Area of service03 / 05

Supply chain.

pleXcreen assesses indications of partner relationships and possible consequences; we clarify open questions with you.

The situation

A standstill creates pressure. Pressure creates exposure to extortion.

Your own company does not have to be attacked for a cyber incident to become your problem. Business partners, service providers and suppliers create dependencies.

When a partner fails, it is often unclear which consequences are evidenced. pleXcreen classifies indications of partner relationships and potential consequences, clarifying open points with you. This way, an incident at a partner does not only become a problem when a standstill occurs.

That is why these relationships belong in the overall picture as well.

Those who know their dependencies earlier can act before a partner's outage dictates their response.

The question for leadership

Which partner is critical to us, and where would its outage disrupt our operations?

What pleXcreen delivers to leadership

  1. 01

    Which relationships are evidenced

    Customers, suppliers and service providers with a clear level of evidence: supported, assumed or unknown.

  2. 02

    Where a disruption would hit you

    Which dependencies carry weight for your decision, such as single sources or regulatory requirements.

  3. 03

    What to do next

    What to verify internally, secure contractually or technically, and keep under observation.

Three partners, one operation. Whose outage would hit you?

Loading dock at night: on the left the gate of the company's own plant, in the middle a supplier's lorry with open doors, on the right an external service provider's van under a copper lamp.Fictitious example
supplierDelivers material. Dependency evidenced by contracts and delivery data.
service providerMaintains equipment remotely. Whether a replacement is available is open.
own operationThis is where it shows which outage actually stops the process.
  1. 1supplier Delivers material. Dependency evidenced by contracts and delivery data.
  2. 2service provider Maintains equipment remotely. Whether a replacement is available is open.
  3. 3own operation This is where it shows which outage actually stops the process.
Illustrative scene, no client data. Evidenced and assumed dependencies are reported separately.
Technical detail · optional · fictitious sampleHow a disruption travels through the chain.

A fictitious case: where the chain breaks, what is evidently affected behind it and what is only assumed.

Fictitious exampleCase B · no client data

A sub-supplier fails. What is affected behind it?

×Sub-supplierSupplierYour productionDeliverySecond source
  • interrupted
  • evidenced
  • derived
  • open
ConsequenceStatusBasis
Supplier loses component XevidencedExternal notice, confirmed by the supplier
Production could stop once stock runs outderivedForecast from internal stock data; separate validation step within the mandate
Second source can take overopenCapacity not confirmed

Whether the second source can deliver in time remains open until it confirms in writing.

Which partner is critical, and where does its failure hit your operation? Illustrative scene.

Method, scope and limits

01

What is examined

Within the agreed scope we collect, externally and passively, which customers, suppliers and service providers are connected to your organisation and which of these connections can be supported by independent sources, through technical dependencies, published references, register data or public contract information, for example.

For relevant partners we look at their own external exposure and known incidents, as far as publicly observable. We do not access third-party systems and carry out no active testing at partners. A partner appears in the result as a supported relationship only where more than one indication exists; everything else is marked as uncertain or unknown.

02

What you receive

You receive a picture of your relevant dependencies with a clear level of evidence: which relationships are supported, which are assumed and where the available information allows no statement. Together with an interpretation of which dependencies carry weight for your decision, because of single sources, regulatory supply-chain requirements or known incidents at a partner.

From this follow prioritised next steps: which relationships to verify internally, where contractual or technical safeguards should be reviewed, and what should be observed on an ongoing basis.

03

Regulatory context

For organisations within the scope of NIS2, in the critical-infrastructure context or with supply-chain due-diligence obligations, this perspective provides the observational basis on which supplier-security requirements can be assessed in the first place. It does not replace contractual or legal review, but prepares it with evidenced facts.

04

Who this is for

Executive management, procurement, risk management and CISOs in industry, critical infrastructure and complex organisations, especially where dependencies have grown historically and have never been systematically viewed from the outside.

What this service is not

  • No access to third-party systems and no active testing at partners, collection remains external and passive.
  • Not a complete map of all business relationships: the agreed scope is examined.
  • Not a credit or legal review of partners; where required, this is agreed separately with specialists.

Frequently asked questions

Where does the information about partners come from?
From independent, publicly observable sources: technical dependencies, published references, register data, public contract and incident information. Third-party systems are not accessed.
When does a relationship count as supported?
When several independent indications point to the same connection. A single indication is marked as uncertain; where indications are missing, the relationship remains unknown, which is not the same as “non-existent”.
Can this perspective run continuously?
Yes. As ongoing support, relevant relationships are reassessed periodically, so that new dependencies, incidents at partners or disappearing connections remain visible.

Next step

Arrange an initial conversation.

Free of charge, with no assessment. Getting in touch triggers neither an engagement nor any technical testing. Scope and depth are agreed only afterwards.