The problem it solves
Most incidents come in through the supply chain. Contracts that are silent leave the organisation with no alerting deadlines, no audit rights and no control over where its data sits.
Who it is for
- Procurement and legal departments;
- Security and IT leads;
- Suppliers that want to answer questionnaires better.
Deliverables
- Assessment criteria and supplier questionnaire;
- Security, incident-alert and audit clauses;
- Clauses for processing of personal data;
- Follow-up and periodic review process.
Method
- 01
Inventory
Suppliers and data.
- 02
Classify
Criticality and risk.
- 03
Contract
Clauses and alerts.
- 04
Monitor
Reviews and evidence.
Regulatory basis
- Article 28 GDPR, on processors;
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
- Article 27 of Decree-Law 125/2025, on supply chain security, where applicable.
Expected results
- Suppliers assessed before they are hired;
- Incident alerts written into contracts;
- Clear responsibilities when something fails.