SUPPLIER SECURITY / FIRST ORIENTATION

How much risk are you actually inheriting?

Before giving a supplier access to sensitive information, systems or critical operations, establish what the relationship exposes — and how much confidence you have in the controls protecting it. This check looks at exposure and assurance separately.

Approx. 7 minutes Anonymous Local browser analysis Immediate risk orientation
01
Define exposureWhat access, dependency and information are you giving away?
02
Assess assuranceWhat evidence supports confidence in the supplier controls?
03
Identify red flagsFind issues that should not disappear inside an average score.
04
Decide next actionTurn the signal into focused supplier questions and next steps.
01

Relationship Criticality

How much operational dependency would the supplier relationship create?

Could failure of this supplier interrupt a critical operation, programme or customer commitment?
Would replacing this supplier require substantial time, specialist knowledge or requalification?
Will the supplier support a security-sensitive, defence-related or otherwise high-consequence activity?
Would a security incident at the supplier create material financial, contractual, reputational or mission impact for your organisation?
02

Information & Access

What information, systems, privileges and physical access will the supplier receive?

Will the supplier receive sensitive technical, commercial, customer, programme or protected information?
Will supplier personnel connect to your internal systems, customer environments or production infrastructure?
Will the supplier receive privileged, administrator or service-account access?
Will supplier personnel require recurring physical access to sensitive facilities, work areas or equipment?
03

Cyber & Information Security

Identity, access, endpoint, vulnerability and security-monitoring assurance.

Are multi-factor authentication and strong identity controls used for relevant systems and remote access?
Are endpoint protection, patching and vulnerability-management practices established and evidenced?
Are privileged and administrator accounts individually assigned, restricted and monitored?
Can the supplier provide meaningful evidence of logging, monitoring and detection for relevant security events?
04

Personnel & Insider Exposure

Role-based access, confidentiality, personnel changes and security awareness.

Are access rights granted on a defined role and need-to-know basis?
Are confidentiality obligations and appropriate personnel-screening measures established where the role requires them?
Are joiner, mover and leaver processes defined so access is changed or removed promptly?
Do personnel with relevant access receive recurring security awareness and role-specific guidance?
05

Supply Chain & Jurisdiction

Downstream suppliers, data locations, ownership and foreign dependencies.

Can the supplier identify subcontractors or downstream providers that may access or process your information?
Are the countries and jurisdictions in which relevant data is stored, processed or remotely accessed known and controlled?
Are ownership, control and material foreign dependencies sufficiently transparent for the relationship?
Does the supplier apply security expectations to its own relevant suppliers and verify them proportionately?
06

Incident & Resilience

Notification, recovery, continuity and the supplier's ability to sustain critical delivery.

Is there a defined requirement to notify you promptly of security incidents that could affect your information, systems or services?
Are backup, recovery and ransomware-response capabilities defined and tested for relevant services?
Can the supplier continue or restore critical delivery following loss of key systems, facilities or personnel?
Are continuity and incident arrangements exercised or otherwise supported by recent evidence?
SUPPLIER RISK SIGNAL

Indicative supplier risk profile

Relationship Exposure
Security Assurance
Residual Supplier Risk
CRITICAL OBSERVATIONS

Issues that should not disappear inside an average score.

QUESTIONS TO ASK YOUR SUPPLIER

Turn weak assurance into focused due diligence.

ASSURANCE BY DOMAIN

Where confidence appears weaker.

RECOMMENDED NEXT ACTION

Need a defensible supplier decision?

Artefaktum can turn this first orientation into a structured Supplier Security Review based on evidence, contracts, access conditions and the actual operational context.

Request Supplier Security Review →
This self-assessment provides an initial supplier-risk orientation only. It is not a formal audit, certification, compliance determination, security clearance, legal opinion or approval of a supplier. Results depend solely on the answers provided and do not replace evidence review, contractual analysis, technical verification, project-specific requirements or competent-authority guidance.
Confidential Consultation

Start a confidential conversation.

Share the essential context of your request.