Most organisations have spent years hardening their own networks, only to find that the easiest way in now runs through someone else's. According to Forrester research cited by Panorays, third-party breaches make up nearly 60% of cyber events. Yet most supplier-risk programmes still run on spreadsheets and annual questionnaires that capture a supplier's security at a single moment and then quietly go stale.
To close that gap, Cyber Retaliator Solutions (CRS) has added Panorays, the third-party cyber risk management platform, to its portfolio. Drystan Govender, Panorays lead at CRS, explains what the platform does, why it matters for organisations in South Africa and across the continent, and how resellers, MSPs and MSSPs can deliver it to their customers as a managed service.
⚠️ Why Third-Party Risk Has Outgrown the Spreadsheet
Every supplier with access to your systems, your data or your customers extends your attack surface. Those suppliers have suppliers of their own, and the chain rarely ends there. Panorays' own research shows how little of that chain most security leaders can actually see.
📊 What CISOs Are Reporting
- According to Panorays' 2025 CISO survey, 91% of CISOs report rising third-party incidents, and only 3% have full visibility of their supply chain.
- Panorays' 2026 CISO survey found that 85% still lack full supply-chain visibility, and that 50% of incidents originated beyond direct third parties.
- The same 2026 survey reports that 71% of CISOs say traditional questionnaires fall short.
📋 Where Spreadsheet Programmes Break Down
- Point-in-time: an annual review says nothing about what changed at the supplier the following week.
- Unverified: questionnaire answers are taken on trust, with no independent check against the supplier's real-world exposure.
- No Nth-party view: fourth parties and beyond, your vendors' vendors, stay invisible.
- Doesn't scale: every new supplier adds manual work, so critical and trivial suppliers end up competing for the same limited hours.
🧬 What Panorays Does: Three Inputs, One Rating
The idea behind Panorays is that a supplier's risk is not one thing. It combines what can be observed from the outside, what the supplier tells you, and what the relationship means to your business. Panorays brings all three together into a single risk rating per supplier through what it calls Risk DNA: a continuous, personalised assessment that factors in your own KPIs and KRIs rather than relying on a generic score.
🌐 1. The Outside View: Cyber Posture Rating
- Panorays runs hundreds of non-intrusive tests across three layers: Network & IT, Application and Human.
- Each supplier receives a Cyber Posture Rating from 0 to 100, typically within hours.
- The tests rely on public data only. There are no penetration tests, no exploits, no agents and no supplier consent required.
- Panorays reports 99.4% rating accuracy, and a supplier that disputes a finding has it validated within 24 hours.
📝 2. The Inside View: Smart Questionnaire
- Built-in SIG and CAIQ templates, or custom questionnaires, with question weights and deal-breakers.
- Answers are validated against the supplier's posture data and uploaded documents, so what a supplier claims can be checked against what Panorays observes.
- AI features such as Smart Match and AI Document Validation reduce the effort on both sides of the questionnaire.
🏢 3. The Business View: Context
- Business criticality, data sensitivity, risk appetite and compliance requirements shape each supplier's final rating.
- The result is a Cyber Risk Rating on five levels (Bad, Poor, Fair, Good and Excellent), derived from a matrix of impact, meaning the business and technology relationship, and likelihood, meaning the scan plus the questionnaire.
- Panorays' machine-learning affiliation model also discovers fourth and Nth parties, as well as Shadow IT, with supporting evidence.
For CRS, the key difference is that the scan and the assessment live in one platform, rather than in two separate tools that someone has to reconcile by hand. Panorays has also added Cyber Risk Quantification and a dedicated DORA Register of Information solution, which we cover in companion articles.
🤝 Delivered as a Managed Service Through CRS Partners
Few organisations have spare headcount to run a third-party programme, so the CRS approach rests on one principle: powered by the Panorays platform, delivered as a managed service. CRS acts as the distributor, the single point of transaction that onboards and trains resellers, while partners deliver the programme to their customers as business partners rather than per-seat software vendors.
🎯 Tiered by Supplier Criticality
- Monitoring for critical IT suppliers: deep assessment plus continuous monitoring.
- Assessment for critical non-IT and non-critical IT suppliers: periodic, structured evaluation.
- Inventory for the long tail of non-critical, non-IT suppliers: centralised visibility and self-attestation.
We unpack this model in Depth Where It Matters: Risk-Based Supplier Tiering with Panorays.
🛠️ What the Managed Service Covers
- A dedicated customer success manager who builds and runs the programme, adds and organises suppliers, and sends questionnaires.
- Active work to drive supplier response rates, with remediation plans sent to suppliers and tracked to completion.
- Monthly update reports and a Management & Board report.
- Extended options such as input on vendor selection, contractual cyber clauses developed with legal teams, risk thresholds, periodic audits, incident escalation and post-incident reviews.
Partners can engage as referral partners, resellers or MSPs and MSSPs delivering Panorays as a service. Service packages cover building a programme end to end (Foundation), fitting Panorays to an existing programme (Adaptation) and continuing consulting and implementation (Ongoing).
🏆 A Leader in The Forrester Wave™
Panorays was named a Leader in The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2026, having also been named a Leader in the Q2 2024 evaluation. Panorays reports that the 2026 evaluation gave it the highest possible scores in nine criteria, including AI capabilities, customer AI adoption, and innovation and roadmap, alongside above-average customer feedback.
In the report, Forrester wrote that "Panorays excels in how it holistically brings together ratings data, vendor discovery capabilities, and questionnaire management capabilities to deliver high-quality and actionable findings for the third-party use case."
Founded in 2016 and headquartered in New York and Tel Aviv, Panorays holds ISO/IEC 27001:2022, ISO/IEC 42001:2023 (AI management) and SOC 2 Type II certifications, and hosts its platform on Google Cloud Platform.
🚀 Getting Started with Panorays
Getting started does not involve an installation project. Panorays is delivered as SaaS, and all it needs to produce an immediate cyber posture rating is the names and domains of your third parties. A proof of concept covers up to five critical suppliers, so customers see real findings on the suppliers that matter most before rolling out a wider programme.
Ready to find out which of your suppliers could hurt you, and fix it before they do? Explore Panorays on the CRS solution page, or, if you are a reseller, MSP or MSSP, become a CRS partner and add continuous third-party cyber risk management to your managed services portfolio.
