Skip to main content

GRC for security leads

From supplier gap
to closed action.

Assess supplier security, record the risks in a register and work through the NIS2 requirements. Every gap gets an owner and a status.

The ChainSec risk register with critical risks, risk level, status and linked controlsRisk treatment with an initial risk level of 20 and a residual risk level of 8
Risk register and risk treatment in ChainSec. Sample data.

One flow, from assessment to follow-up.

What you find at a supplier does not end up in a separate document. It becomes a risk, is linked to a requirement and is followed up as an action.

  1. Assess the supplier
  2. Treat the risk
  3. Work through the requirements

Assess supplier security

Send security assessments for NIS2 and ISO 27001 at three levels of depth, depending on how critical the supplier is. Flag answers that need follow-up and request evidence directly in the answer.

Review of a supplier answer about multi-factor authentication, with a flag and a comment
Reviewing a supplier answer. Sample data.

Treat the risk

Record the risk in the risk register with likelihood and impact. Decide on treatment, write the action plan and see the residual risk level next to the initial one.

Risk treatment with a decision, an action plan and the residual risk level
Risk treatment for a supplier risk. Sample data.

Work through the requirements

The NIS2 requirements catalogue turns the requirements into controls. Each control has a status, an owner and a next review date, and the actions are followed up there.

The NIS2 requirements catalogue with controls per category, status, owner and next review
The NIS2 requirements catalogue. Sample data.

Add-on

Data protection, when you need it.

An asset register with CIA classification, information assets and Article 30 records. Added on top of Risk and requirements, so the assets link to the same risks.

Asset register with CIA values, risks and access per asset

Our Partners

Gibon
Cyber Instinct
Friends of Claudia
Hanger Security
Cybernoden

What GRC in ChainSec covers.

Included

  • Supplier security assessments at three levels of depthNIS2 and ISO 27001
  • Risk register with risk treatment
  • The NIS2 requirements catalogue
  • Actions linked to risks and requirements
  • Data protection as an add-onAsset register and Article 30 records

Not included

  • Your management system. No document control, no process maps.
  • Workflow builders and group structures like an enterprise suite.
  • Legal assessment. That stays with you.

Common questions about GRC in ChainSec

What is included in ChainSec's GRC offering?

Supplier security assessments at three levels of depth for NIS2 and ISO 27001, a risk register with risk treatment, the NIS2 requirements catalogue and actions linked to risks and requirements. Data protection with an asset register and Article 30 records is available as an add-on.

Do we need the supplier module to use Risk and requirements?

Yes. Every customer starts with the supplier module. Risk and requirements is added on top, and Data protection on top of Risk and requirements.

Is ChainSec a GRC system?

Yes, for the parts security work most often needs evidence for: supplier security, the risk register, the NIS2 requirements and the actions, in one system. ChainSec is not an enterprise GRC suite with workflow builders and group structures.

Does ChainSec replace our management system?

No. ChainSec is not an ISO system and does not replace your management system. We handle specific parts: suppliers, risks, requirements and actions.

What does it cost?

Pricing is set per customer based on the parts you need. Book a demo and we will go through your setup.

See the flow with your own suppliers.

30 minutes. We show assessment, risk and action based on the work you do today.