Infocredit Group
RiskRecon by Mastercard
Product we represent

Continuous cybersecurity ratings for every third party you depend on.

Outside-in assessment of a company’s internet-facing footprint, scored against dozens of security criteria and weighted by the value of the asset at risk — so your teams act on the findings that actually matter.

OriginMastercard
Security criteria assessed
40+

Security criteria assessed

Risk domains rated
9

Risk domains rated

Reassessment of every vendor
Continuous

Reassessment of every vendor

Objective rating scale
0–10

Objective rating scale

Why organisations use RiskRecon

Most third-party risk programmes run on annual questionnaires: self-reported, out of date the day they are returned, and impossible to compare across a portfolio. RiskRecon replaces that with continuous, evidence-based assessment. It discovers a company’s internet-facing systems, evaluates them across dozens of security criteria in nine risk domains, and weights every finding by the value of the asset it affects — so a flaw on a system handling customer data outranks a cosmetic issue on a marketing page. The output is an objective 0–10 rating plus an itemised, prioritised action plan that your vendor can work through, and that your risk committee can track over time.

Passive, outside-in assessment

No agents, no scans of your vendor’s internal network and no cooperation required to produce a first rating.

Asset-value weighting

Every finding is prioritised by the criticality of the system affected, so remediation effort goes where the real exposure is.

Nine risk domains

Software patching, application security, web encryption, network filtering, email security, DNS, system hosting, defensibility and threat intelligence.

Portfolio view

Rate and compare an entire vendor, supplier or investment portfolio on one consistent scale.

Continuous monitoring

Ratings refresh as the vendor’s footprint changes, replacing the annual point-in-time questionnaire cycle.

Actionable findings

Each issue includes the affected host, the evidence and the remediation guidance needed to close it.

Automated alerting

Threshold breaches and material deteriorations notify your risk owners automatically.

Reporting for governance

Board-level summaries and per-vendor detail sit side by side for audit and committee reporting.

Coverage and specifications

Risk domains

  • Software patching
  • Application security
  • Web encryption
  • Network filtering
  • Email security
  • DNS security
  • System hosting and reputation
  • Threat intelligence
  • Defensibility indicators

Programme use

  • Vendor onboarding due diligence
  • Ongoing portfolio monitoring
  • M&A and investment screening
  • Insurance underwriting inputs
  • Internal self-assessment

Delivery

  • Web portal for risk teams
  • API access for automation
  • Scheduled reporting
  • Alerting on material change
  • Findings surfaced in ComplianceSuite workflows

Outputs

  • 0–10 objective rating
  • Domain-level sub-ratings
  • Itemised findings with evidence
  • Prioritised action plan
  • Portfolio benchmarking

How it works

  1. 01

    Define the portfolio

    We onboard your vendor, supplier or portfolio-company list and map each entity to its internet footprint.

  2. 02

    Discover assets

    Internet-facing systems, domains and services attributable to each company are discovered automatically.

  3. 03

    Assess and weight

    Findings across the nine risk domains are scored and weighted by the value of the asset at risk.

  4. 04

    Prioritise remediation

    Each vendor receives an itemised action plan ordered by real exposure, not raw issue count.

  5. 05

    Monitor continuously

    Ratings update as footprints change, with alerts on deterioration and threshold breaches.

Where it is used

  • Banks and payment institutions assessing outsourcing and ICT providers under DORA-style expectations
  • Insurers underwriting cyber policies with objective, comparable risk evidence
  • Corporates screening suppliers before onboarding and at contract renewal
  • Private equity and investment teams assessing cyber exposure in a target
  • Regulated firms evidencing ongoing third-party monitoring to supervisors

Outcomes teams report

  • Questionnaire cycles shrink because evidence-based ratings answer most of the questions
  • Remediation effort concentrates on the small share of findings that carry real exposure
  • Risk committees see one consistent scale across the whole third-party portfolio
  • Deterioration is caught between review cycles instead of at the next annual assessment

Frequently asked questions

Do we need the vendor’s permission to rate them?

No. The assessment is passive and outside-in, based on publicly observable internet-facing systems, so a rating can be produced before any vendor engagement.

How is this different from a security questionnaire?

Questionnaires are self-reported and point-in-time. RiskRecon is evidence-based and continuous, and produces a comparable score across your whole portfolio.

Can we rate our own organisation?

Yes. Many clients start by rating themselves to see what an attacker — or a customer — can observe from outside.

How does it support regulatory expectations?

It gives documented, repeatable evidence of ongoing ICT third-party monitoring, with history you can present to auditors and supervisors.

How is it delivered?

Through the RiskRecon portal and API, with Infocredit handling onboarding, portfolio setup, threshold design and analyst support locally.

Interested in RiskRecon?

One contract, local implementation and support — Securing Ease of Mind.