Solutions
Supply chain monitoring: detect partner risk early
Supply chain monitoring continuously observes your company's digital dependencies. blacklens.io matches your suppliers against ransomware leak sites, the dark web and new CVEs.
Challenges in modern supply chains
No view of third-party assets
Which domains and login points of a partner connect to your systems is rarely known in full.
Compromised providers with access
A provider with remote access whose accounts are traded on the dark web leads straight into your network.
Late information
Whether a partner is compromised, you often learn weeks later from the supplier itself.
Regulatory requirements
NIS2, DORA and ISO 27001 require documented, ongoing monitoring of the supply chain.
How blacklens.io monitors your supply chain
Concrete threat signals instead of abstract security grades for third parties.
- CVE published08:12
- 2 assets in your inventory affected09:00
- Confirmed by PoC scan09:26
- Alert sent to Microsoft Teams09:27
- Jira
- Microsoft Teams
- Slack
- GitHub
- GitLab
- Elastic
- AWS
- Microsoft Azure
- Google Cloud
- Cloudflare
- Hetzner
- Webhook
Visuals show sample data.
A monitored supply chain in three steps
- 1
Import suppliers
Import name and domain of your suppliers via CSV, for example straight from procurement.
- 2
Continuous matching
Leak sites of ransomware groups are polled and matched about every 30 minutes.
- 3
Alert with all details
"Potential Supply Chain Ransomware Threat" with actor, sector, country, post and screenshot.
Example from practice
Machinery manufacturer secures its supplier platform
blacklens.io found a partner's publicly reachable development environment with a valid access token for production APIs, plus a leaked IT service provider account on the dark web.
Result: The customer reacted within hours, before any damage occurred.
Evidence for NIS2, DORA and ISO 27001
Watchlist, alert history and activity log prove that you monitor your suppliers continuously and react to incidents.
Frequently asked questions
- Supply chain monitoring is the continuous observation of a company's digital dependencies: IT service providers, cloud providers, software vendors and technical subcontractors whose compromise directly affects your own security. The goal is to learn about an incident at a partner from your own alerting system, not from the press. NIS2 (Article 21(2)(d)), DORA (ICT third-party risk) and ISO 27001 (A.5.19 to A.5.22) demand exactly this view of the supply chain.
Which of your suppliers was on a leak site yesterday?
Import your supplier list as CSV and see within 24 hours which partners are affected.
- 14 days free, all features
- No credit card required
- We walk you through your first findings