Security category

Third-Party Risk & GRC

Assess vendors, evidence controls, and streamline audit and compliance workflows.

What this category includes

  • Discovery and inventory of the assets, identities, or data in scope
  • Policy and control enforcement aligned to your risk appetite
  • Detection, prioritization, and response workflows
  • Reporting and evidence for audit and executive stakeholders
  • Integration with your existing security and IT stack

Why it matters now

Buying pressure in this category is rising as environments change faster than control coverage. Teams that define requirements before engaging vendors move faster and negotiate from a stronger position.

Common buyer triggers

  • An audit finding or regulatory deadline
  • A security incident or near miss
  • Tool consolidation or renewal pressure
  • A major platform, cloud, or AI adoption program
  • Headcount constraints driving automation or managed coverage

Key capabilities to evaluate

  • Coverage breadth across your actual environment, not the demo environment
  • Accuracy and tuning effort in the first 90 days
  • Workflow fit with your ticketing and ownership model
  • Deployment effort and time to first measurable value
  • Commercial model that scales predictably with growth

Questions to ask vendors

  • What does a realistic 90-day rollout look like for an organization our size?
  • Which of these capabilities are generally available today versus on the roadmap?
  • How is pricing metered, and what causes it to increase?
  • What do we lose if we leave — and how portable is our data and configuration?

Featured vendors

Armis logo

Armis

Third-Party Risk & GRC

Armis is the first agentless, enterprise-class security platform to address the new threat landscape of unmanaged and IoT devices.

armis.comopens in a new tab
EstablishedIoT Cyber SecurityIoT Security
View Vendor Profile
BitSight logo

BitSight

Third-Party Risk & GRC

Founded in 2011, BitSight transforms how organizations manage information security risk.

bitsight.comopens in a new tab
EstablishedCyber Security Ratings PlatformCybersecurity Risk Ratings
View Vendor Profile
Netwrix logo

Netwrix

Third-Party Risk & GRC

Netwrix is a software company that enables information security and governance professionals to reclaim control over sensitive, regulated and business-critical data, regardless of where it resides.

netwrix.comopens in a new tab
EstablishedAuditor PlatformAuditor Tools
View Vendor Profile
TrustMAPP logo

TrustMAPP

Third-Party Risk & GRC

TrustMAPP delivers continuous Security Performance Management (SPM), giving CISOs a real-time view of their cybersecurity maturity.

trustmapp.comopens in a new tab
EstablishedSecurity Performance Management (SPM)CISO Performance Tool
View Vendor Profile
Black Kite logo

Black Kite

Third-Party Risk & GRC

In 2016, Black Kite began its journey to redefine third-party risk management (TPRM), building the world's first security ratings service designed from a hacker's perspective.

blackkite.comopens in a new tab
EstablishedCyber Security Ratings PlatformCybersecurity Risk Ratings
View Vendor Profile
AWS Marketplace logo

AWS Marketplace

Third-Party Risk & GRC

AWS Marketplace is a curated digital catalog that makes it easy for organizations to discover, procure, entitle, provision, and govern third-party software.

aws.amazon.comopens in a new tab
EstablishedAWS MarketplaceAWS
View Vendor Profile
Krewe Advisory Group logo

Krewe Advisory Group

Third-Party Risk & GRC

A team of enterprise technology advisors whose core focus is to help you navigate strategic issues and align technology with the vision of the business.

kreweag.comopens in a new tab
EstablishedCyber Security Consulting
View Vendor Profile

BigID

Third-Party Risk & GRC

BigID — Third-Party Risk & GRC.

Established
View Vendor Profile

CyberArk

Third-Party Risk & GRC

CyberArk — Third-Party Risk & GRC.

Established
View Vendor Profile
Valimail logo

Valimail

Third-Party Risk & GRC

Valimail is a pioneering, identity-based, anti-phishing company that has been ensuring the global trustworthiness of digital communications since 2015.

valimail.comopens in a new tab
EstablishedDMARCDMARC Monitoring
View Vendor Profile
Seraphic Security logo

Seraphic Security

Third-Party Risk & GRC

The browser has become the main productivity tool for employees due to driving trends like working remotely, BYOD, and web-based SaaS applications.

seraphicsecurity.comopens in a new tab
EstablishedEnterprise Web BrowserBrowser Security
View Vendor Profile
Zimperium logo

Zimperium

Third-Party Risk & GRC

Zimperium, the global leader in mobile device and application security, offers the only real-time, on-device, machine learning-based protection against Android, iOS, and Chromebooks threats.

zimperium.comopens in a new tab
EstablishedMobile Security
View Vendor Profile
Surf Security logo

Surf Security

Third-Party Risk & GRC

The business landscape is fundamentally changing – the way and location of work has been transformed.

surf.securityopens in a new tab
EstablishedSecure Web BrowserEnterprise Web Browser
View Vendor Profile
Halcyon logo

Halcyon

Third-Party Risk & GRC

alcyon is a cybersecurity company building products that stop ransomware from impacting enterprise customers.

