Skip to main content
All articles
Panorays
11 September 2026Panorays

Depth Where It Matters: Risk-Based Supplier Tiering with Panorays

Ask most organisations how many suppliers they have and the honest answer is "more than we can properly assess". A typical supplier list mixes cloud platforms holding customer data with stationery vendors and catering contractors. Treating them all the same, with one questionnaire and one annual review cycle, produces a mountain of paperwork and very little insight into where the real risk sits.

Cyber Retaliator Solutions (CRS) delivers Panorays through a model captured in one line from the Panorays approach: "Depth where it matters. Not noise everywhere." Drystan Govender, Panorays lead at CRS, explains how risk-based supplier tiering works, how it maps to Panorays' Inventory, Assessment and Monitoring evaluation types, and why it is the most practical way to run third-party cyber risk management when time and people are limited.

📉 Why Flat Assessment Is Just Noise

A flat programme, applying the same depth of assessment to every supplier, feels thorough. In practice it spreads a small team thinly across the entire supplier base. Panorays' 2025 CISO survey found that 81% of CISOs say their third-party risk management budget is insufficient. When resources are that tight, every hour spent chasing a low-risk supplier through a long questionnaire is an hour not spent on the supplier that holds your customer data.

⚠️ The Symptoms of a Flat Programme

  • Questionnaire fatigue: low-risk suppliers receive long questionnaires they have little reason to prioritise, and response rates suffer.
  • Diluted attention: critical suppliers get the same once-a-year review as everyone else, with nothing in between.
  • Undifferentiated findings: hundreds of suppliers with middling scores, and no clear signal of which ones need action today.

Tiering replaces the question "how does every supplier score?" with a sharper one: "which handful of suppliers matter today, and what are we doing about them?" In Panorays' framing, the goal is to know which five vendors matter today, not to be handed 500 vendors with a C grade.

🧭 Two Questions That Sort Every Supplier

The tiering model CRS uses with Panorays sorts suppliers along two simple dimensions. Neither needs a complex scoring exercise to get started.

🔑 Is the Supplier Critical?

  • Would a failure or compromise at this supplier materially disrupt your operations, your customers or your obligations?
  • Does the supplier handle sensitive data on your behalf?
  • Would the supplier be difficult to replace quickly, or do several important processes depend on it?

💻 Is It an IT Supplier?

  • Does the supplier connect to your systems, host your data or provide technology your business depends on?
  • Or is the relationship primarily physical, professional or logistical?

These two questions mirror how Panorays calculates a supplier's Cyber Risk Rating, where impact is driven by the business and technology relationship. They also force a useful conversation about who decides criticality. In most organisations that should be the business owner of the relationship, working with the security team, rather than whoever happens to maintain the supplier spreadsheet.

🗂️ Mapping Tiers to Inventory, Assessment and Monitoring

Crossing the two questions produces four supplier categories, each with its own treatment and a matching Panorays evaluation type. Panorays designs its evaluation types to be mixed and matched to fit different risk profiles, so most customers will use all three.

  1. Critical IT → Monitoring. Typically the smallest group, and the one that deserves the most depth: a deep assessment plus continuous monitoring. Monitoring adds fourth-party auto-discovery, continuous remediation, threat intelligence from cyber news and the dark web, cyber alerts and rating history.
  2. Critical non-IT → Assessment. These suppliers may never touch your network, but losing them would hurt. The focus is a continuity and concentration review, with periodic assessment.
  3. Non-critical IT → Assessment. A standard assessment with scheduled reassessment keeps technology suppliers accountable without the overhead of continuous monitoring.
  4. Non-critical non-IT → Inventory. The majority of most supplier lists. Self-attestation and centralised visibility, with no ongoing monitoring.

Organisations in scope for DORA can add DORA support to the Assessment and Monitoring evaluation types. We look at that in DORA, NIS2 and the Joint Standards.

💡 Why the Model Works

For CRS, the value of the model is proportionality. Inventory gives full visibility of the long tail without burying the team in paperwork. Assessment produces structured evidence where evidence is genuinely needed. Monitoring keeps continuous attention on the small group of suppliers that could do real damage. The effort follows the risk, instead of being spread evenly across suppliers that pose very different levels of threat.

⚙️ How Panorays Automates the Tiering

Tiering by hand works for a dozen suppliers. It does not work for hundreds. Panorays' Third-Party Inventory, also referred to as Smart Inventory, is designed to automate the sorting.

  • Load every supplier: the inventory centralises the full third-party list, through API supplier upload or integrations with procurement and ERP systems such as Coupa, Oracle and SAP.
  • Tier on two indicators: Panorays auto-tiers suppliers using an internal inherent risk questionnaire (IRQ), which captures business impact, alongside each supplier's Cyber Posture Rating.
  • Assign a treatment: each supplier is assigned to continuous monitoring, periodic assessment or a watchlist.
  • Questionnaires by criticality: Smart Questionnaire templates can be customised by criticality, weighted, given deal-breakers and sent on an automatic schedule.
  • Approve by threshold: suppliers can be approved or rejected based on score, with remediation tasks generated automatically for the gaps.

The inventory can also label suppliers that use AI, which Panorays can then assess with its Basic, Detailed or Advanced AI questionnaires. That matters more every quarter as AI features appear inside products organisations already buy.

🔄 Tiers Move When Risk Moves

A tier is a starting point, not a permanent label. Relationships change: a non-critical supplier is given access to a production system, or a critical supplier suffers a breach. Panorays surfaces those changes between scheduled reviews.

  • Continuous Monitoring raises alerts on rating drops, dark-web mentions and compromised credentials, by email or webhook, with a year of rating history.
  • The Risk Insights and Response Portal alerts on breaches, known exploited vulnerabilities (KEVs), zero-days and cyber news, maps the impact across direct and indirect suppliers, and lets teams bulk-send incident questionnaires to those affected.
  • Remediation Management builds one aggregated plan per supplier from questionnaire and scan gaps. Set a target, for example moving a supplier from bad to good, and Panorays computes the fewest steps to get there. Task statuses include to-do, in progress, claim as fixed, decline and accept risk.

🚀 Where to Start

A good tiering exercise begins with a few honest questions. How many third parties do you have, and how many are critical or have access to your systems? Who decides criticality today? And how would you know if a critical supplier had been breached between annual reviews?

In the CRS managed-service model, a dedicated customer success manager tiers suppliers by criticality, sets up workflows, imports legacy spreadsheet questionnaires and adjusts weights, so customers get a working programme rather than another tool to run. A proof of concept on up to five critical suppliers is the quickest way to see the model applied to your own supplier base.

Ready to put depth where it matters? Explore Panorays on the CRS solution page, or, if you deliver security services to your own customers, become a CRS partner and offer risk-based third-party cyber risk management as a managed service.