Supplier Security Services

Supply Chain Cyber Risk Management and SBOM Analysis

We identify, assess and manage the cyber security risks in your supply chain. Our services cover Third-Party Risk Management (TPRM), Software Bill of Materials (SBOM), VEX (Vulnerability Exploitability eXchange) and supplier security auditing.

Service Details

As of 2025, 62% of cyber attacks occur directly or indirectly through the supply chain. High-profile incidents such as SolarWinds Orion (2020), Log4Shell (2021), the 3CX supply chain compromise (2023), the XZ Utils backdoor (2024) and the polyfill.io domain hijack (2024) have shown just how destructive and widespread these attacks can be. CoreDefence Supplier Security Services manage the cyber risk in your supply chain proactively.

Our Third-Party Risk Management (TPRM) programme classifies suppliers as Tier 1/2/3 by criticality and applies the appropriate assessment method to each tier. Automated security questionnaires (SIG Lite, CAIQ), external attack surface scanning, security rating platforms and SOC report analysis continuously monitor your suppliers' security posture. We establish a governance framework that tracks security requirements across the full contract lifecycle.

Our Software Bill of Materials (SBOM) management service inventories every component used in your software projects in CycloneDX and SPDX formats, in line with NTIA minimum SBOM requirements and the EU Cyber Resilience Act (CRA). It continuously scans each component for known vulnerabilities (CVE) against the NVD and OSV databases, evaluates exploit likelihood with EPSS (Exploit Prediction Scoring System) and prioritises actively exploited flaws using the KEV (Known Exploited Vulnerabilities) catalogue.

By producing VEX (Vulnerability Exploitability eXchange) documents we assess whether the vulnerabilities found are genuinely exploitable in your environment, reducing false alarm load. This makes vulnerability management practical and actionable, particularly in large software projects with thousands of dependencies.

Our supplier security audit service reviews the security controls of your critical suppliers on site or remotely against ISO 27001, SOC 2 Type II and sector standards. For cloud SaaS suppliers we perform CSA STAR assessment, API security auditing and data processing agreement (DPA) review. Supplier-originated incident response plans and escalation procedures are also within scope.

Our continuous supplier monitoring programme tracks your suppliers' external attack surface, data leaks, dark web exposures and changes in security scores in real time, presenting them on a risk dashboard. Automated alerts and periodic risk reports make your supply chain risk management proactive.

Our Methodology

01
Supplier inventory, classification and criticality analysis
02
TPRM framework and assessment criteria design
03
Automated security questionnaires and external scan assessment
04
SBOM creation, CVE/EPSS/KEV correlation and VEX analysis
05
Critical supplier security audit (on site / remote)
06
Risk reporting, dashboard setup and remediation tracking
07
Supplier incident response plan and escalation procedure
08
Continuous monitoring programme and periodic review

What We Offer

Tier-based Third-Party Risk Management (TPRM) programme
SBOM creation, management and continuous vulnerability monitoring
Exploitability assessment with VEX to reduce false alarms
Vulnerability prioritisation through EPSS and KEV
Supplier security scoring and external attack surface monitoring
EU Cyber Resilience Act (CRA) and NTIA SBOM compliance
Contractual security requirements and DPA consulting
Dark web monitoring and supplier data leak detection
Supplier-originated incident response planning

Learn More About This Service

Our experts will assess your organisation individually and recommend the solution that fits best.

Contact Us