We've introduced a new security questionnaire to help assess an organization’s security controls in line with the supplier risk management requirements of the NIS 2 Directive. This questionnaire integrates and expands on the controls from ISO 27001:2022 and NIST CSF 2.0, addressing the alignment with international standards and key components of NIS 2 supplier risk management requirements such as incident response, contractual safeguards, compliance with data protection laws and regulations, and cross-border data flows.
SIG Core and Lite questionnaires updated to 2025 versions
We've updated our SIG Core and SIG Lite questionnaires to the 2025 versions, incorporating the latest review and updates driven by industry standards and regulatory requirements for enhanced risk assessment. You can also now choose which sections of the SIG questionnaires to send, removing unnecessary sections and streamline the vendor’s response.
Other improvements
- We’ve added vulnerability detection for vulnerabilities in Palo Alto PAN-OS and FortiManager to our passive scanners, broadening our scanning capabilities for both Breachsight and Vendor Risk.
- We’ve continued to expand our sources for News and Incidents.