Skip to content
Under attack?Get emergency help now
Third-Party Risk Management (TPRM) · Powered by Panorays

Prove your supply chain is secure. Continuously.

Every vendor scored 0 to 100, the way an attacker would. We run the whole program for you.

The whole idea, in 18 seconds.

Explainer poster: the vendors your business runs on, ready to be scored 0 to 100

Your business runs on companies you don't control.

Cloud & software
Payments & banking
Payroll & HR systems
Data & IT providers
Logistics & freight
Contractors & agencies

Every one of them holds your data, your money or your uptime. When one of them is breached, it becomes your breach. Your clients, your regulator and your board will ask you, not them.

Questionnaires by hand. Proof that expires on arrival.

Hundreds of vendors, a handful of analysts.

Spreadsheets, email chases and PDF screenshots don't scale.

Self-reported ticks.

Nobody verifies what the vendor claims. Auditors know it.

Out of date on arrival.

A vendor's risk changes weekly. Your last assessment doesn't.

Blind below tier one.

Your vendor's vendors can take you down, and you can't see them.

The uncomfortable truth

A questionnaire is a photograph.

Your risk is a live video.

Vendors get breached, lose certifications and expose new systems every week. Point-in-time audits can't see any of it.

Regulators moved first. The accountability is yours.

South Africa

Joint Standard 2 of 2024 makes third-party oversight a supervisory requirement for financial institutions. POPIA carries fines up to R10 million plus criminal liability.

United Kingdom & EU

DORA and NIS2 put vendor risk on the board's desk, with strict incident reporting duties and personal accountability for oversight failures.

Your contracts

Major clients, tenders and insurers now demand continuous evidence of supplier security as a condition of doing business at all.

Non-compliance is no longer a paperwork problem. It is fines, lost contracts and personal exposure.

How it works

Two views of every vendor. One defensible score.

What your vendors claim, checked against what an attacker can actually see. Continuously, with nothing installed anywhere.

Outside-in

The attacker's view. No permission needed.

  • Starts with one domain, nothing else
  • Maps every connected asset: subdomains, IPs, mail, cloud, open ports
  • Hundreds of non-intrusive tests: web, DNS, TLS, reputation, breach history
  • First rating ready within hours

Inside-out

The vendor's claims, put to the test.

  • AI questionnaire matched to each vendor's risk profile
  • Suggested answers speed vendor completion
  • AI validates answers against real evidence, not ticks
  • Covers internal controls: policies, encryption, access, compliance

Cross-checked automatically. A vendor claims all traffic is encrypted, the scan finds expired certificates. The gap surfaces on its own.

Verified evidence, weighted to your business.

1

Inherent risk

Every vendor tiered 1 to 5 by the damage they could actually do to you: data held, access granted, criticality.

2

External scan

116+ automated tests on every internet-facing asset, refreshed about every 72 hours and mapped to known CVEs.

3

AI questionnaires

Auto-generated, evidence-validated answers. Claims are checked against the scan, not taken on trust.

4

Your risk policy

The final score is weighted to your risk appetite and policies, so it stands up in front of auditors.

Plus: 4th and Nth-party discovery, dark web mentions, live breach alerts, prioritised remediation plans and board-ready reporting.

What changes, in numbers.

0%

lower third-party risk

0%

less evaluator time

0%

more vendors uncovered

0%

less downtime

~1

full-time hire saved

Measured across Panorays customer deployments. Forrester Wave™ Leader, Cyber Risk Rating Platforms, Q2 2026. Platform certified ISO 27001, SOC 2 Type II and ISO 42001.

We've sat on your side of the table.

We did not reinvent this. We partnered with the specialist who has spent years perfecting it, and we run it for you.

We've sat on your side of the table

Our team has answered banks' vendor security questionnaires by hand, for real clients. This automates exactly what we lived.

16+ years in IT and security

Built on financial services clients who never accept second best.

Local and accountable

South African roots, serving SA, the UK and the EU. A named team in your timezone, no offshore handoffs.

A select partnership

One of only a few authorised Panorays MSSP partners in South Africa.

You get the outcome, not the workload.

Running vendor risk by hand eats hours you don't have. So we run it. Fully managed, or co-managed alongside your team.

Build and run your third-party risk program
Create and send custom questionnaires
Onboard suppliers and drive response rates
Monitor continuously with live breach alerts
Send prioritised remediation plans
Deliver monthly and board-level reporting

From first look to board report in 90 days.

Week 0

Live demo

See the platform map and score a vendor base like yours, live, before you commit to anything.

Weeks 1 to 4

Onboard & tier

We stand up your program, onboard suppliers and rank every vendor by the damage they could do.

By month 3

Monitor & report

Continuous scoring is live, and the first board-ready report is in your hands.

The demo costs you 45 minutes and shows your own kind of supply chain, mapped live.

Third-party risk, answered.

What is third-party risk management (TPRM)?

Third-party risk management is the practice of identifying, scoring and continuously monitoring the security of the vendors and suppliers your business relies on. Attackers often breach a business through a weaker third party, so managing that risk is now a core part of cybersecurity and compliance.

Why does vendor risk matter if our own systems are secure?

Your suppliers can access your data, systems and email. If one of them is compromised, attackers can reach you through that trusted connection even when your own defences are strong. A single weak vendor can become the entry point for a breach.

How does F1's managed TPRM service work?

We run third-party risk management for you as a managed service, powered by Panorays. Every vendor is assessed and scored from 0 to 100 the way an attacker would see them, from the outside in. We monitor them continuously and flag changes, so you always know where your supply chain stands without drowning in paperwork.

What is Panorays?

Panorays is a third-party security ratings and monitoring platform. F1 uses it to evaluate and continuously monitor your vendors, combining an outside-in view of their attack surface with security questionnaires into a single risk score.

How often are vendors re-assessed?

Continuously. A vendor's risk can change from week to week as new vulnerabilities appear, so monitoring is ongoing rather than a once-a-year questionnaire. You are alerted when a vendor's risk changes.

Which regulations and standards does TPRM help with?

Managed third-party risk supports compliance with POPIA and GDPR, and frameworks that increasingly require supply-chain oversight such as the Joint Standard 2 of 2024, DORA and NIS2.

Prove it continuously. Let us run it for you.

Serving South Africa, the United Kingdom and the European Union. Fully managed or co-managed.