Supply Chain Security
Watch Every Tier of Your Supply Chain.
A supplier’s compromise rarely stays with the supplier: it reaches you through shared data, shared access or a component you rely on. The Deepinfo Platform treats each supplier, at any tier, as its own portfolio on the External Attack Surface Management engine, and Cyber Threat Intelligence adds context on the actors aiming at your sector.
-
You
-
acme.example (scanned)
-
-
Tier 1
-
Logistics (scanned)
freight.
example -
Payroll (scanned)
payroll.
example -
Packaging (scanned)
packaging.
example
-
-
Tier 2
-
Hosting provider (scanned)
hosting.
example -
Software provider (carries that CVE) (scanned)
erp-
vendor. example -
Service provider (scanned)
helpdesk.
example -
Cloud provider (scanned)
cloud.
example
-
-
Tier 3
-
Component maker (scanned)
components.
example
-
Tiers 2 and 3: added as your team maps them
Event
An actor · targets your sector · uses a CVE
Tier 2 · Software provider: carries that CVE
Contracts end at tier one. Exposure doesn’t.
The hosting, software and service providers your suppliers depend on usually get no review from you, although a breach there can reach you through them. Mapping those dependencies is your team’s work. Watching them, once mapped, is what the platform does.
One Model at Each Tier.
Tiers organize portfolios. They are not a different product: a supplier three tiers down gets the same scanning, issues and score as a direct one.
| Tier | Typical entities | What the platform does |
|---|---|---|
| Tier 1 | Direct suppliers under contract with you | A portfolio per supplier: discovery, scanning, issues and a score |
| Tier 2 | Hosting, software and service providers your suppliers depend on | That portfolio model, added as your team maps each dependency |
| Tier 3 and beyond | Component makers and providers further down the chain | Same model again: depth is set by your map, not by the scanning |
| Your group | Subsidiaries and acquired entities that share the chain | Portfolios of their own, read on one scale |
Point the Engine Down the Chain.
Third-Party Risk Management does the scanning and scoring. Cyber Threat Intelligence says who is likely to come looking.
Vendor Discovery
Maps each supplier’s subdomains, IPs and related domains from its primary domain, including group companies that share its registrant or mail servers.
Continuous Monitoring
Scans each supplier asset across all data layers and raises changes, such as a new open port or a certificate change, as events.
Vendor Risk Assessments
Findings on supplier assets, from weak TLS to known exploited CVEs, each with evidence and a severity.
Vendor Risk Scoring
Scores each supplier, at any tier, on the scale your surface uses.
Threat Actor Intelligence
Profiles record the industries and countries each actor targets and the CVEs and tools it uses. Filter by the sectors in your chain.
Map the Chain and Act on What It Shows.
-
01
Map
Start from your tier-one list and ask each supplier which providers it depends on for hosting, software and services.
-
02
Add
Create a portfolio for each entity from its primary domain. Discovery maps its assets and your team approves them.
-
03
Watch
Notification rules cover supplier assets like your own: new and reappeared issues, score drops, new open ports.
-
04
Correlate
When an actor aimed at your sector lists a CVE among the ones it uses, check which supplier assets carry that CVE.
-
05
Act
Take the evidence to the supplier, or to the tier-one partner that manages it, and track the issue to a verified fix.
Use This Data in Your Tools
Your tools can look up any company’s domains, subdomains and registration data through the API, from the index the Deepinfo Platform scans vendors with.
Questions About Supply Chain Security
How is supply chain security different from third-party risk management?
Third-party risk management usually covers the vendors you contract with directly. Supply chain security follows the dependency further, to the providers your suppliers rely on. On the platform both use the same portfolio model.
Does the platform find our suppliers’ suppliers automatically?
No. Your team decides which entities belong in the chain. Once a supplier is added, discovery maps its own internet-facing assets, including related domains that share its registrant or mail servers.
Do suppliers have to install anything?
No. Discovery and scanning read what each supplier exposes on the public internet: DNS, certificates, WHOIS, open ports and web responses. There is no agent and no login.
Will discovery find every host a supplier runs?
It finds what links back to the supplier in public data: a shared registrant, mail servers, name servers, IP addresses and certificate names. A host with no public link can be added to the supplier’s portfolio by hand.
What can’t external scanning see?
Anything not reachable from the internet: internal networks, endpoint controls, policies and people. Questionnaires and contracts still cover those, at each tier.
Is the threat actor context specific to our sector?
Actor profiles record the industries, countries and organizations each actor targets, so your team can filter to the actors aiming at your sector and at the sectors your suppliers serve.
Start With Tier One, Then Go Deeper.
Bring your tier-one list and a few of the providers behind it to a demo.