ESRM Program · Operations Cluster
Supply Chain Security
Know which vendors and suppliers could hurt you, and what they can reach.
$2,500 fixed-fee assessment 3–4 weeks Credited toward the vCSO program
Measured against ISO 28000 and NIST SP 800-161. Led by Don Oxman, CPP, CISSP, CISM. Licensed by Texas DPS. In business since 2013.
Most vendor reviews end when the contract is signed.
Supply chain security is one of thirteen domains in our Enterprise Security Risk Management (ESRM) program, and part of the Operations cluster with Organizational Resilience, Business Continuity, and Crisis Management. It covers the vendors you rely on: a Grand Prairie plant with a sole-source part from overseas, or a payroll vendor with access to your network.
Vendor risk usually falls to purchasing, which watches price and delivery, or to the IT provider, which may only look at software. Nobody tracks who can get into the building, the network, or customer data, and vendor access often stays open long after the work is done. We help you rank vendors by risk and put controls on the ones that matter.
Where your vendors can expose you
Vendor breach
A software provider, IT firm, or payroll processor is compromised, and the attacker uses that vendor's access to reach your systems or data.
Lingering access
Contractors and former vendors keep badges, remote access accounts, or shared passwords long after the work ends, and nobody reviews them.
Sole-source failure
One supplier provides a critical part or service, and a fire, bankruptcy, or port delay on their side stops your production.
Cargo theft & tampering
Loads go missing between the dock and the customer, or shipments are opened and altered, sometimes with help from someone inside the chain.
Counterfeit parts
Fake or substandard components come in through a secondary distributor and cause product failures, warranty claims, or safety problems.
Hidden subcontractors
Your vendor passes work to subcontractors you have never heard of, who handle your data or products under weaker controls.
Five questions for leadership
- Do you have a current list of every vendor with access to your network, building, or data?
- Which single supplier, if it failed tomorrow, would stop your operations?
- Do your contracts require vendors to tell you promptly about a security incident?
- When a vendor relationship ends, who confirms that the vendor's access has been removed?
- Do you know which vendors pass your data on to their own subcontractors?
If you answered “no” or “not sure” to any of these, that is where we would start. Most of these gaps cost little to fix before an incident and a great deal to fix after one.
How an Engagement Works
Every ESRM domain starts with the same fixed-fee assessment. If you decide to continue, we credit the fee toward the program, and supply chain security becomes part of your vCSO engagement alongside whichever other domains you need.
Supply Chain Security Assessment
- Interviews with purchasing, operations or logistics, finance, and your IT provider.
- Structured review: a 15-question risk profile, a 25-point practices checklist, and a maturity score from 1 (Initial) to 5 (Optimized).
- Vendor inventory: your critical suppliers, what each can access, and what you would do without them.
- Gap analysis against ISO 28000 and NIST SP 800-161, the standards for supply chain security and cyber supply chain risk.
- Written report and prioritized roadmap, walked through with your leadership team. The report is yours whether or not you continue.
The fee is credited in full toward the program if you start within 90 days.
The vCSO / ESRM Program
- Assess (Q1): we start from your assessment findings and the vendor inventory.
- Build (Q2): vendor risk tiers, security terms for contracts, a standard vendor questionnaire, and a regular review of third-party access.
- Dependency planning: backup suppliers and workarounds for your sole-source and highest-risk vendors.
- Vendor access rules: access granted only as needed and removed when the work ends. Your IT provider makes the system changes.
- Operate (Q3+): we stay on as the named owner, with annual reviews of critical vendors and quarterly reporting to leadership.
Month to month. Cancel with 30 days’ notice. About the vCSO program →
Vendor Risk Services
- Deep-dive review of one critical vendor's security and continuity.
- Questionnaire program setup sized to your vendor list and risk tiers.
- Pre-contract review of a new vendor before you sign.
- Contract terms review for security and incident notice, with your counsel.
Why Total 360
Digital and physical risk
Vendor risk covers the remote access a vendor holds and the trucks and warehouses your goods pass through. We assess both in one review, so neither side gets missed.
Independent recommendations
We don’t resell vendor-risk platforms or take referral fees from suppliers. Our advice is based on your risk, not on a product we need to sell.
Experienced leadership
Led by Don Oxman: M.S. in Security Management, CPP, CISSP, CISM. U.S. Army and AT&T background. In business since 2013 and licensed by Texas DPS.
Common questions
What does a supply chain security assessment cost?
$2,500, as a fixed fee. It usually takes three to four weeks from kickoff to the readout. If you start the vCSO program within 90 days, the full fee is credited toward it.
What do we get at the end of the assessment?
A written report with your maturity score from 1 (Initial) to 5 (Optimized), the gaps we found against ISO 28000 and NIST SP 800-161, the standards for supply chain security and cyber supply chain risk, and a prioritized roadmap. We walk your leadership team through it, and the report is yours whether or not you continue.
Do we have to sign up for the full program?
No. The assessment stands on its own. If you continue, supply chain security runs inside the vCSO program at $2,500 to $7,500 a month depending on scope. It is month to month, and you can cancel with 30 days’ notice.
Can we buy vendor risk services without the program?
Yes. They are available to any client. Billed per vendor, quoted in advance.
Will you replace the people and providers we already use?
No. We work alongside your IT provider, attorney, insurer, and other advisors. We set the standard, help them meet it, and check that the work gets done.
Start with a 30-minute Risk Discussion
No deck and no sales pitch. Tell us which vendors and suppliers you rely on most. We’ll give you an honest read on where they expose you and send a scoped proposal within five business days.
Schedule a Risk Discussion Or call 817-677-0515 · info@total360security.com