Start With Where

Understand where third parties matter to your business.

Start With Where is our approach to making third-party risk management relevant. We begin with your business—the services you deliver, the processes that support them and the third parties they depend on—so that assessments, priorities and continuity planning are grounded in what actually matters.

The output is a clear view of your important dependencies and where a third-party problem could become a business problem.

It's not just about who your suppliers are.

Most third-party risk programmes begin with a list of suppliers and send assessments to all of them. The result is often a lot of activity that doesn't clearly connect to business priorities.

We start somewhere different: with your business. By understanding which services and processes matter most, and which third parties they depend on, we can focus attention where a disruption would have real consequences.

This doesn't replace risk assessment. It makes it more useful.

The methodology

Five connected steps.

  1. 01

    Identify your business services

    We begin by understanding the services your organisation delivers—whether to external customers or internal functions—and why each one matters to your operations and objectives.

  2. 02

    Map the supporting processes

    For each important service, we identify the business processes that enable it, including the people, systems and activities involved in delivery.

  3. 03

    Map the dependencies

    We identify which third parties support those processes, what each one provides and the information or systems they can access.

  4. 04

    Assess the potential impact

    We consider what could happen if each third party experiences a security incident, service failure or other disruption—and what that would mean for the business services that depend on them.

  5. 05

    Focus risk management and continuity

    We use that understanding to prioritise assessments, treatment planning and continuity preparation for the dependencies that carry the greatest potential business impact.

The output is a clearer view of your important dependencies and the business impact associated with them.

Better questions. Clearer answers.

When you understand dependencies, the questions you ask about third parties become more specific. Instead of asking only whether a supplier has adequate security controls, you can explore:

  • Which services would be affected if this third party became unavailable?
  • What processes depend on their product, service or data?
  • What information or systems can they access?
  • How quickly could we respond, and what would we need in place?
  • What workarounds or alternatives exist if they fail?

One methodology. Two ways to use it.

Start With Where shapes how we deliver our Managed Third-Party Risk Management service and how organisations use VenDefend to run their own programmes. Whichever route you choose, the work starts with your business.

Start with a conversation about where your business depends on others.

Tell us about the services that matter most to your organisation. We will discuss how mapping dependencies can sharpen your third-party risk management.