Skip to content

Solutions

Supply chain monitoring: detect partner risk early

Supply chain monitoring continuously observes your company's digital dependencies. blacklens.io matches your suppliers against ransomware leak sites, the dark web and new CVEs.

Supplier watchlist12 suppliers
Logistik Partner GmbHListed on a ransomware leak site, 30 min agoCritical
Software Zulieferer AGSoftwareNo hits
Muster SteuerberatungTax advisoryNo hits

Challenges in modern supply chains

No view of third-party assets

Which domains and login points of a partner connect to your systems is rarely known in full.

Compromised providers with access

A provider with remote access whose accounts are traded on the dark web leads straight into your network.

Late information

Whether a partner is compromised, you often learn weeks later from the supplier itself.

Regulatory requirements

NIS2, DORA and ISO 27001 require documented, ongoing monitoring of the supply chain.

How blacklens.io monitors your supply chain

Concrete threat signals instead of abstract security grades for third parties.

Compromised identities3 new hits
m.hu•••@beispiel-gmbh.atStealer log, 2 h agoEmployee
Microsoft 365 session cookieStealer log, 5 h agoEmployee
k.wa•••@gmx.atCombolist, 3 days agoCustomer

Visuals show sample data.

A monitored supply chain in three steps

  1. 1

    Import suppliers

    Import name and domain of your suppliers via CSV, for example straight from procurement.

  2. 2

    Continuous matching

    Leak sites of ransomware groups are polled and matched about every 30 minutes.

  3. 3

    Alert with all details

    "Potential Supply Chain Ransomware Threat" with actor, sector, country, post and screenshot.

Example from practice

Machinery manufacturer secures its supplier platform

blacklens.io found a partner's publicly reachable development environment with a valid access token for production APIs, plus a leaked IT service provider account on the dark web.

Result: The customer reacted within hours, before any damage occurred.

Evidence for NIS2, DORA and ISO 27001

Watchlist, alert history and activity log prove that you monitor your suppliers continuously and react to incidents.

Evidence for auditors and insurersas PDF
Supplier watchlistNIS2 Art. 21 (2) devery ~30 min
Matches on findingsDORA Art. 28on every match
Activity logISO/IEC 27001 A.5.22continuous

Frequently asked questions

Supply chain monitoring is the continuous observation of a company's digital dependencies: IT service providers, cloud providers, software vendors and technical subcontractors whose compromise directly affects your own security. The goal is to learn about an incident at a partner from your own alerting system, not from the press. NIS2 (Article 21(2)(d)), DORA (ICT third-party risk) and ISO 27001 (A.5.19 to A.5.22) demand exactly this view of the supply chain.

Which of your suppliers was on a leak site yesterday?

Import your supplier list as CSV and see within 24 hours which partners are affected.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings