account_tree Cyber & Privacy Supply Chain

The weakest link in your security may be the supplier you have not audited.

Cyber and privacy risk management across the supply chain, for companies whose exposure extends beyond their own perimeter.

Supply chain · mapping
warning
Unaudited logistics operator
Access to the order database, delivery data and customer contact details. No evidence of controls provided.
14
Suppliers
5
Critical
1
No evidence

Companies that already trust us

Electrolux Hypera Pharma Grupo Soma La Moda Grupo Boticário Metropolitano de Lisboa Grupo Supley L'Oreal MediaProbe Grupo Aço Cearense Grupo DPSP Grupo Tempus Obramax IOTA.HUB Diageo MEDX
Data chain of custody

How many hands touch your customer's order after the purchase.

A completed order generates a bundle of personal data that keeps circulating for days. Each handover is a new copy, in a system your team does not manage.

What moves at each handover
full name CPF address telefone order items amount paid
01
Your operation
Platform, gateway and anti-fraud
full order payment data
verified_userDirect control
02
Fulfilment operator
Receives the order via API to pick and ship
nome address itens
handshakeContract, no audit
End of your perimeter
03
Carrier
Imports the delivery list into its own system
nome address telefone
visibility_offNo visibility of access
04
Route subcontractor
A company the carrier hires and you do not know
nome address telefone
blockOutside any contract of yours
05
Courier
App on a personal device, high turnover
nome address telefone
smartphoneScreenshots and messaging groups
06
Outsourced reverse logistics and customer service
Exchanges, returns and post-delivery support
full order purchase history
support_agentExported database with no deletion deadline
4 custodians beyond the end of your perimeter

Under the LGPD, responsibility for the data remains with whoever collected it. Checkout anti-fraud does not reach any of these four hands.

The risk that comes from outside

Supplier-borne attacks doubled in one year.

Percentage of security breaches originating from third parties or suppliers.

Breaches originating from third parties
Observed 2026
40%30%20%10%0
2024
11.3% of breaches
11,3%
2025
22.5% of breaches
22,5%
2026
35.5% of breaches
35,5%
2024 2025 2026

Source: Cipher / x63 Unit, 2026.

22,5%
of 2025 breaches came from third parties
Double the figure observed the previous year.
€4.33M
average impact per incident
Estimated global cost of US$53.2B per year.
200+ days
to detect without monitoring third parties
Time during which the incident remains active in your chain.
The reality of most supply chains

More than 60% of data breaches involve a third-party supplier.

no_encryption

Suppliers without minimum security controls

Integrators, SaaS providers and service providers access critical systems without the business having any way to assess whether their controls are adequate for the risk they pose.

contract_delete

Personal data shared without adequate contracts

Data shared with suppliers without a DPA, without security clauses and without regular review. Regulatory exposure grows with every contract signed.

visibility_off

No visibility of third-party risk

Without a TPRM programme, every new supplier comes in as a black box. The incident usually appears first in the partner's environment and only later in your operation.

How the risk becomes visible

Supplier risk documented with evidence.

TPRM · Supplier scoring
Supplier
Criticality
Posture score
Gaps
Northern logistics operator
Critical
34
9
Marketplace integrator
Critical
58
5
Last-mile carrier
High
62
4
Customer service SaaS
Medium
81
2
Payment gateway
Medium
93
0
Profile · Northern logistics operator
Posture score
34
High criticality · access to customers' personal data
Data sharedName, address, phone
Access levelOrders API
Last assessmentFeb/2026
Evidence requested
Information security policyReceived
Access control and MFAMissing
Signed DPA with security clausesMissing
Incident response planUnder review
Subcontractor managementMissing
Team training recordReceived
Emergency action: suspend access to the orders API until the DPA is signed and MFA is enabled.
Executive report · Supply chain risk
14
Suppliers
5
High criticality
61
Average score
8
Pending DPAs
Risk distribution
Critical5
Attention4
Adequate5
Prioritised recommendations
01Review logistics operators' access to the order database
02Sign DPAs with security clauses in 8 active contracts
03Require MFA and a subcontractor register from the 5 critical suppliers
04Add a "third-party incident" scenario to the response plan
What we deliver

Visibility and control over the risk that comes from your suppliers.

