Home • Services • TPRM-Reifegradanalyse für 360TPRM

360TPRM – Identify and Manage Third-Party Risks Holistically

Intelligence-driven Third-Party Risk Management for transparent,

resilient, and audit-ready supply chains

Third-Party Risk Management in the Context
of Cybersecurity, Compliance, and Resilience


Companies today are more dependent than ever on suppliers, cloud services, software providers, and other business partners. At the same time, cyber risks, geopolitical conditions, and regulatory requirements are constantly changing. Traditional supplier lists and occasional self-assessments are therefore no longer sufficient to reliably manage critical dependencies.

360TPRM brings supplier, risk, and evidence data together on a central platform. The solution combines structured assessments with continuous Cyber Threat Intelligence and makes it visible which business processes, products, and value chains are affected by a third party or sub-supplier. This creates a reliable basis for risk-based decisions – from onboarding through offboarding.

360TPRM Features from darkscope


360TPRM helps organizations manage risks across the entire third-party lifecycle in a structured and scalable manner.

  • Central register for suppliers, service providers, and other third parties
  • Criticality assessment and risk-based tiering
  • Structured assessments with deadlines, reminders, and supplier access
  • Linking self-assessments with external evidence
  • Continuous Cyber Threat Intelligence and event-driven alerts
  • Mapping suppliers to business processes, products, and value chains
  • Mapping sub-suppliers, Tier-N dependencies, and concentration risks
  • Support for relevant frameworks and requirements, such as NIS2, DORA, ISO 27001, and TISAX/VDA ISA
  • Documentation of findings, measures, exceptions, and decisions
  • Audit trails, evidence tracking, and meaningful management reporting

These features create a shared data and decision-making basis for Procurement, Information Security, Data Protection, Compliance, Business Continuity, and business units.

Third-Party Lifecycle Management


Third-Party Lifecycle Management describes the end-to-end management of supplier and service-provider risks – from the initial request through ongoing collaboration to the orderly termination of the business relationship.

Objectives of Third-Party Lifecycle Management:

  • Identify critical third parties at an early stage
  • Align assessments with risk and business relevance
  • Manage approvals, measures, and responsibilities transparently
  • Identify changes and new risks throughout the relationship
  • Ensure resilience, auditability, and secure termination

Onboarding

New third parties are recorded, assigned to a Business Owner and the relevant services, and classified according to criticality and inherent risk. The appropriate assessment and approval process is then initiated.

Monitoring

Throughout the business relationship, assessments, evidence, and external risk signals are brought together. Relevant changes can trigger targeted reassessments, measures, or escalations.

Offboarding

At the end of the relationship, access rights, the return or deletion of data, outstanding findings, contractual obligations, and potential dependencies are systematically completed and documented.

Continuous Monitoring & Cyber Threat Intelligence


Risks do not arise only when a supplier is selected. The security situation, ownership structure, availability, or external conditions can change significantly during the term of a contract. 360TPRM therefore supplements periodic assessments with continuous external signals and supplier-specific Cyber Intelligence.

Typical Monitoring Areas Include

  • Indicators of exposed credentials or compromised accounts
  • Anomalies involving accessible systems, certificates, and security characteristics
  • Cyber incidents and changes to the externally visible attack surface
  • Availability and indicators of operational disruptions
  • Data protection, reputation, and transparency indicators
  • Country, geopolitical, and sanctions risks
  • Changes in critical dependencies and sub-suppliers

Sources, confidence scores, and risk impacts help classify signals and have them reviewed by the responsible experts. This turns external signals into traceable decisions and targeted measures.

Continuous Monitoring

In the DACH market, companies face the challenge of creating an up-to-date picture of their critical dependencies from established supplier, contract, and IT data – going far beyond annual questionnaires. With 360TPRM, we combine continuous Cyber Intelligence, transparent value chains, and audit-ready processes. As OEDIV, we provide consulting, Managed Services, and secure German data center operations from a single source – enabling our customers not only to document risks, but also to identify them early and manage them effectively.


