Continuous cybersecurity ratings for every third party you depend on.
Outside-in assessment of a company’s internet-facing footprint, scored against dozens of security criteria and weighted by the value of the asset at risk — so your teams act on the findings that actually matter.
- Security criteria assessed
- 40+
- Risk domains rated
- 9
- Reassessment of every vendor
- Continuous
- Objective rating scale
- 0–10
Security criteria assessed
Risk domains rated
Reassessment of every vendor
Objective rating scale
Why organisations use RiskRecon
Most third-party risk programmes run on annual questionnaires: self-reported, out of date the day they are returned, and impossible to compare across a portfolio. RiskRecon replaces that with continuous, evidence-based assessment. It discovers a company’s internet-facing systems, evaluates them across dozens of security criteria in nine risk domains, and weights every finding by the value of the asset it affects — so a flaw on a system handling customer data outranks a cosmetic issue on a marketing page. The output is an objective 0–10 rating plus an itemised, prioritised action plan that your vendor can work through, and that your risk committee can track over time.
Passive, outside-in assessment
No agents, no scans of your vendor’s internal network and no cooperation required to produce a first rating.
Asset-value weighting
Every finding is prioritised by the criticality of the system affected, so remediation effort goes where the real exposure is.
Nine risk domains
Software patching, application security, web encryption, network filtering, email security, DNS, system hosting, defensibility and threat intelligence.
Portfolio view
Rate and compare an entire vendor, supplier or investment portfolio on one consistent scale.
Continuous monitoring
Ratings refresh as the vendor’s footprint changes, replacing the annual point-in-time questionnaire cycle.
Actionable findings
Each issue includes the affected host, the evidence and the remediation guidance needed to close it.
Automated alerting
Threshold breaches and material deteriorations notify your risk owners automatically.
Reporting for governance
Board-level summaries and per-vendor detail sit side by side for audit and committee reporting.
Coverage and specifications
Risk domains
- Software patching
- Application security
- Web encryption
- Network filtering
- Email security
- DNS security
- System hosting and reputation
- Threat intelligence
- Defensibility indicators
Programme use
- Vendor onboarding due diligence
- Ongoing portfolio monitoring
- M&A and investment screening
- Insurance underwriting inputs
- Internal self-assessment
Delivery
- Web portal for risk teams
- API access for automation
- Scheduled reporting
- Alerting on material change
- Findings surfaced in ComplianceSuite workflows
Outputs
- 0–10 objective rating
- Domain-level sub-ratings
- Itemised findings with evidence
- Prioritised action plan
- Portfolio benchmarking
How it works
- 01
Define the portfolio
We onboard your vendor, supplier or portfolio-company list and map each entity to its internet footprint.
- 02
Discover assets
Internet-facing systems, domains and services attributable to each company are discovered automatically.
- 03
Assess and weight
Findings across the nine risk domains are scored and weighted by the value of the asset at risk.
- 04
Prioritise remediation
Each vendor receives an itemised action plan ordered by real exposure, not raw issue count.
- 05
Monitor continuously
Ratings update as footprints change, with alerts on deterioration and threshold breaches.
Where it is used
- Banks and payment institutions assessing outsourcing and ICT providers under DORA-style expectations
- Insurers underwriting cyber policies with objective, comparable risk evidence
- Corporates screening suppliers before onboarding and at contract renewal
- Private equity and investment teams assessing cyber exposure in a target
- Regulated firms evidencing ongoing third-party monitoring to supervisors
Outcomes teams report
- Questionnaire cycles shrink because evidence-based ratings answer most of the questions
- Remediation effort concentrates on the small share of findings that carry real exposure
- Risk committees see one consistent scale across the whole third-party portfolio
- Deterioration is caught between review cycles instead of at the next annual assessment
Frequently asked questions
Do we need the vendor’s permission to rate them?
No. The assessment is passive and outside-in, based on publicly observable internet-facing systems, so a rating can be produced before any vendor engagement.
How is this different from a security questionnaire?
Questionnaires are self-reported and point-in-time. RiskRecon is evidence-based and continuous, and produces a comparable score across your whole portfolio.
Can we rate our own organisation?
Yes. Many clients start by rating themselves to see what an attacker — or a customer — can observe from outside.
How does it support regulatory expectations?
It gives documented, repeatable evidence of ongoing ICT third-party monitoring, with history you can present to auditors and supervisors.
How is it delivered?
Through the RiskRecon portal and API, with Infocredit handling onboarding, portfolio setup, threshold design and analyst support locally.
Interested in RiskRecon?
One contract, local implementation and support — Securing Ease of Mind.
