The thinking behind The Agency.
Insights and analysis on third-party risk management, vendor security, regulatory compliance, and the agentic shift reshaping how TPRM teams actually work.

How to implement NIS2 vendor monitoring in your organisation
NIS2 Article 21(2)(d) requires measures covering each direct supplier. Here is how to turn that obligation into a process that works at real supplier counts.
Read articleFrom the team.
Risk ManagementVendor due diligence: what to assess before you sign
Vendor due diligence is the assessment you run before you sign, while you still have leverage. What to assess, how deep to go, and how it connects to onboarding.
Read more
ComplianceHow to get Cyber Essentials certified
The route to Cyber Essentials certification step by step — scope, the automatic-fail items, the clocks that catch people out, and how to verify a supplier’s certificate.
Read more
ComplianceCyber Essentials vs Cyber Essentials Plus
Cyber Essentials and Cyber Essentials Plus assess exactly the same five controls. The difference is who checks, and how — plus what that means when a supplier sends you a certificate.
Read more
ComplianceHow much does Cyber Essentials cost?
The published IASME assessment fees for every organisation size, what Cyber Essentials Plus actually costs, what renewal costs, and the costs that never appear on the price list.
Read more
Small to Medium-Size Business: Top 8 Cyber Security Best Practices
Security advice for SMBs is usually enterprise advice, shortened. Eight practices that survive being implemented by someone with another job — in order of what they remove.
Read moreStop reading. Start running TPRM differently.
Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on a vendor of your choice inside 24 hours.