Robert Hauschild
Senior Sales Manager, OEDIV SecuSys GmbH

Understand Risks Where They Impact the Business


A conspicuous supplier score alone does not answer what the consequences of an outage would be for the company. 360TPRM maps third parties to the affected business processes, products, organizational units, and value chains. Direct relationships with sub-suppliers can also be mapped.

This Makes the Following Visible, Among Other Things:

  • Dependencies of critical products and services on individual providers
  • Shared sub-suppliers behind multiple direct suppliers
  • Concentrations by provider, technology, region, or service
  • Impact of an incident on business processes and customer services
  • Need for action regarding Business Continuity, substitution, and exit planning

This business-oriented perspective helps management, Procurement, and risk functions focus resources on the dependencies with the greatest impact.

System Integration and Data Connectivity


360TPRM is integrated into existing procurement, supplier, and risk processes. Existing data can be transferred and supplemented with risk, assessment, and intelligence information. This creates a shared supplier view without requiring established system landscapes to be completely replaced.

Typical Integrations and Data Sources Include:

  • ERP and procurement systems, such as SAP or Oracle
  • Existing supplier registers and Excel-based data
  • Contract and vendor management systems
  • GRC, ISMS, and compliance solutions
  • Identity and Access Management systems
  • Business Continuity and Service Management processes
  • APIs for automated data exchange

Through integration, supplier data, Business Owners, criticality levels, assessment status, and measures can be kept consistent. Procurement, approval, monitoring, and reporting processes can therefore work together more effectively.

Create Transparency Around Your Critical Third Parties

Find out how 360TPRM brings supplier, cyber, and dependency risks together in a shared situational overview – and how you can achieve reliable results quickly with a clearly defined starting point.

FAQ

Frequently Asked
Questions

Here you will find answers to the most important questions

about our services and solutions.

What Is Third-Party Risk Management and Why Is a Traditional Supplier Assessment Not Enough?

Third-Party Risk Management manages risks arising from suppliers, service providers, cloud providers, business partners, and their sub-suppliers. A traditional supplier assessment often focuses primarily on price, quality, and delivery reliability or is based on a one-time self-assessment. However, cyber risks, data access, regulatory requirements, and operational dependencies are constantly changing.

Effective TPRM therefore combines a reliable third-party inventory with risk-based assessments, continuous monitoring, action management, and clear mapping to critical business services.

A ‘big bang’ rollout is not usually necessary. First, existing supplier data from ERP, procurement or Excel systems is consolidated into a central register. Business-critical services and the relevant third parties are then prioritised. A sensible starting point is often to focus on the 20 to 50 most critical services and suppliers. From there, data quality, audit trails and monitoring can be expanded step by step.

No. External signals cannot fully assess internal controls, the terms of contracts, tested contingency plans or subcontractors that are not publicly visible. 360TPRM uses cyber intelligence and external evidence to verify self-reported information, apply questionnaires in a more targeted manner and trigger a reassessment in the event of relevant changes. This reduces the amount of manual work required, whilst allowing critical issues to be examined in greater depth.

360TPRM supports the structured recording of third parties, criticality levels, controls, evidence, findings and actions. Relevant frameworks can be used as a basis for audit and verification processes; shared evidence can be reused to meet multiple requirements. Audit trails and reporting facilitate traceability for management, customers and auditors. The platform thus supports implementation and documentation – however, it does not automatically ensure a company’s regulatory compliance.

360TPRM combines traditional TPRM workflows with continuous cyber threat intelligence and a business-oriented view of value chains, products and Tier-N dependencies. This not only reveals whether a supplier poses a risk, but also which services and business areas may be affected. Added to this are the consultancy and managed services provided by OEDIV SecuSys, as well as SaaS operations in OEDIV’s German data centres. This creates a combination of platform, intelligence, expert support and reliable operations.