A third-party risk management programme that assesses, classifies and monitors critical suppliers, integrating cyber security and data protection compliance.

inventory

Supplier inventory and classification

We map and classify suppliers by criticality, access level and type of data shared. This is the foundation of TPRM and sets where effort is prioritised.

fact_check

Third-party security assessment

Technical questionnaires, evidence review and security posture assessment of critical suppliers, with scoring and an individual gap report.

gavel

Contracts and security clauses

Review and drafting of DPAs and technical annexes aligned with the LGPD, GDPR and sector requirements, ready for signature.

monitor_heart

Continuous supplier monitoring

Periodic reviews with updated risk scoring, checks for public incidents and tracking of relevant operational changes.

emergency

Response to third-party incidents

A protocol for managing incidents where a supplier is the vector: containment, notification, impact analysis and regulatory communication as applicable.

summarize

Supply chain risk report

A consolidated executive report with a view of risk by supplier, trends and recommendations, for leadership, the board and external audits.

From inventory to contract.
From contract to monitoring.

The process is divided into strategic stages. Click each one to explore.

01
Identify suppliers
02
Define criticality
03
Supply Chain 360° Assessment
04
Action plan
05
Monitoring
06
Continuous improvement
hub

Identify suppliers

We map your business's critical processes and the suppliers involved, assessing potential cyber and compliance risks that could affect your organisation.

stacked_bar_chart

Define criticality

We classify suppliers by criticality, setting priorities and the depth of the analyses to be carried out.

travel_explore

Cyber & Privacy Supply Chain 360° Assessment

We carry out detailed analyses based on frameworks, best practice and data protection legislation. The more critical the supplier, the deeper the audit.

checklist

Action plan

We produce strategic and operational recommendations: emergency and medium/long-term actions, raising cyber security and data protection maturity.

query_stats

Monitoring

We put in place a follow-up process with clear indicators: executive reports per supplier, identification of risks and corrective actions, and compliance progress metrics.

autorenew

Continuous improvement

We revisit the process periodically, adjusting strategies and presenting risk and performance reports to your team and to suppliers.

Checkout Anti-Fraud One-Page, a free B10SEC resource
Free resource

Checkout Anti-Fraud

Strategies to protect your sales and data in real time: prevention, detection and response to the risks that grow between checkout and delivery. Designed to circulate among the board on a single page.

By completing this form, you agree that B10SEC will process your personal information solely to send you this material.

Your data is processed by B10SEC Proteção de Dados e Cibersegurança Ltda. to respond to your enquiry, on the basis of pre-contractual steps and legitimate interest. We keep the data for 12 months. You can exercise your rights of access, rectification, erasure, objection and portability by contacting our Data Protection Officer at dpo@b10sec.pt. Find out more in our Privacy Policy and exercise your Data Subject Rights.

Market comparison

What changes when there is a real programme.

Three ways of handling supplier risk, side by side, from inventory to the evidence the audit asks for.

Recommended
B10SEC
One-off questionnaire
No programme
Supplier mapping
check_circleBy criticality and risk
removeNon-existent
closeNone
Technical assessment
check_circleEvidence and questionnaires
removeForm only
closeNone
Contracts and DPAs
check_circleReviewed and updated
removeGeneric
closeMissing
Monitoring
check_circleContinuous with scoring
removeOne-off
closeNone
Audit evidence
check_circleReady and organised
removePartial
closeNon-existent
See the programme applied to your case arrow_forward

Scope defined by the number of suppliers and the criticality level of each one.

What sustains a third-party risk
programme over time.

Integrated technical and regulatory view

We assess suppliers on their cyber security posture and their data protection compliance, with a team that works on both fronts.

Scoring by supplier criticality

We prioritise effort where risk is highest: access to sensitive data, integration with critical systems and the number of exposed employees.

Defined review cycles

The programme runs on a cadence: scheduled review cycles, alerts on supplier changes and continuous updating of the risk register.

A deliverable ready for the external auditor

ISO 27001, SOC 2, NIS2 and the LGPD require evidence of TPRM. The programme produces this documentation in an organised way, available when the audit arrives.

Ready to control the risk that comes from outside?

Your perimeter extends to the last supplier in the chain.

Talk to a B10SEC specialist and find out how to structure a TPRM programme tailored to the number of suppliers, criticality level and regulatory requirements of your context.

Your data is processed by B10SEC Proteção de Dados e Cibersegurança Ltda. to respond to your enquiry, on the basis of pre-contractual steps and legitimate interest. We keep the data for 12 months. You can exercise your rights of access, rectification, erasure, objection and portability by contacting our Data Protection Officer at dpo@b10sec.pt. Find out more in our Privacy Policy and exercise your Data Subject Rights.

B10SEC

B10SEC: Security that protects what you cannot see yet.

comercial@b10sec.com
Most visited
Social
© 2026 B10SEC Proteção de Dados e Cibersegurança Ltda. All rights reserved.