Resources
Practical guides for running a vendor risk programme.
Written for MSP, MSSP and vCISO operators. Grounded in the frameworks your clients actually get audited against - CISA, NIST, NCSC, ISO 27001, SOC 2, DORA.
Best-practice guide
The MSP & MSSP guide to vendor risk management
A 6-pillar operating model synthesised from CISA, NIST, NCSC, ENISA, CIS, ISO 27001 and DORA. Regulatory floor, tiering, evidence, scoring and a 90-day rollout.
18 min readRead guide
Business guide
How to build a profitable TPRM-as-a-service practice
Pricing tiers, scope, margin math and a 90-day launch playbook for MSPs, MSSPs and vCISOs turning vendor risk into recurring revenue.
16 min readRead guide