Third-party & Cyber Risk

Vendors, vulnerabilities and incidents — all tied to the controls they affect.

Third parties are dependencies. Vulnerabilities are signals. Incidents are evidence.

DPDPRBIGDPRCERT-InISO 27001
The Problem

None of them talk to each other. None tie back to controls.

Vendors are managed in spreadsheets — registries expire silently, reassessments slip, and no one knows which vendor's failure breaks which control. VAPT findings sit in PDFs disconnected from the controls they affect. Security incidents are managed in a separate ITSM or SIEM tool with no link to control failures or the risk register. Regulator notifications (DPDP, RBI 6-hour, GDPR 72-hour) happen in email, by memory. None of these systems talk to each other — and none tie back to the controls they are supposed to protect.

The GRAC Approach

A third party is a dependency. A vulnerability is a signal. An incident is evidence.

Third-party Risk is built on top of GRAC's Dependency Registry — a third party is a dependency type. VAPT engagements scope and log findings; findings link to Practice Instances, dependencies and obligations. Incidents are case-managed with timeline reconstruction and direct linkage to the Practice Instances and dependencies that failed. Regulator notification workflows fire on incident type. The asset registry submodule ties every system to controls and VAPT findings. The dependency map makes every vendor-to-control relationship visible.

Dependency Registry
Vendors are a first-class dependency type.
Linked VAPT Findings
Every finding ties to controls, risks, assets.
Case-managed Incidents
Timeline reconstruction + dependency linkage.
Notification Workflows
Pre-built for DPDP / RBI / GDPR / CERT-In.
What You Get

Four capability groups. One operating fabric.

01

Third-party Risk Management

  • Vendor registry tiered by risk (critical / high / medium / low) on configurable criteria — extends the master dependency registry

  • Questionnaire templates aligned to authority requirements and internal policies

  • Send, score, rate assessments; auto-score objective questions, flag subjective for review; link outcomes to specific Practice Instances and obligations

  • Onboarding approval workflow with threshold gating

  • Periodic reassessments at frequency configured per risk tier; API integrations where available, manual tickets otherwise

  • Scoped vendor portal — vendors see only what's shared with them; every external action logged

  • Dependency health flags surface the exact Practice Instances affected when any vendor degrades

  • Escalation and offboarding workflows

02

VAPT Management

  • Engagements scoped by type (VA, PT, or both), methodology, target systems, internal owners, external testing vendors

  • Configurable recurrence — annual, semi-annual, on-demand, post-change

  • Findings logged with severity, affected asset, linked Practice Instances, dependencies, obligations

  • Remediation lifecycle with owners, deadlines, retest scheduling

  • Exception and risk acceptance workflows

  • Findings above severity threshold surface candidate risks to Risk Management

  • Coverage tracking by system, application, dependency

03

Asset Registry

  • IT assets, applications, systems, data stores, infrastructure as a dependency category

  • Asset attributes — owner, criticality, classification, location, lifecycle status

  • Linkage to Practice Instances and to VAPT findings via affected asset

04

Incident Management

  • Multiple intake channels — security incidents, breaches, regulatory inquiries, customer complaints, whistleblower reports

  • Triage and classification with severity and type; configurable response workflows by incident type

  • Investigation case file with timeline reconstruction

  • Linkage to affected Practice Instances, dependencies and assets

  • Root cause analysis with structured templates

  • Containment, eradication, recovery action tracking

  • Lessons learned and corrective action plans

  • Regulatory notification workflow where required (DPDP, RBI 6-hour, GDPR 72-hour)

  • Incident-to-risk linkage — incidents become risk signals and audit triggers

  • Incident metrics and trend analysis

What Changes For You

From four disconnected tools to one operational fabric.

The moment a critical vendor degrades, you see exactly which controls are affected.

Every VAPT finding ties to controls, risks and assets — no orphan PDFs.

Every incident traces to the specific Practice Instances and dependencies that failed.

Regulator notifications are workflow-managed, not “who sent the email last time?”.

Reassessments run on schedule, not when someone remembers.

Proof

One fabric. Every vendor, finding, incident.

One platform replaces vendor mgmt + PT tracking + incident response + ITSM ticketing for security.

Direct linkage to Practice Instances and risk register — no orphan findings.

Regulator notification workflows pre-built for DPDP, RBI, GDPR, CERT-In.

Legacy GRC toolsModern Compliance ToolsSiloed (SIEM + Vendor sheet)GRAC
Vendor-to-control linkageNoneNoneNoneNative via Dependency Web
VAPT findingsBolted onNarrow / bolted onPDF reportsLinked to controls, risks, assets
Incident responseSeparate toolNot built for itSeparate ITSMLinked to controls + dependencies + risk
Regulator notificationManualNot supportedManual emailsWorkflow-managed (DPDP, RBI, GDPR)
See it in your environment

Book a Demo.

We'll walk you through a vendor onboarding, a VAPT finding and a simulated incident — all tied to your real controls.