Third-Party Risk Management

Full Visibility and Validated Data Across Your Entire Supply Chain

The most rigorous TPRM platform available Audited depth from the inside, continuous visibility from the outside, scored on a single, comparable framework.



LEET TPRM — Risk Coverage at a Glance
Self-Assessment
400-question questionnaire — low-risk suppliers, at scale
Low Risk
LEET Assessment
Documentary evaluation — security programme design
Medium Risk
LEET Rating
On-site audit + continuous perimeter monitoring
High Risk
Pillar 2 — EASM Native
Continuous external monitoring — built in, not bolted on
All Tiers
Single Framework
D → A+ scale · 1,300+ controls · NIST, GDPR, NIS2, DORA

Your Exposure Doesn't End at Your Own Perimeter

Nearly half of all cybersecurity incidents originate not in an organisation's own systems, but in their suppliers'. Yet most tools were never built to answer the one question that matters: how much can you actually trust a provider?

Every provider carries a different level of risk and demands a different level of scrutiny. A one-size-fits-all approach, whichever you pick, always leaves gaps.
Certificates & Standards (ISO 27001)
Confirm a management system exists, not that the controls behind it actually work or how robust they are.
Self-Built Questionnaires
Demand constant effort to design and supervise, effort often skipped, leaving them unreliable in practice.
External Audits
Expensive to repeat per client, and results cannot be reused across your supplier base.
Perimeter / Outside-In Scans
Convenient, but surface only public reputational exposure, never the operational controls that actually protect the service.

Two Pillars, One Unique Framework

LEET TPRM rests on two complementary pillars that share a single control framework and a single rating language, so results stay comparable no matter which combination you apply.

Both pillars feed the same scoring system, so audit results and continuous exposure monitoring read side by side, as one coherent picture.

Pillar 1
Comprehensive and Adaptive Methodology
The inside view

One reference framework rates cybersecurity, resiliency, and privacy across Confidentiality, Integrity, and Availability in five levels — from D to A+ — powering three progressively rigorous tiers of assurance:

Self-Assessment 400-question questionnaire, no external verification. Best for lower-risk providers, at scale.
LEET Assessment Documentary evaluation in which an analyst reviews submitted evidence, rating the design of the security programme itself.
LEET Rating The highest level of assurance: on-site audit + continuous perimeter monitoring, with detailed report, improvement recommendations, and compliance mappings.
Pillar 2
Continuous External Monitoring
The outside view

Native EASM (External Attack Surface Management) capabilities, built into the same platform and the same report, never a bolted-on third-party feed:

Standard TPRM Track up to five key providers by exposure score, external asset count, and number of detected issues, without technical detail. Available as a free tier.
Enhanced TPRM Full visibility into providers' internet-facing assets and exposure, with detailed information about potential issues and recommendations to reduce cyber risk.

Matching Scrutiny to Risk

Not every provider deserves the same level of scrutiny, and LEET TPRM is engineered to reflect that.

Here is how a multinational insurance company applies the model across hundreds of suppliers: More scrutiny as risk rises, from a self-assessment for the bulk of the supply chain to a full on-site LEET Rating for the providers that matter most.

Risk Level Methodology Tier EASM Monitoring
No Risk No formal rating required Standard exposure monitoring
Low Self-Assessment - conditional thresholds set against a quantitative score Standard exposure monitoring
Medium Assessment — higher thresholds Enhanced TPRM-Monitoring
High LEET Rating — top tier assurance Enhanced TPRM-Monitoring

The Only Model That Combines Both Dimensions



One comparable scale, inside and out
The only model combining validated self-assessment, documentary assessment, and on-site audit alongside native exposure data, on a single comparable framework. Competitors give you one or the other.
EASM is native, not an add-on
Continuous exposure lives in the same platform and report as the audited rating — never a third-party feed stitched on top.
Efficient for vendors
A provider rated once can present that same rating to multiple clients, cutting questionnaire and audit fatigue across the entire ecosystem.
Built for suppliers of every size
A dedicated SME-friendly framework assesses smaller providers on the controls that matter most — without diluting the rigour of the overall programme.
More scrutiny as risk rises
From a self-assessment for the bulk of the supply chain to a full on-site LEET Rating for the providers that matter most.
Sector-proven, not theoretical
Adopted by a multinational insurer across its entire supplier base, and by the Spanish financial sector through PINAKES, the first cybersecurity risk rating platform of its kind in Europe.

The Right Intelligence for Every Function

LEET TPRM delivers targeted value to each team involved in supplier risk management, from Procurement through to the Board.

AreaWhat LEET TPRM Delivers
Procurement Cuts the risk of business disruption and makes supplier selection faster, simpler, and more defensible.
IT Keeps the business ecosystem running on objective security controls and policies, with risk continuously reassessed, never a point-in-time snapshot.
Risk Mgmt Minimises threats to continuity with complete, continuously updated intelligence on every supplier's cybersecurity posture.
DPO Delivers a precise view of how third parties interact with company data, curbing unwanted access and reinforcing privacy compliance.
Compliance Demonstrates, on an ongoing basis, compliance with the third-party controls demanded by regulations such as NIS2 and DORA.
Board & Exec NIS2 and DORA carry personal liability. LEET TPRM supplies the evidence trail to prove governance, continuously, not just at renewal.
Regulatory Compliance, in Real Time

Turn Compliance from a Once-a-Year Exercise into a Continuous, Evidence-Backed State

NIS2 and DORA do not simply require supply-chain security measures, they require organisations to be able to demonstrate them, on an ongoing basis, not just at renewal. By combining an audited rating with continuous external monitoring, LEET TPRM turns compliance from a once-a-year exercise into a continuous, evidence-backed state, mapped to the most common international standards and regulations.

NIS2 DORA GDPR NIST CIS PCI DSS ISO 27001
Continuous Compliance Coverage
Supply-chain security controlsNIS2 · DORA
Personal liability evidence trailNIS2 · DORA
Third-party data access monitoringGDPR
Cyber resilience index (0–1000)DORA Passport
Control framework mappingNIST · CIS · ISO 27001
Continuous vs point-in-timeAlways On
Audit results + EASM monitoring read side by side — one coherent compliance picture

Adopted Where It Matters Most

LEET TPRM has been validated by some of the most demanding supply-chain risk environments in Europe.

Runs a blended model across its entire supplier base: every RFP participant completes the LEET Self-Assessment, selected providers advance to LEET Assessment, and the organisation's most critical suppliers must hold a full LEET Rating. A simple decision matrix, based on rating level and activity risk, determines which providers are qualified, conditionally qualified, or not qualified.

Built on LEET Security's methodology and backed by Spain's Centro de Cooperación Interbancaria and the country's financial entities, Pinakes is the first platform in Europe for centralised cybersecurity risk management in finance. Banks supervise supplier security centrally, and providers demonstrate compliance once — recognised across the entire sector, replacing a landscape where every bank once audited the same providers separately.

One Platform. Zero Extra Infrastructure.

Unified Platform
One secure SaaS where providers and clients manage assessments, download reports, and run the whole TPRM process end to end.
ROC, as a Service
LEET's own analyst team backs quality control on every Self-Assessment, LEET Assessment, and LEET Rating. No in-house expertise needed.
Automated Alerts
Multi-channel notifications for critical risk-profile changes, pending documentation, or corrective-action updates. No manual monitoring required.

Ready to See Exactly How LEET TPRM Fits Your Supply-Chain Risk Model?