Supply Chain Risk
Understand the risk your suppliers carry, and evidence it with questionnaires.
Loading documentation…
Supply Chain Risk helps you keep an eye on the security of your third-party suppliers. It is available to HackRisk customers, and there is no limit on the number of suppliers you can add.
You invite a supplier to HackRisk. Once they accept, they can run a free HackRisk scan. They can then choose to share their scores with you, which gives you a high-level view of their security posture and helps you judge the implications of working with them.
You can also request and review compliance documents, such as ISO 9001, ISO 27001 and Cyber Essentials or Cyber Essentials Plus certificates. This lets a supplier provide evidence of compliance alongside their HackRisk scores.
This creates a link between your organisation and the supplier. Until they join, they appear as Pending, and you can send them a reminder after three days.
If the supplier is already a HackRisk customer, or signs up after your invitation, they appear as Active.
Once a supplier is Active, two extra options become available:
Selecting either sends a request to the supplier. When they next sign in, they see a notification at the top of the screen telling them that requests are waiting for review. They can follow the notification, or go to the Admin section and open Permission Requests, where each request can be accepted or declined individually.
Once permission has been granted, you can view a summary of the supplier's account. If they have not already uploaded their documents, you can request them. Uploaded documents can be viewed or downloaded.
You cannot see a supplier's full HackRisk Report or the exact issues behind their scores. The aim is to give you enough information to spot potential concerns and start a conversation where needed.
Questionnaires let you gather evidence directly from a supplier.
Select the button on the Supply Chain Risk dashboard to configure your questionnaire.
When the questionnaire is ready, select Send on the main Supply Chain Risk page. The dashboard shows which suppliers have been sent a questionnaire, and the expanded supplier view shows the details of each one.
When the supplier signs in, a notification at the top of the screen tells them a questionnaire has been assigned to them. Selecting it takes them to the admin area to complete it.
Once a supplier has submitted, select View to open the questionnaire. You can rate each response using a dropdown:
| Rating | Colour |
|---|---|
| Pass | Green |
| Potential Risk | Amber |
| Fail | Red |
The overall questionnaire score updates as you rate responses, giving an average risk score across the whole questionnaire.