CyberGrape – cyber security certification and GRC platform for small business
Black Kite
Supply chain risk

Black Kite

Attackers often get in through a supplier, not through you. We use Black Kite to watch your whole supply chain in real time.

6
Total controls covered
1
SMB1001 controls
5
ISO 27001 controls
Supply chain risk
Category

What they do

Black Kite continuously rates the cyber risk of the vendors, suppliers and partners you rely on. It does this from the outside using open intelligence and threat feeds, so there are no agents to install and no questionnaires to chase. Each vendor gets a clear risk rating, a ransomware likelihood score, and an estimate of what a breach could cost in dollars.

How we use it for you

We monitor your critical suppliers around the clock and alert you the moment one of them is exposed, breached or slipping. You get vendor scorecards you can share straight back to a supplier with the fixes spelled out, and board-ready reporting that puts risk in plain financial terms.

Where it shows up in CyberGrape GRC

Your vendor risk dashboard, vendor scorecards, posture-change alerts, and the supply chain section of your board reporting. You can also monitor your own organisation the same way an attacker would see it.

Standards it helps you meet

SMB1001:20261 control
  • 4.9.0.1Digital trust programme with suppliers
ISO 27001:20225 controls
  • 5.19Information security in supplier relationships
  • 5.20Addressing security within supplier agreements
  • 5.21Managing information security in the ICT supply chain
  • 5.22Monitoring and review of supplier services
  • 5.7Threat intelligence

Black Kite is part of CyberGrape's managed service delivery. Our team deploys, configures and monitors it so you get the protection without managing the tool yourself.

Learn more

Get Black Kite working for your business

Talk to our team about deploying Black Kite as part of a managed security programme, with evidence collection and compliance reporting built in from day one.