Vendor Risk Assessment
Your security posture includes every supplier with a connection into your environment or a copy of your data. Astra assesses third parties against a consistent framework — what they hold, how they protect it, what they are contractually obliged to do, and what happens when they have an incident.
What you get
Outcomes, not activity.
- Exposure mappedWhich vendors touch sensitive data, how it moves, and where their systems integrate with yours — the points that become your problem.
- Controls verified, not assumedNetwork defences, access control, encryption in transit and at rest, and physical security assessed against evidence rather than a self-assessment questionnaire.
- Contractual and regulatory alignmentAgreements reviewed for security obligations, breach notification timelines and the data protection requirements that apply to your sector.
- Incident readinessWhether the vendor can detect, respond to and tell you about an incident on a timeline that works for your own obligations.
How it runs
A defined sequence, agreed up front.
You know what happens in each stage, who is involved, and what lands at the end of it before the engagement starts.
- 01
Tier the vendor population
Suppliers are ranked by data sensitivity and integration depth so effort goes where the exposure is.
- 02
Assess
Policy and evidence review, technical questionnaire, and where warranted a direct assessment of the vendor's controls.
- 03
Review agreements
Contracts and data processing terms are checked for the security and incident clauses your obligations require.
- 04
Report and monitor
Findings, risk ratings and required remediation per vendor, with a re-assessment cadence proportionate to tier.
Deliverables
What lands on your desk.
Written for two audiences: the engineers who have to fix it and the executives who have to fund it.
- Vendor tiering model and assessed inventory
- Per-vendor risk report with findings and ratings
- Contract and data processing gap analysis
- Remediation requirements and tracking
- Ongoing assessment schedule
Next step
Scope a vendor risk engagement.
Half an hour with a practitioner. You will leave knowing what the work involves, roughly how long it takes, and what it would find.

