1stone Research

Third-party cyber risk, measured from the inside out

Notes on connecting a third party's own cloud and SaaS accounts with read-only credentials, on how the Security Score is composed, on the fix-first remediation queue and on evaluating CIS, NIST 800-53, PCI DSS 4.0, ISO 27001, GDPR, DORA, FedRAMP, GxP and C5 without a single questionnaire. Every article ships with the real 1stone console screens.

Third-party risk

An outside-in rating and a questionnaire measure two different things — neither is your third party's posture

A security rating reads what is visible from the public internet. A questionnaire reads what the third party is willing to write down. Neither one opens an account and checks a configuration. That is the gap an inside-out program closes.

Read article
An outside-in rating and a questionnaire measure two different things — neither is your third party's posture
1stone Research

Articles

Long-form material on how third-party risk is actually measured: the problem with outside-in signals, the architecture that replaces them and the operating cadence that keeps a third party's posture converging.

1stone Research

Talk to the team about a third-party program

A working session against your actual third-party portfolio: how workspaces are created, which accounts get connected first, and what the Security Score looks like in week one.

Request a walkthrough