Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.
Supplier and Third-Party Security
Your supply chain is part of your risk picture. Berigo helps you map, assess and follow up on suppliers and data processors in line with NIS2, the GDPR and ISO 27001.
No organisation is more secure than its weakest supplier. Cloud services, managed service providers, software vendors and subcontractors are now an integral part of the value chain, and therefore of the risk picture. An incident at a supplier can quickly become your own incident, and regulation reflects this: NIS2 sets explicit requirements for supply-chain security, the GDPR demands control over data processors, and ISO/IEC 27001 expects systematic supplier management.
Berigo helps organisations make supplier security part of governance rather than an annual questionnaire exercise. We combine experience in security, management systems and regulatory frameworks, and we work as readily with boards and executive teams as with procurement, IT and specialist functions. The goal is to give leadership a basis for decisions they can stand behind: which suppliers are critical, what risk they represent, and which requirements and controls are actually in place.
What we deliver
- Mapping and classification: a clear view of suppliers, dependencies and data flows, classified by how critical they are to the business.
- Third-party risk assessment: structured assessment of security, compliance and concentration risk at critical suppliers, with findings leadership can act on.
- Requirements and contracts: security requirements in procurement, agreements and data processing agreements, aligned with NIS2, the GDPR and ISO/IEC 27001.
- Audits and follow-up: supplier audits and privacy audits of data processors and critical vendors, with clear findings and prioritised actions.
- Integration into the management system: supplier management as a natural part of your ISMS, with roles, processes and documentation that work in practice.
- Reporting to management and the board: status, deviations and risk presented so that decisions can be made at the right level.
Who it is for
The service is relevant for organisations covered by NIS2 that must be able to document supply-chain security, for data controllers that need control over their data processors, and for any organisation whose operations, data or reputation depend on third parties. It suits both organisations establishing supplier management from scratch and those looking to professionalise an existing practice.
How an engagement starts
An engagement typically begins with a mapping of the supplier portfolio and a review of current practice against the relevant requirements. The result is a prioritised action list based on risk and maturity. From there, Berigo can support a defined project, for example audits of critical suppliers or new contractual requirements, or provide ongoing supplier management as an integrated part of your security work.
Related services
DPO as a Service
Berigo offers DPO as a Service, an independent data protection officer function that meets the requirements of GDPR Articles 37 to 39, without the need to hire in-house.
Risk Management
Digital risk is business risk. Berigo helps organisations integrate digital risk into enterprise risk management, with risk assessments that support decisions and maturity development that lasts.
Proven Executive Outcomes
Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.
Is your Board ready for NIS2?
Download the 2026 Executive Checklist for Cyber Liability.
Your address is used to send you the guide, and handled as described in our privacy statement. privacy statement.