UpGuard release notes show fourth-party data moving into operational workflows
API availability and questionnaire-remediation changes suggest that downstream visibility is being judged less as a map and more as data that must enter governed work.
Reporting and analysis on the standards, companies, products, incidents, and research changing third-party risk decisions.
API availability and questionnaire-remediation changes suggest that downstream visibility is being judged less as a map and more as data that must enter governed work.
ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.
The finalized C-SCRM quick-start guide gives organizations a clearer floor for evaluating technology suppliers before risk teams build a larger program around it.
The vendor-funded analysis shows the value—and the limits—of using relationship-scale datasets to understand concentration and downstream cyber exposure.
APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.
SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.
A compromised third-party integration involving Klue and Salesforce shows why application connections need their own inventory, ownership, and revocation playbook.
The acquisition extends a broader contest over who can map external assets, dependencies, and threat signals into a third-party decision workflow.
The April package adds limited contractual exemptions, clarifies their management, and updates the material service-provider register ahead of the July commencement date.
The announced integration joins corporate ownership and trade intelligence with component- and material-level sourcing data, pushing third-party analysis deeper into product-specific exposure.
The UK policy expands reporting beyond outsourcing, separates notification from register templates, and gives firms a year to govern the data behind material third-party arrangements.
The new rating approach reflects a market shift toward combining external signals with evidence from the organization's own assessment and control process.
ProcessUnity and Ponemon Institute report a gap between incident volume and assessment response, but buyers should separate the study's directional signal from a universal benchmark.
The 2026 study brings healthcare organizations, industry groups, and several control frameworks into one benchmarking program, creating useful peer context with important participation limits.
The partnership combines outside-in cyber signals with healthcare-specific assessment and advisory work, illustrating how managed TPRM providers are packaging intelligence into response workflows.
The Mirato deal connects corporate and trade data with AI-assisted assessment workflow, creating a broader risk-intelligence operating model whose post-acquisition packaging still requires scrutiny.