Third Party Risk Pack
Tier your suppliers in an afternoon, assess the ones that matter, and fix the contracts that leave you exposed.
£69
one-time
4
included items
- Instant digital delivery
- Permanent access after purchase
- Single-organisation licence
- Editable working files
Your biggest breach risk is on someone else's payroll
Built for a real piece of work
Preparedness material for one licensed organisation. Adapt the working files before adoption; this is not legal advice.
Only a minority of small businesses ever review the security of their suppliers, yet the incidents that hurt most arrive through exactly that door: the IT provider with admin access, the payroll service holding your people's data, the SaaS tool nobody assessed. UK GDPR makes the point sharper. You may only use processors providing sufficient guarantees, and the regulator holds you primarily responsible for your processors' compliance.
This pack makes supplier security a process instead of a worry. List your suppliers from accounts payable, answer three questions per supplier, and the tiering formula sorts them into three levels of scrutiny. Tier 1 suppliers get a twenty-two question assessment with model good answers and red flags. Tier 2 and 3 get proportionate shorter versions. The twelve-clause contract library gives you the security terms to ask for at the next renewal, in plain language a supplier cannot pretend to misunderstand.
Customers increasingly push these requirements down their supply chain. This pack is how a small organisation answers credibly, and how a consultant runs supplier risk for every client from one instrument.
What you get
Everything included
4 included items
- 01Start Here guide (PDF)
- 02Supplier Security Guide (Word): tiering, assessment and the twelve-clause contract library
- 03Supplier Register & Toolkit (Excel): the tiered register with questionnaires for each tier
- 04Brandable versions of both working files (folder)
How it arrives
Digital delivery, clearly explained
Instant digital download: one zip file (RightCyber_Third_Party_Risk_Pack_v1.0.0.zip) containing everything listed above. Open the Start Here guide first. Nothing is posted.
Read the product and licence boundaries
Single organisation licence. Not for use across multiple client organisations. Contact RightCyber about consultant licensing for use across client engagements. These are preparedness materials, not legal advice. RightCyber provides independent cyber security documentation and support. It is not affiliated with, endorsed by, or approved by any government body, regulator, standards organisation or certification body referenced in its products.