Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Third-Party Risk Dashboard

Shows portfolio-level supplier exposure: assessment coverage, overdue reviews, open findings and concentration.

Available soon

Format
Excel
Size
119 KB
Length
12 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Register Data
  • Findings Data
  • Metric Definitions
  • Quarterly Report
  • Trend
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Register Data sheet: in the Supplier Security Risk Register, copy the Register table's rows (columns A to AM, from row 4 down) and paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order.
2Findings Data sheet: copy the register's Findings table rows (columns A to O, from row 4 down) and paste them as values into cell A4.
3Delete the EXAMPLE rows on both data sheets before you paste, and check that dates are real dates (right-aligned), not text.
4Quarterly Report sheet: enter the report date, normally the last day of the quarter. The EXAMPLE uses 2026-09-30; replace it with your quarter end. Assessment status, days past due and finding deadlines are recalculated at this date; tiers, residual scores and positions are as the register calculated them. Set the due-soon window and the TPM-01 target date to match the register's Summary sheet.
5The Trend sheet holds last quarter's figures: type the three earlier quarters from the reports you kept. The last row comes from this quarter's data.
6Read the four headline measures. Each has its target, its direction since last quarter and a status in words; the colour only repeats the word. Add a line of commentary to every measure that missed its target or moved.
7For each High finding past its deadline, confirm it was escalated to the business owner and write what they decided (TP-08). For each supplier outside appetite, write the decision needed and the reference in the P05 Information Security Risk Register (TP-06).
8Complete 'What to tell executive management' and take the report to [[e.g. Executive Committee]] every quarter (TP-12). Carry TPM-01 into the board report as BM-05 so both say the same.
9Keep a copy of this workbook for each quarter as the record.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The EXAMPLE is a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30: the same suppliers and findings as the Supplier Security Risk Register. 9 of 14 Tier 1 suppliers are assessed (was 6); 1 High finding is past its deadline; 6 providers support two or more critical services, 2 of them without an exit plan. The earlier quarters on the Trend sheet are EXAMPLE figures typed in.

Tailoring — small organisation: the report can be one page — the four measures, the late findings and the decisions. Take it to whoever runs the organisation, every quarter.

Tailoring — regulated entity: under NIS2 the management body approves and oversees the risk-management measures, which include supply chain security (Art 20(1), 21(2)(d)); take the report to it. A DORA financial entity assesses ICT concentration risk (Art 29(1)): show the providers several critical or important functions depend on, and keep each quarter's copy.

Tailoring — IT run by a service provider: ask the provider to confirm, before your quarter end, the status of any finding it owns and any change to the providers it relies on for your service.

Status words: In date, Due soon, Overdue, Planned, Not required for assessments; On target or Action needed for measures; "Within appetite", "Outside appetite, within tolerance", "Outside tolerance" for residual risk, the same words as the P05 pack.

Register Data

Paste the Register table of the Supplier Security Risk Register here as values (columns A–AM, from row 4). Columns AN–AY are calculated at the report date. The 14 EXAMPLE rows are that register's example — delete them first.

