I will assess your vendors for security risk
The Cyber Friend, where you can Trust Us, with your Security
Vetted by Fiverr Pro
Sam was selected by the Fiverr Pro team for their expertise.
Vetted for
Cybersecurity
About this Gig
Vetted Pro
Your regulator already requires this. 16 CFR 314.4(f) requires periodic assessment of your service providers based on the risk they present. 45 CFR 164.308(b)(1) requires satisfactory assurances from every business associate. PCI DSS 12.8 says the same for cardholder data.
Almost nobody does it. The contract is signed, the vendor gains access, and nothing is checked again until an auditor requests the file and finds none.
I run the process so there is one.
What you receive:
- A security questionnaire sent to each vendor, chased until it comes back
- Public record review: breaches, litigation, and exposed infrastructure
- A written risk summary for every vendor in plain language
- Risk ratings so you know which relationships need attention
- A prioritized remediation list you can take to the vendor
- Vendor scorecards and an executive report
- Documentation dated and filed, so the next auditor gets an answer
I contact your vendors directly. You send the list, and I chase them, including the ones who ignore it twice.
CISM. CMMC Registered Practitioner Advanced. Master's in Cybersecurity.
Message me with how many vendors touch your regulated data, and I will tell you which tier fits.
Technology:
Cloud - IaaS
•
Mail Services
•
Saas
•
Databases
Regulation:
Other
Other Cybersecurity Services I Offer
FAQ
Are we actually required to do this?
If you are a financial institution under the FTC Safeguards Rule, 16 CFR 314.4(f) requires periodic assessment of service providers. If you handle patient data, 45 CFR 164.308(b)(1) requires assurances from business associates. If you take cards, PCI DSS 12.8 applies. Most firms hit at least one.
Do we have to contact the vendors ourselves?
No. You send the list of vendors with contact details. I send the questionnaire, follow up when they ignore it, and follow up again. Chasing vendors is the bulk of the work, and it is the part you are paying me to take on.
What if a vendor refuses to respond?
Some will. I document the outreach attempts and the non-response, then assess what I can from public records. A vendor who will not answer a security questionnaire is itself a finding, and it is one your auditor will want recorded rather than left blank.
How do we know which vendors to include?
Start with anyone who stores, processes, or can access your regulated data, plus anyone whose outage would stop you operating. Send me your list, and I will tell you if the count looks wrong before you order.
What is the difference between this and a vendor risk management program?
This is a point-in-time review with a report at the end. The program includes ongoing monitoring, quarterly reviews, and annual reassessment for a larger vendor population. Most people start here and move to the program once they see the size of the problem.
Do you assess the vendor, or just read their answers?
Both. The questionnaire is the vendor's account of itself. I check it against public records: known breaches, litigation, exposed infrastructure, and certificate and DNS history. Where the two disagree, that goes in the report.
How long does it take?
20 days for 5 vendors, 30 for 10, 45 for 15. Most of that is waiting on vendors. If yours respond quickly, it comes back sooner, and I keep you updated on who has replied and who has not.
What do we do with the report?
Three things. Keep it as evidence that you assessed your vendors. Work the remediation list with the vendors that scored poorly. Reuse the answers when a client sends you a security questionnaire, since they overlap heavily.
Can you review vendors we have not signed with yet?
Yes, and that is the best time. Assessing before signing means findings become contract terms instead of problems you inherit. Say which vendors are prospective when you send the list.
We only have three vendors. Is there a smaller option?
Message me. The 5-vendor tier is the smallest package, but if you genuinely have fewer, I would rather scope it honestly than sell you slots you cannot use.

