Supply chain
Supply-chain cyber risk: mapping Critical Third Parties
ENISA names supply chain among the dominant 2026 threats, with Critical Third Parties carrying high impact.
Map critical suppliers (access, data, dependency), assess their posture, and contractually require controls (TOMs, audit, incident notification). NIS2 and DORA mandate ICT/third-party mapping. MiliSec maintains the third-party risk register and treatment plan.
The MiliSec method
What we run for our Virtual CISO clients:
- Map critical third parties.
- Contractual security clauses.
- Monitor and test providers.
Going further
Map critical suppliers and assess their posture.
Contractualise security requirements and incident notification.
Besoin d'un RSSI Virtuel ?
Notre veille alimente nos recommandations de conformité. Contactez-nous pour un diagnostic.
Demander un audit