Skip to content
BIZENIUS.

Third-Party & Supply Chain Cyber Risk

Attackers stopped knocking on hardened front doors — they come in through the supplier with your credentials and their weaknesses.

Format

Classroom · Live Virtual

The programme

The defining breaches of recent years came through vendors, managed service providers and software updates — through trust, not walls. This programme builds the discipline that manages that trust: a vendor inventory that finds the access nobody remembers granting; assessment that predicts rather than papers — beyond questionnaires to evidence, ratings and criticality tiers; contracts with real security obligations, audit rights and breach notification clocks; concentration risk — the one provider everyone uses — faced honestly; and the response plan for the day a supplier calls with bad news: your obligations, your customers, and containment across a boundary you do not control.

What you will do

Build the third-party inventory, forgotten accesses included
Assess vendors with evidence and criticality tiers, not questionnaires alone
Contract security obligations, audit rights and notification clocks that bind
Respond to a supplier breach across a boundary you do not control

Who attends

Security and risk teams owning third-party risk; procurement staff buying technology and services; vendor managers; auditors and regulators examining outsourcing risk.

Cohorts bring together board members, executives and the rising leaders behind them — kept deliberately small, so every seat is a peer’s.

Programme agenda

Built for the decisions no textbook prepares you for

I.Seeing the exposure
  • The inventory: vendors, accesses, data flows — found, not assumed
  • Criticality tiers: assessment effort matched to real dependence
  • Concentration: the provider everyone uses, faced honestly
II.Managing the trust
  • Assessment beyond questionnaires: evidence, ratings, continuous signals
  • Contracts with teeth: obligations, audit rights, notification clocks
  • Access architecture: least privilege for suppliers too
III.When the call comes
  • The supplier-breach playbook: assess, contain, notify — across the boundary
  • Software supply chain events: updates, libraries, the emergency triage
  • Exit and substitution: leaving a compromised provider without breaking

Frequently asked

Which security frameworks do the programmes work with?

The frameworks security teams are audited against — including ISO 27001, the NIST Cybersecurity Framework and GDPR obligations — plus industrial control-system security for oil, gas and utilities environments. BIZENIUS does not certify against these standards; participants leave able to run the risk assessments, write the ISMS documentation and prepare the evidence an auditor asks for.

Is there cybersecurity content for boards and non-technical executives?

Yes. Dedicated programmes address risk and cybersecurity for board members, and cyber governance, risk and compliance for executives, alongside practitioner-level depth for security teams — from emerging threats and countermeasures to fraud detection and investigation. Boards leave knowing which questions to put to their CISO, and what a satisfactory answer looks like.

How is pricing handled for cybersecurity programmes?

There is no public rate card. The fee arrives in the proposal, shaped by format, location and any tailoring — request the brochure and a senior practitioner replies within one business day with the details.

Can security training run inside our own environment?

Yes. Every programme runs in-house, tailored to your threat model, your sector and your control environment — including operational-technology settings such as process-control systems. Delivery is in English or French, on site or as a private live virtual cohort.

Share this programme

LinkedInWhatsAppFacebookEmail

Know the right person for this seat?Nominate a colleague →

In their words

Knowledge transfer, emphasised throughout

“We worked with BIZENIUS for our Fresh Graduates Programme — they are simply amazing. Knowledge transfer and practical learning were emphasised throughout.”

Kuwait Investment Authority

Teams from these institutions train with BIZENIUS

  • Citi
  • Barclays
  • ExxonMobil
  • Total
  • Gazprom
  • Standard Bank
  • QNB
  • Crédit Agricole
  • Nedbank
  • Absa
  • Raiffeisen
  • Halliburton
  • Baker Hughes
  • ConocoPhillips
  • Ooredoo
  • National Bank of Kuwait
  • Kuwait Finance House
  • Bank Muscat
  • Bank Audi
  • SABB
  • Garanti BBVA
  • Ecobank
  • Arab Bank
  • National Bank of Egypt
  • ADIB
  • Access Bank
  • Afreximbank
  • Repsol
  • QNB ALAHLI
  • Stanbic Bank
  • Equity Group Holdings
  • KCB Bank
  • Lombard Odier
  • NOV
  • Weatherford
  • Subsea 7
  • Al Baraka
  • Banque Misr
  • Burgan Bank
  • Bank ABC

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
Number of participants
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.