The most rigorous TPRM platform available Audited depth from the inside, continuous visibility from the outside, scored on a single, comparable framework.
Nearly half of all cybersecurity incidents originate not in an organisation's own systems, but in their suppliers'. Yet most tools were never built to answer the one question that matters: how much can you actually trust a provider?
LEET TPRM rests on two complementary pillars that share a single control framework and a single rating language, so results stay comparable no matter which combination you apply.
Both pillars feed the same scoring system, so audit results and continuous exposure monitoring read side by side, as one coherent picture.
One reference framework rates cybersecurity, resiliency, and privacy across Confidentiality, Integrity, and Availability in five levels — from D to A+ — powering three progressively rigorous tiers of assurance:
Native EASM (External Attack Surface Management) capabilities, built into the same platform and the same report, never a bolted-on third-party feed:
Not every provider deserves the same level of scrutiny, and LEET TPRM is engineered to reflect that.
Here is how a multinational insurance company applies the model across hundreds of suppliers: More scrutiny as risk rises, from a self-assessment for the bulk of the supply chain to a full on-site LEET Rating for the providers that matter most.
| Risk Level | Methodology Tier | EASM Monitoring |
|---|---|---|
| No Risk | No formal rating required | Standard exposure monitoring |
| Low | Self-Assessment - conditional thresholds set against a quantitative score | Standard exposure monitoring |
| Medium | Assessment — higher thresholds | Enhanced TPRM-Monitoring |
| High | LEET Rating — top tier assurance | Enhanced TPRM-Monitoring |
LEET TPRM delivers targeted value to each team involved in supplier risk management, from Procurement through to the Board.
| Area | What LEET TPRM Delivers |
|---|---|
| Procurement | Cuts the risk of business disruption and makes supplier selection faster, simpler, and more defensible. |
| IT | Keeps the business ecosystem running on objective security controls and policies, with risk continuously reassessed, never a point-in-time snapshot. |
| Risk Mgmt | Minimises threats to continuity with complete, continuously updated intelligence on every supplier's cybersecurity posture. |
| DPO | Delivers a precise view of how third parties interact with company data, curbing unwanted access and reinforcing privacy compliance. |
| Compliance | Demonstrates, on an ongoing basis, compliance with the third-party controls demanded by regulations such as NIS2 and DORA. |
| Board & Exec | NIS2 and DORA carry personal liability. LEET TPRM supplies the evidence trail to prove governance, continuously, not just at renewal. |
NIS2 and DORA do not simply require supply-chain security measures, they require organisations to be able to demonstrate them, on an ongoing basis, not just at renewal. By combining an audited rating with continuous external monitoring, LEET TPRM turns compliance from a once-a-year exercise into a continuous, evidence-backed state, mapped to the most common international standards and regulations.
LEET TPRM has been validated by some of the most demanding supply-chain risk environments in Europe.
Runs a blended model across its entire supplier base: every RFP participant completes the LEET Self-Assessment, selected providers advance to LEET Assessment, and the organisation's most critical suppliers must hold a full LEET Rating. A simple decision matrix, based on rating level and activity risk, determines which providers are qualified, conditionally qualified, or not qualified.
Built on LEET Security's methodology and backed by Spain's Centro de Cooperación Interbancaria and the country's financial entities, Pinakes is the first platform in Europe for centralised cybersecurity risk management in finance. Banks supervise supplier security centrally, and providers demonstrate compliance once — recognised across the entire sector, replacing a landscape where every bank once audited the same providers separately.