ExampleSupplier refSupplierSupplier typeBusiness ownerCritical services supportedCritical services (number)DataAccessTC-1 ServiceTC-2 DataTC-3 AccessTC-4 SubstitutabilityOverrideTierTier set byQuestionnaire setReassess every (months)Last assessedPlanned assessmentNext dueAssessment statusDays past dueEvidence validated (TP-04)Open High findingsOpen Medium findingsOpen Low findingsHigh findings past deadlineResidual impact (1–4)Residual likelihood (1–4)Residual scoreResidual bandPosition against appetiteP05 risk register refDecisionContract clauses in place (TP-07)Exit plan (TP-11)Record checkNotesTier 1 assessed in 12 months (calc)Status at report date (calc)Days past due (calc)Assessed this quarter (calc)Due next quarter (calc)Concentration (calc)Outside appetite (calc)This quarter no. (calc)Next quarter no. (calc)Overdue no. (calc)Concentration no. (calc)Outside no. (calc)
EXAMPLESUP-001Managed IT service providerITHead of ITOnline ordering; Warehouse dispatch; Finance and payroll3Customer dataPrivilegedTier 1Tier 1Tier 1Tier 1GDPR processorTier 1TC-1, TC-2, TC-3, TC-4A1218 Nov 202518 Nov 2026Due soonYes0000313LowWithin appetiteR-06ApproveYesYesOKP05 risk R-06 (treatment: Transfer).YesDue soonReassessmentYes11
EXAMPLESUP-002Cloud hosting providerITHead of ITOnline ordering; Finance and payroll2Customer dataNetworkTier 1Tier 1Tier 1Tier 1GDPR processorTier 1TC-1, TC-2, TC-3, TC-4A1227 Jan 202627 Jan 2027In dateYes0000313LowWithin appetiteApprove with conditionsYesYesOKF-04 closed 2026-03-30.YesIn dateYes2
EXAMPLESUP-003Payment service providerFinanceChief Financial OfficerPayments1Card data (held by the provider)NoneTier 1Tier 1Tier 4Tier 1NoneTier 1TC-1, TC-2, TC-4A1224 Feb 202624 Feb 2027In dateYes0000313LowWithin appetiteApproveYesYesOKYesIn date
EXAMPLESUP-004ERP software provider (hosted)ITChief Financial OfficerFinance and payroll; Warehouse dispatch2Personal dataRemote supportTier 1Tier 2Tier 2Tier 1GDPR processorTier 1TC-1, TC-4A1221 Apr 202621 Apr 2027In dateYes1101326MediumWithin appetiteApprove with conditionsYesYesHigh finding past deadline: escalate to the business owner (TP-08)Conditions: F-01 and F-02 fixed by their deadlines.YesIn dateYes3
EXAMPLESUP-005Email and office software providerITHead of ITCustomer contact1Personal dataNoneTier 1Tier 2Tier 4Tier 2GDPR processorTier 1TC-1A1219 May 202619 May 2027In dateYes0000212LowWithin appetiteApproveYesYesOKYesIn date
EXAMPLESUP-006Security monitoring providerITHead of Information SecurityOnline ordering; Warehouse dispatch2Log dataPrivilegedTier 1Tier 3Tier 1Tier 2NoneTier 1TC-1, TC-3A1216 Jun 202616 Jun 2027In dateYes0000212LowWithin appetiteApproveYesYesOKYesIn dateYes4
EXAMPLESUP-007National parcel carrierLogisticsHead of LogisticsWarehouse dispatch1Customer addressesIntegrationTier 1Tier 1Tier 2Tier 2GDPR processorTier 1TC-1, TC-2A1214 Jul 202614 Jul 2027In dateYes0000224MediumWithin appetiteApproveYesYesOKYesIn dateYes1
EXAMPLESUP-008Express courierLogisticsHead of LogisticsWarehouse dispatch1Customer addressesIntegrationTier 1Tier 1Tier 2Tier 2GDPR processorTier 1TC-1, TC-2A1218 Aug 202618 Aug 2027In dateYes0000212LowWithin appetiteApproveYesYesOKYesIn dateYes2
EXAMPLESUP-009Pallet networkLogisticsHead of LogisticsWarehouse dispatch1Customer addressesPortalTier 1Tier 1Tier 4Tier 2GDPR processorTier 1TC-1, TC-2A1215 Sep 202615 Sep 2027In dateYes0100224MediumWithin appetiteApprove with conditionsYesYesOKCondition: F-03 fixed by its deadline.YesIn dateYes3
EXAMPLESUP-010Warehouse management system providerITHead of LogisticsWarehouse dispatch1InternalRemote supportTier 1Tier 3Tier 2Tier 1NoneTier 1TC-1, TC-4A1220 Oct 202620 Oct 2026Planned0000YesNoAgree an exit plan (TP-11)NoPlannedFirst assessment2
EXAMPLESUP-011Backup service providerITHead of ITOnline ordering; Finance and payroll2Customer dataNetworkTier 1Tier 1Tier 1Tier 2GDPR processorTier 1TC-1, TC-2, TC-3A123 Nov 20263 Nov 2026Planned0000YesNoAgree an exit plan (TP-11)NoPlannedFirst assessmentYes35
EXAMPLESUP-012Payroll bureauFinanceHR DirectorFinance and payroll1Personal data (staff)PortalTier 1Tier 1Tier 4Tier 2GDPR processorTier 1TC-1, TC-2A1217 Nov 202617 Nov 2026Planned0000YesNoAgree an exit plan (TP-11)NoPlannedFirst assessment4
EXAMPLESUP-013Outsourced customer contact centreServiceChief Operating OfficerCustomer contact1Customer dataRemote userTier 1Tier 1Tier 2Tier 2GDPR processorTier 1TC-1, TC-2A121 Dec 20261 Dec 2026Planned0000NoNoAdd the tier's security clauses to the contract (TP-07)Contract predates the policy; clauses added at renewal.NoPlannedFirst assessment5
EXAMPLESUP-014Network connectivity providerITHead of ITOnline ordering; Warehouse dispatch2None storedNetworkTier 1Tier 4Tier 1Tier 1NoneTier 1TC-1, TC-3, TC-4A128 Dec 20268 Dec 2026Planned0000NoNoAdd the tier's security clauses to the contract (TP-07)Contract predates the policy; clauses added at renewal.NoPlannedFirst assessmentYes66

Findings Data

Paste the register's Findings table here as values (columns A–O, from row 4). Columns P–S are calculated at the report date. EXAMPLE: that register's example.

