Request demo

Supply Chain Security

Watch Every Tier of Your Supply Chain.

A supplier’s compromise rarely stays with the supplier: it reaches you through shared data, shared access or a component you rely on. The Deepinfo Platform treats each supplier, at any tier, as its own portfolio on the External Attack Surface Management engine, and Cyber Threat Intelligence adds context on the actors aiming at your sector.

  1. You

    • acme.example (scanned)

  2. Tier 1

    • Logistics (scanned)

      freight.example

    • Payroll (scanned)

      payroll.example

    • Packaging (scanned)

      packaging.example

  3. Tier 2

    • Hosting provider (scanned)

      hosting.example

    • Software provider (carries that CVE) (scanned)

      erp-vendor.example

    • Service provider (scanned)

      helpdesk.example

    • Cloud provider (scanned)

      cloud.example

  4. Tier 3

    • Component maker (scanned)

      components.example

Tiers 2 and 3: added as your team maps them

Event

An actor · targets your sector · uses a CVE

Tier 2 · Software provider: carries that CVE

Contracts end at tier one. Exposure doesn’t.

The hosting, software and service providers your suppliers depend on usually get no review from you, although a breach there can reach you through them. Mapping those dependencies is your team’s work. Watching them, once mapped, is what the platform does.

One Model at Each Tier.

Tiers organize portfolios. They are not a different product: a supplier three tiers down gets the same scanning, issues and score as a direct one.

TierTypical entitiesWhat the platform does
Tier 1Direct suppliers under contract with youA portfolio per supplier: discovery, scanning, issues and a score
Tier 2Hosting, software and service providers your suppliers depend onThat portfolio model, added as your team maps each dependency
Tier 3 and beyondComponent makers and providers further down the chainSame model again: depth is set by your map, not by the scanning
Your groupSubsidiaries and acquired entities that share the chainPortfolios of their own, read on one scale

Map the Chain and Act on What It Shows.

  1. 01

    Map

    Start from your tier-one list and ask each supplier which providers it depends on for hosting, software and services.

  2. 02

    Add

    Create a portfolio for each entity from its primary domain. Discovery maps its assets and your team approves them.

  3. 03

    Watch

    Notification rules cover supplier assets like your own: new and reappeared issues, score drops, new open ports.

  4. 04

    Correlate

    When an actor aimed at your sector lists a CVE among the ones it uses, check which supplier assets carry that CVE.

  5. 05

    Act

    Take the evidence to the supplier, or to the tier-one partner that manages it, and track the issue to a verified fix.

Questions About Supply Chain Security

How is supply chain security different from third-party risk management?

Third-party risk management usually covers the vendors you contract with directly. Supply chain security follows the dependency further, to the providers your suppliers rely on. On the platform both use the same portfolio model.

Does the platform find our suppliers’ suppliers automatically?

No. Your team decides which entities belong in the chain. Once a supplier is added, discovery maps its own internet-facing assets, including related domains that share its registrant or mail servers.

Do suppliers have to install anything?

No. Discovery and scanning read what each supplier exposes on the public internet: DNS, certificates, WHOIS, open ports and web responses. There is no agent and no login.

Will discovery find every host a supplier runs?

It finds what links back to the supplier in public data: a shared registrant, mail servers, name servers, IP addresses and certificate names. A host with no public link can be added to the supplier’s portfolio by hand.

What can’t external scanning see?

Anything not reachable from the internet: internal networks, endpoint controls, policies and people. Questionnaires and contracts still cover those, at each tier.

Is the threat actor context specific to our sector?

Actor profiles record the industries, countries and organizations each actor targets, so your team can filter to the actors aiming at your sector and at the sectors your suppliers serve.

Start With Tier One, Then Go Deeper.

Bring your tier-one list and a few of the providers behind it to a demo.