain Risk

Understand the risk your suppliers carry, and evidence it with questionnaires.

Loading documentation…

Recon Scan< PreviousSecurity Awareness & PhishingNext >

Powered by heyo

On this page

How it worksInvite a supplierRequest access to scores and certificatesView a supplier's recordsQuestionnairesSet up your questionnaireSend a questionnaireWhat your supplier seesReview the answers

Supply Chain Risk helps you keep an eye on the security of your third-party suppliers. It is available to HackRisk customers, and there is no limit on the number of suppliers you can add.

How it works

You invite a supplier to HackRisk. Once they accept, they can run a free HackRisk scan. They can then choose to share their scores with you, which gives you a high-level view of their security posture and helps you judge the implications of working with them.

You can also request and review compliance documents, such as ISO 9001, ISO 27001 and Cyber Essentials or Cyber Essentials Plus certificates. This lets a supplier provide evidence of compliance alongside their HackRisk scores.

Invite a supplier

  1. Open the Supply Chain Risk page and select Invite a supplier.
  2. Enter the supplier's name and the email addresses of the people who should receive the invitation. The platform provides a pre-written email to make this easier.
  3. Send the invitation.

This creates a link between your organisation and the supplier. Until they join, they appear as Pending, and you can send them a reminder after three days.

If the supplier is already a HackRisk customer, or signs up after your invitation, they appear as Active.

Request access to scores and certificates

Once a supplier is Active, two extra options become available:

  • Request permission to share scores.
  • Request permission to share certificates.

Selecting either sends a request to the supplier. When they next sign in, they see a notification at the top of the screen telling them that requests are waiting for review. They can follow the notification, or go to the Admin section and open Permission Requests, where each request can be accepted or declined individually.

View a supplier's records

Once permission has been granted, you can view a summary of the supplier's account. If they have not already uploaded their documents, you can request them. Uploaded documents can be viewed or downloaded.

You cannot see a supplier's full HackRisk Report or the exact issues behind their scores. The aim is to give you enough information to spot potential concerns and start a conversation where needed.

Questionnaires

Questionnaires let you gather evidence directly from a supplier.

Set up your questionnaire

Select the button on the Supply Chain Risk dashboard to configure your questionnaire.

  • Mark each question as either hidden or required.
  • Questions are organised into sections.
  • Add your own custom questions at the bottom.

Send a questionnaire

When the questionnaire is ready, select Send on the main Supply Chain Risk page. The dashboard shows which suppliers have been sent a questionnaire, and the expanded supplier view shows the details of each one.

What your supplier sees

When the supplier signs in, a notification at the top of the screen tells them a questionnaire has been assigned to them. Selecting it takes them to the admin area to complete it.

  • They complete one section at a time, a page at a time, and answers are saved as each page is submitted.
  • At the end, they can review and edit their answers before submitting.
  • Once submitted, the questionnaire becomes read-only. They can still view it from their questionnaires admin page.

Review the answers

Once a supplier has submitted, select View to open the questionnaire. You can rate each response using a dropdown:

RatingColour
PassGreen
Potential RiskAmber
FailRed

The overall questionnaire score updates as you rate responses, giving an average risk score across the whole questionnaire.