ExampleFinding IDSupplier refSupplierSeverityFindingOwnerRaisedDeadlineStatusClosed onDays past deadlineDeadline flagEscalated to business owner onNotesOpen (calc)Days to deadline (calc)Past deadline (calc)Open no. (calc)
EXAMPLEF-01SUP-004ERP software provider (hosted)HighSupport staff reach our ERP without multi-factor authenticationChief Financial Officer21 Apr 202620 Jul 2026Open72Past deadline21 Jul 2026Escalated to the business owner the day after the deadline (TP-08).Yes-72Past deadline1
EXAMPLEF-02SUP-004ERP software provider (hosted)MediumNo evidence that our data is deleted at contract endChief Financial Officer21 Apr 202618 Oct 2026OpenYes182
EXAMPLEF-03SUP-009Pallet networkMediumShared portal accounts used by depot staffHead of Logistics15 Sep 202614 Mar 2027OpenYes1653
EXAMPLEF-04SUP-002Cloud hosting providerHighPenetration test older than 12 monthsHead of IT27 Jan 202627 Apr 2026Closed30 Mar 2026New penetration test summary received and checked.

Metric Definitions

Metric definitions

The four headline measures of the Third-Party Security Policy, defined once so every quarter is calculated the same way (TP-12).

MeasureDefinitionHow this workbook calculates itTargetHow to read it
TPM-01 Tier 1 suppliers assessedTier 1 suppliers with an assessment within the last 12 months, out of all Tier 1 suppliers.Tier 1 rows whose last assessment is within the 12 months up to the report date, out of all Tier 1 rows. On target while every other Tier 1 supplier has a planned assessment before the target date.All Tier 1 by [[year end]]The board measure BM-05 in the P03 pack, in the same words: "n of N critical suppliers". Higher is better.
TPM-02 Reassessments overdueSuppliers past their tier's reassessment interval.Rows whose next due date is before the report date, including a supplier never assessed whose planned date has passed; and of those, more than 90 calendar days past it.Zero Tier 1; none more than 90 days overdueAn overdue reassessment is a supplier whose security nobody has checked within its tier's interval (TP-09). Name each one with its business owner.
TPM-03 High findings past deadlineOpen High findings past their remediation deadline.Open High findings whose deadline is before the report date.ZeroEach must have been escalated to the supplier's business owner (TP-08). Show the escalation date and what the owner decided.
TPM-04 ConcentrationProviders that two or more critical services depend on.Rows supporting 2 or more of the critical services on the register's Critical Services sheet; and of those, without an exit plan.Each one known, with an exit plan (TP-11)Not a number to drive down: it shows where one failure would stop several services. What matters is that each has an exit plan (TP-11).

Quarterly Report

Third-party security risk — quarterly report

Yellow cells are yours: the report settings, the commentary and the decisions. Everything else is calculated. Every status is in words; the colour only repeats it.

Report settings

SettingValue
Report date (the quarter end)30 Sep 2026EXAMPLE report date: replace with your quarter end.
QuarterQ3 2026
Due soon: calendar days before the next due date90As on the register's Summary sheet.
Target date: all Tier 1 suppliers assessed (TPM-01)31 Dec 2026EXAMPLE: the year end, from the target "All Tier 1 by [[year end]]".

Summary

9 of 14 Tier 1 suppliers assessed in the last 12 months; the other 5 are all planned by 2026-12-31. 1 High finding is past deadline; 0 reassessments are overdue.

Headline measures

MeasureThis quarterLast quarterDirectionTargetStatusCommentary — what changed, and why
TPM-01 Tier 1 suppliers assessed9 of 146 of 14Better (was 6)All Tier 1 by [[year end]]On target[[EXAMPLE: Better: the three logistics suppliers (SUP-007, SUP-008, SUP-009) were assessed this quarter; the remaining five are planned for Q4. SUP-001's reassessment falls due on 2026-11-18 and must be done to keep 14 of 14 at year end.]]
TPM-02 Reassessments overdue00SameZero Tier 1; none more than 90 days overdueOn target
more than 90 days overdue00Same0
TPM-03 High findings past deadline10Worse (was 0)ZeroAction needed[[EXAMPLE: F-01 (ERP software provider (hosted): support staff reach our ERP without multi-factor authentication) passed its deadline on 2026-07-20 and was escalated to the Chief Financial Officer on 2026-07-21 (TP-08).]]
TPM-04 Concentration: providers66SameEach one known, with an exit plan (TP-11)Action needed
of those, without an exit plan22Same0[[EXAMPLE: Backup service provider (SUP-011) and network connectivity provider (SUP-014) have no exit plan yet; each is written at its Q4 assessment (TP-11).]]

