Third-party risk

An outside-in rating and a questionnaire measure two different things — neither is your third party's posture

A security rating reads what is visible from the public internet. A questionnaire reads what the third party is willing to write down. Neither one opens an account and checks a configuration. That is the gap an inside-out program closes.

Blog

September 5, 2026 · 10 min read

01

What an outside-in rating can and cannot see

A rating built from internet-facing signals — exposed services, certificate hygiene, mail authentication records, breach chatter — is genuinely useful for a first pass across a large portfolio. It is also structurally limited to whatever a third party exposes to the public internet.

Most of a modern third party's risk surface is not internet-facing at all: internal identity permissions, storage bucket policies, Kubernetes namespace configuration, SaaS admin settings. None of that is visible from outside, no matter how sophisticated the scanning.

Dashboard: a third party's Security Score, KPIs and alerts on one screen — evidence, not an external inference.
Dashboard: a third party's Security Score, KPIs and alerts on one screen — evidence, not an external inference.
02

A questionnaire records an answer, not a configuration

A self-assessment questionnaire is a snapshot of what someone was willing to attest to on a given day, reviewed by no one but the person filling it in. It is slow to collect, quickly stale, and gives a contracting organization no way to verify a single answer.

The two approaches are not competitors to inside-out measurement; they simply answer a different question. Inside-out measurement answers: what is actually configured in the third party's own environment, right now.

  • Outside-in rating: what is visible from the public internet
  • Questionnaire: what the third party attests to, unverified
  • Inside-out: what is actually configured, evidenced control by control
03

The inside-out model, in one sentence

The contracting party creates an isolated workspace for the third party, invites the responsible contact by email, and the third party connects its own cloud, container and SaaS accounts using a read-only credential. From that point, the platform evaluates real configuration continuously and produces a Security Score with evidence behind every control.

  • One isolated workspace per third party
  • Invitation-based onboarding; the third party connects its own accounts
  • Read-only credential only — no standing write access is requested
  • Continuous re-evaluation, not a point-in-time snapshot
1stone Research

Talk to the team about a third-party program

A working session against your actual third-party portfolio: how workspaces are created, which accounts get connected first, and what the Security Score looks like in week one.

Request a walkthrough