Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

USE CASE · SUPPLY CHAIN

A thousand suppliers. One defensible risk position.

Supply-chain attacks come in through the vendors you trust. Run third-party risk as a continuous program: inventory, proportionate assessment, shared remediation, and the regulatory deliverables that come with it.

Supplier dependency graph Illustrative data

Suppliers · Trust Grade

Nordwind Logistics B
Helios Cloud Services D
Corvus Analytics A−

Assessment initiatives

Portal onboarding

Onboarding

Remediation plan · Q4

Active · shared

Annual reassessment

Validated

Shared frameworks · value chain

ISO 27001
DORA

Value chain

Online payments

Has initiative Uses framework Supports

The inventory as a graph: one degraded Trust Grade, and every framework and business activity it touches is one hop away.

THE SITUATION

Your attack surface signed a contract with you.

  1. Questionnaire fatigue, both sides

    Your team chases answers; suppliers drown in forms. Response rates drop exactly where the risk is highest.

  2. Concentration hides in a flat list

    One cloud provider behind twelve critical services looks like a single vendor line, right up until it fails.

  3. DORA does not wait for your program

    The register of information is due whether your third-party program is ready or not.

  4. Annual reassessment always arrives late

    A supplier assessed in January can be breached in March. A yearly cycle guarantees you find out the following January.

CAPABILITIES

From vendor list to risk program.

  1. An inventory that shows dependencies

    Suppliers mapped as a graph: who provides, operates or hosts what, and where a single failure would spread.

  2. Assessments that scale

    A guided assessment flow on a versioned questionnaire library: proportionate questions, AI-suggested frameworks, one process from intake to validation.

  3. Suppliers answer fast

    A dedicated portal where vendors respond, with Ernest drafting answers from their own documents for a human to confirm. Days, not months.

  4. Scores you can compare and defend

    Automated scoring against NIST CSF, enriched with external ratings, comparable across your whole vendor base.

  5. Remediation both sides sign

    Joint action plans negotiated with the supplier in the platform: accepted, rejected or counter-proposed, then tracked as tickets on both sides.

  6. DORA deliverables built in

    Register of information, ICT concentration analysis (Art. 29) and TLPT engagement tracking (Art. 26-27), fed by the same living data.

REMEDIATION, SHARED

A finding your supplier never accepted is a finding that never closes.

Most programs end at the scorecard. Mindlapse continues into remediation: action plans are negotiated with the supplier, accepted explicitly, and tracked to completion on both sides, with re-assessment armed for when the work lands.

  1. 01

    Inventory and tier

    Import your vendor base, map dependencies, and tier by criticality so the effort follows the risk.

  2. 02

    Assess in context

    Proportionate questionnaires through the vendor portal, AI-drafted answers for speed, automated scoring for comparability.

  3. 03

    Remediate and re-verify

    Joint action plans with your suppliers, and re-assessments triggered by events, not by the calendar.

FAQ

Supply-chain risk, in practice

Do suppliers need a Mindlapse license?

No. They respond through a dedicated portal invitation, at no cost to them. And when a supplier runs Mindlapse too, answers and action plans synchronize between the two organizations.

How is this different from sending spreadsheets?

Proportionate questionnaires instead of one-size-fits-all, AI-drafted answers instead of blank forms, automated scoring instead of manual review, and a remediation loop instead of a filed PDF.

Does it produce the DORA register of information?

Yes. The register is built from the same living data, functions, systems and suppliers, rather than assembled once a year, and exported when you need it.

What triggers a re-assessment?

Events you configure: new findings, expiring attestations, changes of scope or criticality. Triggers fire targeted re-checks instead of another full annual campaign.

SUPPLY CHAIN, VERIFIED

Bring your supplier list. Leave with a program.

A live walkthrough on a real example: tiering, assessment, joint remediation and the DORA register.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.