For years, third-party cyber risk management was treated as good practice: something mature security teams did well and everyone else intended to get round to. In the view of Cyber Retaliator Solutions (CRS), that era is over. In the EU, and increasingly in South Africa's financial sector, organisations are expected to show how they identify, assess and monitor the security of the suppliers they depend on.
Drystan Govender, Panorays lead at CRS, looks at what Panorays provides for DORA and NIS2, and sets out CRS's own view of how South African regulation is heading in the same direction. To keep things clear, this article separates what the Panorays platform provides from CRS commentary throughout.
⚖️ Why Supplier Risk Became a Compliance Issue
The logic is straightforward. According to Forrester research cited by Panorays, third-party breaches make up nearly 60% of cyber events. IBM's Cost of a Data Breach 2024 report, as quoted by Panorays, found that 15% of breaches originated from supply-chain vulnerabilities. When that much risk sits outside the organisation, it is no surprise that regulators treat the supply chain as part of an organisation's own resilience.
The regulations and frameworks Panorays addresses reflect that shift. Alongside DORA and NIS2, they include NIST CSF, ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, NYDFS, the EBA outsourcing guidelines, PRA SS2/21 and FCA requirements.
🔁 What Regulators Tend to Ask For
In CRS's view, whatever the framework, the underlying expectations are similar:
- A complete, current inventory of third parties, including which ones are critical.
- Assessment that is proportionate to the risk each supplier poses.
- Ongoing monitoring between formal reviews, not just an annual snapshot.
- Evidence that identified gaps are remediated, or consciously accepted.
- Oversight at management and board level.
🏦 DORA and the Register of Information
At the heart of DORA's third-party requirements is the Register of Information, which Panorays describes as a "mandatory, standardised record of all contractual arrangements with ICT third-party providers". Building and maintaining it by hand is a substantial undertaking. Panorays offers what it calls the "first full-fledged TPCRM-based DORA RoI solution".
📑 What the Panorays DORA Solution Includes
- A guided checklist that walks teams through building the register.
- Nine regulator-mapped DORA templates.
- Register of Information simulation and error handling, so problems are caught before submission rather than after.
- A submission-ready ZIP output.
- DORA support is available as an add-on to the Assessment and Monitoring evaluation types.
Panorays-published case studies show the approach in practice. Insurer Lemonade automated its DORA Register of Information with Panorays, and marine insurer NorthStandard used the platform to address PRA SS2/21 and DORA requirements, reporting 75% less assessment time.
🔎 Why DORA Matters Here
In CRS's view, DORA's reach extends well beyond the EU financial entities it regulates directly, because those entities must account for their ICT suppliers. South African technology and service providers that support EU financial institutions should expect to be asked for information that feeds their customers' registers, and South African groups with EU-regulated subsidiaries may carry obligations of their own. Applicability depends on each organisation's circumstances.
🌐 NIS2 and the Wider Framework Landscape
NIS2 is among the EU regulations Panorays lists for its platform. In CRS's reading, NIS2 carries the same basic expectation as DORA, that organisations understand and manage the security of their supply chains, into a much wider range of sectors than financial services. For South African organisations that serve EU customers, supply-chain security questions are likely to arrive through contracts and due-diligence requests.
🤖 AI Suppliers Are the Next Frontier
- Panorays can automatically label suppliers that use AI, so AI risk does not hide inside ordinary supplier relationships.
- Its Basic, Detailed and Advanced AI questionnaires assess those suppliers, with the Advanced questionnaire aligned to ISO 42001, the NIST AI RMF and the EU AI Act.
- Panorays itself holds ISO/IEC 42001:2023 certification for AI management, alongside ISO/IEC 27001:2022 and SOC 2 Type II, which matters when your third-party risk platform is itself one of your suppliers.
🌍 CRS's View: South Africa Is Moving the Same Way
This section is CRS commentary. The South African instruments below do not feature in Panorays' own materials. How the platform can support organisations subject to them is CRS's view, not a Panorays claim.
🏛️ The Joint Standards
The Prudential Authority and the Financial Sector Conduct Authority have issued Joint Standard 1 of 2023, on IT governance and risk management, and Joint Standard 2 of 2024, on cybersecurity and cyber resilience. In CRS's reading, both include requirements relating to third parties and outsourced providers. For financial institutions, that means having a defensible, documented way to identify, assess and monitor the ICT suppliers they rely on.
🔐 POPIA Sections 19 and 21
POPIA reaches well beyond financial services. Section 19 requires a responsible party to secure personal information through appropriate, reasonable technical and organisational measures. Section 21 requires it to ensure, through a written contract, that operators processing personal information on its behalf establish and maintain those security measures. In CRS's view, knowing whether a supplier actually maintains them, rather than simply promising to, is a third-party cyber risk question.
📘 King IV and ISO/IEC 27001:2022
King IV Principle 12 calls on the governing body to govern technology and information in a way that supports the organisation in setting and achieving its strategic objectives, which, in CRS's view, includes technology risk held by suppliers. For organisations certified to or aligning with ISO/IEC 27001:2022, supplier relationships are covered by Annex A controls 5.19 to 5.22: information security in supplier relationships, addressing security within supplier agreements, managing security in the ICT supply chain, and monitoring, review and change management of supplier services.
This commentary is general in nature and is not legal advice. Customers should confirm their specific obligations under these instruments with their compliance advisers.
🧰 Turning Obligations into Evidence
Auditors and regulators tend to ask the same practical questions. Here is what Panorays provides against each of them.
- "Do you know who your third parties are?" Third-Party Inventory centralises every supplier and tiers them automatically, while supply chain discovery identifies fourth and Nth parties and Shadow IT, with evidence.
- "Is your assessment proportionate?" Risk-based tiering across the Inventory, Assessment and Monitoring evaluation types, with questionnaires customised by criticality. See risk-based supplier tiering with Panorays.
- "How do you verify what suppliers tell you?" Smart Questionnaire answers are validated against posture data, and AI Document Validation checks certifications and attestations against questionnaire answers.
- "How do you monitor between reviews?" Continuous Monitoring with alerts and a year of rating history, plus the Risk Insights and Response Portal for breaches, KEVs and zero-days.
- "What happens when you find a gap?" Remediation Management tracks every task, including decisions to accept risk, creating a record of how each issue was handled.
- "What does the board see?" The Board Member View and Compliance & Standards reports.
Panorays also integrates with GRC platforms including Archer, AuditBoard, Diligent, Drata, ServiceNow and OneTrust. In CRS's view, that is the right way to position it: GRC tools manage the policies, paperwork and workflow, while Panorays supplies the cyber evidence layer alongside them.
🚀 Next Steps
Compliance is rarely the only reason to manage third-party cyber risk, but it is often the reason a programme finally gets a named owner and a deadline. CRS partners can deliver Panorays as a managed service, so customers can build the evidence auditors and regulators ask for without building a new team. Customers should still confirm their specific obligations with their compliance advisers.
Ready to turn supplier-risk obligations into evidence? Explore Panorays on the CRS solution page, or, if you are a reseller, MSP or MSSP, become a CRS partner and help your customers meet the growing expectations on third-party cyber risk.