TPM-01 is the board measure BM-05. Last quarter comes from the Trend sheet. Tiers, scores and positions are as the register calculated them; status and deadlines are recalculated at the report date.

Assessments completed this quarter

SupplierBusiness ownerAssessedResidualPositionDecisionOpen findingsExit planNext due
SUP-007 National parcel carrierHead of Logistics14 Jul 20264 (Medium)Within appetiteApprove0Yes14 Jul 2027
SUP-008 Express courierHead of Logistics18 Aug 20262 (Low)Within appetiteApprove0Yes18 Aug 2027
SUP-009 Pallet networkHead of Logistics15 Sep 20264 (Medium)Within appetiteApprove with conditions1Yes15 Sep 2027

Due next quarter: first assessments and reassessments

SupplierBusiness ownerTypeDue or plannedTierCritical servicesExit planContract clausesStatus now
SUP-001 Managed IT service providerHead of ITReassessment18 Nov 2026Tier 13YesYesDue soon
SUP-010 Warehouse management system providerHead of LogisticsFirst assessment20 Oct 2026Tier 11NoYesPlanned
SUP-011 Backup service providerHead of ITFirst assessment3 Nov 2026Tier 12NoYesPlanned
SUP-012 Payroll bureauHR DirectorFirst assessment17 Nov 2026Tier 11NoYesPlanned
SUP-013 Outsourced customer contact centreChief Operating OfficerFirst assessment1 Dec 2026Tier 11NoNoPlanned
SUP-014 Network connectivity providerHead of ITFirst assessment8 Dec 2026Tier 12NoNoPlanned

Overdue reassessments (TPM-02)

SupplierBusiness ownerTierNext dueDays past dueResidualDecisionExit planNotes

None overdue

Open findings (TPM-03 and TP-08)

FindingSupplierSeverityOwnerDeadlineDays to deadlineFlagEscalated onNotes
F-01 Support staff reach our ERP without multi-factor authenticationSUP-004 ERP software provider (hosted)HighChief Financial Officer20 Jul 2026-72Past deadline21 Jul 2026Escalated to the business owner the day after the deadline (TP-08).
F-02 No evidence that our data is deleted at contract endSUP-004 ERP software provider (hosted)MediumChief Financial Officer18 Oct 202618
F-03 Shared portal accounts used by depot staffSUP-009 Pallet networkMediumHead of Logistics14 Mar 2027165

Concentration: providers 2 or more critical services depend on (TPM-04)

SupplierCritical services supportedNumberTierStatus nowResidualExit planContract clausesBusiness owner
SUP-001 Managed IT service providerOnline ordering; Warehouse dispatch; Finance and payroll3Tier 1Due soon3 (Low)YesYesHead of IT
SUP-002 Cloud hosting providerOnline ordering; Finance and payroll2Tier 1In date3 (Low)YesYesHead of IT
SUP-004 ERP software provider (hosted)Finance and payroll; Warehouse dispatch2Tier 1In date6 (Medium)YesYesChief Financial Officer
SUP-006 Security monitoring providerOnline ordering; Warehouse dispatch2Tier 1In date2 (Low)YesYesHead of Information Security
SUP-011 Backup service providerOnline ordering; Finance and payroll2Tier 1PlannedNoYesHead of IT
SUP-014 Network connectivity providerOnline ordering; Warehouse dispatch2Tier 1PlannedNoNoHead of IT

Suppliers outside appetite for third-party dependency (TP-06)

SupplierBusiness ownerResidualPositionDecisionP05 register refDecision needed

None: every assessed supplier is within appetite

A supplier outside appetite is entered in the P05 Information Security Risk Register; its owner decides the treatment there (TP-06).