halcyon.aiopens in a new tab
EstablishedRansomware PreventionAnti-Ransomware
View Vendor Profile
Conceal logo

Conceal

Third-Party Risk & GRC

Conceal’s mission is to stop ransomware and credential theft for organizations of all sizes by developing innovative solutions that provide social engineering protection in any browser, ensuring employee productivity and…

conceal.ioopens in a new tab
EstablishedSecure Web BrowserWeb Browser Security
View Vendor Profile
Safe Security logo

Safe Security

Third-Party Risk & GRC

Safe Security is a pioneer in the “Cybersecurity and Digital Business Risk Quantification” (CRQ) space.

safe.securityopens in a new tab
EstablishedCyber Risk Quantification - CRQ
View Vendor Profile
Venminder logo

Venminder

Third-Party Risk & GRC

Venminder is an industry recognized leader of third-party risk management solutions.

venminder.comopens in a new tab
EstablishedThird Party Risk Management - TPRMIT Vendor Risk Management
View Vendor Profile
OpenVPN logo

OpenVPN

Third-Party Risk & GRC

OpenVPN® solutions help organizations to easily create secure, virtualized, reliable networks that ensure secure communications between on-premise applications, SaaS applications, a remote workforce, business partners, I…

openvpn.netopens in a new tab
EstablishedZTNA - Zero Trust Access Control
View Vendor Profile
Zero Networks logo

Zero Networks

Third-Party Risk & GRC

Zero Networks provides a simple, unified Zero Trust platform for secure remote connectivity and software-defined segmentation for any asset: IT/OT, on prem and in the cloud.

zeronetworks.comopens in a new tab
EstablishedMicrosegmentation
View Vendor Profile
ThreatConnect logo

ThreatConnect

Third-Party Risk & GRC

ThreatConnect enables threat intelligence operations, security operations, and cyber risk management teams to work together for more effective, efficient, and collaborative cyber defense and protection.

threatconnect.comopens in a new tab
EstablishedCyber Risk Quantification - CRQ
View Vendor Profile
Axio logo

Axio

Third-Party Risk & GRC

Axio is the leader in SaaS-based cyber management software, which empowers security leaders to build and optimize security programs and quantify risk in financial terms.

axio.comopens in a new tab
EstablishedCyber Risk Quantification - CRQ
View Vendor Profile
X-Analytics logo

X-Analytics

Third-Party Risk & GRC

Secure Systems Innovation Corporation (SSIC) is a cyber risk analytics firm with a mission to inform strategic decision-making by harmonizing enterprise cybersecurity strategy with risk management strategy.

x-analytics.comopens in a new tab
EstablishedCyber Risk Quantification - CRQRisk Management Solution
View Vendor Profile

DeskTime

Third-Party Risk & GRC

DeskTime — Workforce Analytics.

EstablishedWorkforce Analytics??Workforce Analytics
View Vendor Profile
Senteon logo

Senteon

Third-Party Risk & GRC

Senteon automates the deployment of 400+ security configurations, resulting in unmatched operational efficiency, accuracy, and cost savings.

senteon.coopens in a new tab
EstablishedCIS Controls ComplianceCIS Compliance Automation
View Vendor Profile
Gutsy logo

Gutsy

Third-Party Risk & GRC

Gutsy is a data-driven security governance platform which gives security leaders a process centric understanding of how their security teams, tools, and services really work together, so they can lower risk, get better s…

gutsy.comopens in a new tab
EstablishedGovernance Risk and Compliance - GRCGRC Automation Platform
View Vendor Profile
SeeMetrics logo

SeeMetrics

Third-Party Risk & GRC

SeeMetrics is an automated cybersecurity performance management platform that integrates security data and business objectives into a simple interface.

seemetrics.coopens in a new tab
EstablishedCybersecurity Performance DashboardCybersecurity Stack Management
View Vendor Profile
Hubstaff logo

Hubstaff

Third-Party Risk & GRC

Hubstaff is a workforce management tool that helps businesses reach new heights through better team, project, and time management.

hubstaff.comopens in a new tab
EstablishedWorkforce ManagementWorkforce Productivity
View Vendor Profile
Amplifier Security logo

Amplifier Security

Third-Party Risk & GRC

First Autonomous User Security platform – a system that uses AI to automate user engagement, drive remediation, and close security gaps in real time.

amplifiersecurity.comopens in a new tab
EstablishedUser Security Posture ManagementUser Security
View Vendor Profile
TruOps logo

TruOps

Third-Party Risk & GRC

TruOps is a multi-tenant Governance, Risk, and Compliance (GRC) platform, offering a cutting-edge, cloud solution to transform traditionally siloed processes into a comprehensive risk management solution.

truops.comopens in a new tab
EstablishedGovernanceRisk
View Vendor Profile

Emerging vendors from Breach Tank

Early-stage companies surfaced through Breach Tank pitch sessions. Inclusion is for discovery, not endorsement.

Featured Breach Tank startups will appear here soon. Visit breachtank.com to see the latest pitches.

Get a Third-Party Risk & GRC buying roadmap.

We will map the category, shortlist vendors matched to your environment, and coordinate evaluations.