Skip to main content
Essentials course

Cybersecurity Supply Chain and Third-Party Risk Management

How suppliers, vendors and partners become part of your security: the risks they bring, the questions to ask before you sign, sharing data and access safely, and what to do when a supplier has an incident.

  • Format Online, self-paced
  • Scope 7 lessons
  • Duration About 60 min
  • Cost Included in your subscription

About this course

This course explains how an organization’s security depends on the suppliers, vendors and partners it works with, and where that risk comes in: the software and cloud services you rely on, the contractors with access to your systems, and the partners you share data with. It covers the security questions to ask a vendor before you sign, how to share data and access safely, the warning signs of a supplier breach, a fake vendor or a hijacked account, and what to do when a supplier has an incident. It’s written for every employee who works with third parties, in plain language, with scenarios from everyday procurement and partnership work.

Many of the largest breaches now start at a supplier: a compromised software update, a contractor’s stolen credentials, or a partner who kept more data than they needed. The people who choose vendors, share files with them and answer their emails are rarely security specialists, so questions go unasked, access is granted and never removed, and a supplier’s incident reaches the organization before anyone knows to react. Customers, insurers and rules such as NIS2 now ask organizations to show how they manage this risk.

  • Scenarios and a knowledge check
  • Web and mobile app, including offline

Content

  1. Lesson 1

    Why suppliers, vendors and partners are part of your security

  2. Lesson 2

    Where third-party risk comes in: software, cloud services, contractors and partners

  3. Lesson 3

    Before you sign: the security questions to ask a vendor

  4. Lesson 4

    Sharing data and access with third parties safely

  5. Lesson 5

    Warning signs: supplier breaches, fake vendors and hijacked accounts

  6. Lesson 6

    What to do when a supplier has an incident

  7. Lesson 7

    Scenarios

Builds on

Recommended before this course. Every course stands on its own and restates what it relies on, so none of these is a requirement.

Who it is for

  • All employees who work with suppliers, vendors and partners

Fee and registration

Included in your subscription

How to get started

  1. Book a demo

    We show the Course Library on your own use case and set up your subscription.

  2. Add your people

    Invite your users to TechClass. Each user license includes every Essentials course.

  3. Assign the course

    Pick it from the Course Library and assign it to everyone, or to the roles that need it. Completions and certificates are recorded for your reporting.

Already a TechClass customer? Your admin can assign the course from the Course Library right away.

Book a demo
Questions, answered

Cybersecurity Supply Chain and Third-Party Risk Management FAQ

Yes. Every TechClass user license includes the Essentials courses in the Course Library, and this is one of them. There is no fee per course or per learner.

About 60 minutes, in short lessons. It is self-paced, so a learner can stop and continue on any device, including the mobile app, and offline.

Yes. A certificate of completion is issued when the knowledge check is passed, and the completion is recorded for your reporting.

It supports one, where a rule asks that people are trained on the subject, and TechClass records who completed it. Whether a requirement is met depends on your own policies and processes, so that is a question for your compliance lead or legal adviser.

Library courses are ready to use as they are. You can build and fully edit your own courses in TechClass, including from your own policies with the AI Course Creator, and combine both in one learning program.

An Essentials course gives everyone the concepts and rules in about an hour. A Skills course goes deeper for the roles that need it: about 8 hours with practice, a graded assessment and a certificate that lists the skills, licensed per learner.

English, at this stage.

Cybersecurity

Interested in Cybersecurity Supply Chain and Third-Party Risk Management?

How suppliers, vendors and partners become part of your security: the risks they bring, the questions to ask before you sign, sharing data and access safely, and what to do when a supplier has an incident.