What to tell executive management

PointWhat to say
Summary (one sentence)9 of 14 Tier 1 suppliers assessed in the last 12 months; the other 5 are all planned by 2026-12-31. 1 High finding is past deadline; 0 reassessments are overdue.
Direction: better or worse, and why[[EXAMPLE: Better: 9 of 14 critical suppliers assessed, up from 6; all five remaining are planned for Q4, so 14 of 14 by year end is on target.]]
What could hurt us most[[EXAMPLE: One High finding past its deadline at the ERP software provider (hosted) (F-01): support staff reach our ERP without multi-factor authentication.]]
Decisions needed[[EXAMPLE: Ask the Chief Financial Officer for the supplier's fix date for F-01, or a decision to restrict its support access until it is fixed. Note that two concentration providers still need exit plans.]]
Prepared by (name, role) and date[[Name, role, YYYY-MM-DD]]

Trend

Trend — the last four quarters

The headline measures at each of the last four quarter ends. Type the three earlier quarters from the reports you kept; the last row is calculated from this quarter's data. Direction compares each quarter with the one before.

Quarter endQuarterTPM-01 assessedTier 1 suppliersTPM-02 overdueTPM-02 over 90 daysTPM-03 High past deadlineTPM-04 providersTPM-04 without exit planTPM-01 directionCommentary
31 Dec 2025Q4 202511400065—[[EXAMPLE figures: replace with your own]]
31 Mar 2026Q1 202631400064Better (was 1)[[EXAMPLE figures: replace with your own]]
30 Jun 2026Q2 202661400062Better (was 3)[[EXAMPLE figures: replace with your own]]
30 Sep 2026Q3 202691400162Better (was 6)

EXAMPLE: the three earlier quarters are typed in, as you would from the reports kept for them. 2026-06-30: 6 of 14 Tier 1 suppliers assessed — the "was 6" in the board report.

For this workbook's example, the earlier figures assume the example firm's supplier assessments began in November 2025 and each exit plan was agreed at the first assessment.

Lists

StatusPositionMeasureStatusNextQuarterType
In dateWithin appetiteOn targetFirst assessment
Due soonOutside appetite, within toleranceAction neededReassessment
OverdueOutside tolerance

Planned

Not required

Definitions

Definitions

TermMeaning in this workbook
Report dateThe quarter end the report is for. Assessment status, days past due and finding deadlines are calculated at this date.
Assessment statusIn date; Due soon (next due within the due-soon window, 90 calendar days by default); Overdue (next due date passed, or never assessed and the planned date passed); Planned (not yet assessed, planned date ahead); Not required (a tier reassessed only on change).
Assessed this quarterLast assessed after the previous quarter end and on or before the report date.
Due next quarterNext due (or planned) after the report date and on or before the end of the next quarter: a first assessment if the supplier has never been assessed, otherwise a reassessment.
Concentration providerA supplier 2 or more critical services depend on (TPM-04). Every Tier 1 and Tier 2 contract must have an exit plan: data return or deletion, access removal, and a transition period.
Past deadlineAn open finding whose deadline is before the report date. Every finding must have an owner and a deadline set by its severity; a High finding past its deadline must be escalated to the business owner.
PositionWithin appetite; Outside appetite, within tolerance; Outside tolerance: the supplier's residual band against the appetite for third-party dependency, as the register calculated it (TP-06).
DirectionBetter, Same or Worse than last quarter, with last quarter's figure: for example Better (was 6). For TPM-01 higher is better; for the others lower is better.
TPM-01 Tier 1 suppliers assessedTier 1 suppliers with an assessment within the last 12 months, out of all Tier 1 suppliers. Target: all Tier 1 by [[year end]].
TPM-02 Reassessments overdueSuppliers past their tier's reassessment interval. Target: zero Tier 1; none more than 90 days overdue.
TPM-03 High findings past deadlineOpen High findings past their remediation deadline. Target: zero.
TPM-04 ConcentrationProviders that two or more critical services depend on. Target: each one known, with an exit plan (TP-11).
(calc)A column the workbook calculates. Do not type or paste over it.
TP-nn, TPM-nnRule and measure numbers in the Third-Party Security Policy.
EXAMPLEThe example organisation's figures as at 2026-09-30. Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationThe workbook as a whole: four defined measures, calculated the same way each quarter, analysed and reported
ISO/IEC 27001:2022Annex A 5.22 — Monitoring, review and change management of supplier servicesAssessments this quarter, due next quarter and overdue; open findings and their deadlines: supplier security monitored and reviewed
NIST CSF 2.0GV.SC-09 — “Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle”Headline measures against targets and the Trend: supply chain security performance monitored and reported to executive management
NIST CSF 2.0GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship”Open findings, escalation and suppliers outside appetite: supplier risk responded to and monitored through the relationship
DORA — Regulation (EU) 2022/2554Article 29(1) — assessing concentration risk: providers not easily substitutable, or several arrangements with the same providerConcentration: providers several critical services depend on, with their exit plans
NIS2 — Directive (EU) 2022/2555Article 21(2)(d) — “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”The quarterly report as management's oversight of supply chain security

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)