Platform · Supply chain detection & response

Detection and response, extended into the supply chain.

EDR watches the endpoint. XDR widens the lens to the network. SCDR pushes it past the perimeter — into the vendors, sub-processors and fourth-party hops where most modern breaches actually start.

What is supply chain detection and response?

Supply chain detection and response (SCDR) applies the logic of detection and response — continuous monitoring, alerting, triage, containment — to risk originating in an organisation's suppliers rather than inside its own perimeter.

The lineage is familiar. EDR watches endpoints. XDR correlates across endpoints, network, identity and cloud. Both stop at the boundary of what you own. SCDR extends the same posture outward, on the observation that a significant share of breaches now arrive through a third party — a compromised supplier, a sub-processor's incident, a fourth-party dependency nobody had mapped.

In practice it means treating vendor risk as an operational signal rather than a periodic assessment: continuous monitoring of supplier posture, breach and dark-web correlation, detection of material change while it still matters, and a defined response path when something fires — who is contacted, what is asked, what is escalated, and what gets reported. The difference from conventional TPRM is timing. An assessment tells you what a vendor looked like when you asked; SCDR is built around finding out that something changed before it becomes your incident.

The numbers your team already knows.

Endpoint and network detection close two of the three doors. The third — your supply chain — is where ransomware operators and nation-state actors increasingly live, because nobody else is looking.

60%+
Of major breaches now involve a third or fourth party
Industry estimate
11 days
Average time to act on a vendor-side breach signal
Industry average
24/7
How often The Agency watches the supply chain on your behalf

REX detects. TARA tiers. NOVA closes the loop.

SCDR is a three-stage workflow: detect the supply-chain event, decide what it means, and act on it without waiting for someone to draft an email. The Agency runs all three.

REX avatar
REX
Risk & Breach Intelligence

The detection layer for everything outside your perimeter. REX continuously watches your vendors and their vendors — attack surface, breach signal, dark-web mentions, fourth-party exposure — and ranks every event by impact before it lands in your queue.

What you get
  • Continuous outside-in scanning across 5M+ companies
  • BreachWatch + dark-web correlation, ranked by vendor impact
  • Fourth-party discovery — the chain hop you didn't know existed
TARA avatar
TARA
Tiering & Remediation

Decision logic on top of the detection feed. TARA decides what each event means for that vendor's tier and your regulatory posture, then opens an SLA-bound remediation track in your ITSM — so a critical-tier breach doesn't queue behind a low-tier banner grab.

What you get
  • Smart tiering weighted by inherent risk
  • SLA-driven remediation in ServiceNow, Jira, Asana
  • Regulatory-aware response — DORA, NIS2, ISO 27001 framings included
NOVA avatar
NOVA
Vendor Relationship Manager

Vendor-side action, on the channel they actually use. When the issue belongs to a vendor, NOVA reaches out across email, WhatsApp or in-app chat — subject to your autonomy mode — and tracks the response back into the same workflow.

What you get
  • Three-channel vendor outreach when the issue is theirs
  • Customer can join any conversation NOVA opens
  • Action loop closes inside your ITSM, evidence linked back

From alerts firehose to closed loop.

SCDR turns the supply chain from the part of TPRM that gets reviewed quarterly into the part that's monitored continuously and actioned automatically.

Detection happens twenty-four-seven

REX watches every vendor in the portfolio (and their vendors) without a duty rota. Material events surface in real time, not at the next review window.

Triage stops being a meeting

TARA decides what the event means against tier and regulatory framework, and opens the right ticket in the right place automatically.

Vendor outreach happens

NOVA tells the vendor on the channel they read. Your team stops drafting incident emails and starts reviewing the response.

Audit trail composes itself

Every detection-to-resolution loop links back to the originating signal. When the regulator or board asks "how did we respond to X?" the answer is already structured.

We had a leaked-credential dump matched to a Critical-tier vendor inside two hours of REX seeing it — and NOVA had the vendor's CISO on a call before our team had finished triaging it.

AH
Group CISO
Multinational logistics

What teams ask about SCDR.

Where it sits relative to EDR and XDR, and what responding to a vendor event involves.

How does SCDR differ from EDR and XDR?
By where the telemetry comes from. EDR and XDR run on assets you own and control, with agents and logs you can deploy. SCDR covers organisations you do not control, so the signal is necessarily outside-in: externally observable posture, breach and credential exposure, corporate and regulatory events, and change over time. It is a complementary layer rather than a replacement — XDR will not tell you your payroll provider was breached, and SCDR will not tell you a laptop is running ransomware.
What counts as a supply chain detection?
A material change in a supplier's risk position: a confirmed breach or public incident, credentials for their domain appearing in a new dump, a sharp deterioration in external posture, newly exposed infrastructure or a critical unpatched internet-facing vulnerability, a fourth-party dependency changing, or a corporate signal such as insolvency proceedings, sanctions or enforcement action. The distinction that matters is material change versus noise: a single-point anomaly is usually not a detection, while a sustained move is.
What does response look like when you do not control the vendor?
It is a sequence of decisions rather than a technical containment. Confirm the finding and its attribution; establish whether the affected asset or service is one you actually depend on; determine your own exposure, including whether your data or credentials are implicated; contact the vendor with something specific rather than a general enquiry; and decide what the finding obliges you to do — remediation with a deadline, an incident report to a regulator where a statutory window applies, or invoking exit provisions. The value is in reaching those decisions in hours.
Is SCDR a recognised category?
It is an emerging term rather than an established analyst category, and worth treating as descriptive. What it describes is a real convergence — TPRM platforms adding continuous monitoring and alerting, and security operations teams taking on supplier signal that used to sit with risk or procurement. If the term is unfamiliar to your stakeholders, the substance usually translates as "continuous third-party monitoring wired into the way we run detection and response".

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.