Skip to content
BIZENIUS

Third-Party & Supply Chain Cyber Risk

Attackers stopped knocking on hardened front doors — they come in through the supplier with your credentials and their weaknesses.

The programme

The defining breaches of recent years came through vendors, managed service providers and software updates — through trust, not walls. This programme builds the discipline that manages that trust: a vendor inventory that finds the access nobody remembers granting; assessment that predicts rather than papers — beyond questionnaires to evidence, ratings and criticality tiers; contracts with real security obligations, audit rights and breach notification clocks; concentration risk — the one provider everyone uses — faced honestly; and the response plan for the day a supplier calls with bad news: your obligations, your customers, and containment across a boundary you do not control.

What you will do

Build the third-party inventory, forgotten accesses included
Assess vendors with evidence and criticality tiers, not questionnaires alone
Contract security obligations, audit rights and notification clocks that bind
Respond to a supplier breach across a boundary you do not control

Who attends

Security and risk teams owning third-party risk; procurement staff buying technology and services; vendor managers; auditors and regulators examining outsourcing risk.

Cohorts bring together board members, executives and the rising leaders behind them — kept deliberately small, so every seat is a peer’s.

Programme agenda

Built for the decisions no textbook prepares you for

I.Seeing the exposure
  • The inventory: vendors, accesses, data flows — found, not assumed
  • Criticality tiers: assessment effort matched to real dependence
  • Concentration: the provider everyone uses, faced honestly
II.Managing the trust
  • Assessment beyond questionnaires: evidence, ratings, continuous signals
  • Contracts with teeth: obligations, audit rights, notification clocks
  • Access architecture: least privilege for suppliers too
III.When the call comes
  • The supplier-breach playbook: assess, contain, notify — across the boundary
  • Software supply chain events: updates, libraries, the emergency triage
  • Exit and substitution: leaving a compromised provider without breaking

Frequently asked

What does the third-party cyber risk course cover?

The full discipline of managing trust: a vendor inventory that finds the access nobody remembers granting, assessment that goes beyond questionnaires to evidence, ratings and criticality tiers, contracts with real security obligations, audit rights and breach notification clocks, concentration risk faced honestly, and the response plan for the day a supplier calls with bad news.

Does it address software supply chain attacks?

Yes — software supply chain events are worked as their own case: compromised updates and libraries, the emergency triage they demand, and containment across a boundary you do not control. Exit and substitution — leaving a compromised provider without breaking your own operation — closes the module.

Who should attend?

Security and risk teams who own third-party risk, procurement staff buying technology and services, vendor managers, and auditors and regulators examining outsourcing risk. The programme is as useful to the people writing the contracts as to those who will answer for the breach.

Can it be delivered in-house for our vendor-risk team?

Yes — like every BIZENIUS programme, it is available in-house, tailored to your supplier portfolio, contracts and assessment practices, and delivered in English and French. Sessions run on a rolling calendar, with dates confirmed on request, and fees and quotations are provided on enquiry.

Who teaches this

Practitioners, not presenters.

Led by risk and cybersecurity practitioners who have owned security and technology-risk accountability in regulated institutions and advised boards through incidents, alongside data-privacy specialists who have implemented the regimes they teach. The emphasis is governance and decision-making, taught by people who have had to make the call.

What the bench brings

  • Information security governance and risk assessment
  • Security management systems, audit and certification
  • Data protection and privacy compliance
  • Cloud, network and industrial-control security
  • Sourcing decisions: make, buy or partner
  • Supplier due diligence and third-party risk

Where they have practised

Current and former practitioners — people who hold the seat today alongside those who have held it.

Sectors: Technology & fintech · Banking & financial services · Government & public sector · Insurance

Regions: Africa · the Middle East · Europe · Asia · the Americas

How they teach

  • Incident and breach scenario exercises
  • Hands-on labs and control walk-throughs
  • Board-briefing role plays
  • Exam-style knowledge checks and quizzes
  • A personal action plan

Cohorts are kept small so every exercise is worked on the participants’ own situations — in person or live virtual.

The faculty profile for your cohort is sent with the full agenda and the next dates when you enquire.Request brochure →

Share this programme

LinkedInWhatsAppFacebookEmail

Know the right person for this seat?Nominate a colleague →

In their words

Knowledge transfer, emphasised throughout

“We worked with BIZENIUS for our Fresh Graduates Programme — they are simply amazing. Knowledge transfer and practical learning were emphasised throughout.”

Kuwait Investment Authority

Teams from these institutions train with BIZENIUS

  • Citi
  • Barclays
  • ExxonMobil
  • Total
  • Gazprom
  • Standard Bank
  • QNB
  • Crédit Agricole
  • Nedbank
  • Absa
  • Raiffeisen
  • Halliburton
  • Baker Hughes
  • ConocoPhillips
  • Ooredoo
  • National Bank of Kuwait
  • Kuwait Finance House
  • Bank Muscat
  • Bank Audi
  • SABB
  • Garanti BBVA
  • Ecobank
  • Arab Bank
  • National Bank of Egypt
  • ADIB
  • Access Bank
  • Afreximbank
  • Repsol
  • QNB ALAHLI
  • Stanbic Bank
  • Equity Group Holdings
  • KCB Bank
  • Lombard Odier
  • NOV
  • Weatherford
  • Subsea 7
  • Al Baraka
  • Banque Misr
  • Burgan Bank
  • Bank ABC

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.