NORA
Vendor Assessment

Can You Rely on the Firms You Bring In?

NORA's Vendor Assessment is for the professional-services firms you work with — the consultancies, MSPs, contractors, and providers who have access to your systems, data, or operations. It isn't a scan of your software stack. It's a structured, defensible judgment about the outside organizations you let inside your business.

A Vendor Is a Firm — Not a Product.

In NORA, your software and SaaS are assets, assessed in the Risk model. A vendor is different: it's an outside organization — a consultancy, managed service provider, staffing partner, or specialist firm — that you engage and that touches your systems or data. NORA assesses those relationships: how much access the firm has, how well they protect what they can reach, and whether relying on them is a risk you can defend. This isn't third-party software risk management — it's about the people and firms behind the badge.

The Access Map

It's Not the Score. It's What They Can Reach.

A vendor's rating only means something relative to what it can touch. NORA's Asset–Vendor Network Map puts each firm at the center and shows the systems it can reach, colored by each system's own risk — then flags the combinations that matter: a middling firm with a path into a critical system. That's the exposure a score alone will hide, and one of the most common ways attackers actually get in. The map is built from the access your team records for each firm — NORA never scans your systems.

Asset–Vendor Network Map
Firm at the center · Surrounding nodes are the systems it can reach · Color = asset risk
CriticalHighMediumLowMonitorNo Risk
1 high-risk vendor–asset exposure — Contoso IT Services can reach Salesforce (Critical).
ContosoIT ServicesMEDIUMSalesforceCritical · 108OktaHigh · 82BoxLow · 22WorkdayLow · 30Microsoft 365Not assessed

A Medium-rated firm with access to a Critical system is a finding — not a footnote.

The Model

What NORA Assesses in a Firm

NORA evaluates each firm across eight risk domains — the questions that actually determine whether you can rely on an outside organization with access to your business.

1

Data Security & Privacy

How the firm protects the data you share with them.

2

Access Management

Who at the firm can reach your systems, and how that access is controlled and revoked.

3

Incident Response

Whether the firm can detect, contain, and tell you about a breach on their side.

4

Business Continuity

Whether the firm can keep operating — and keep you operating — through disruption.

5

Contractual & Compliance

Whether the right protections and obligations are actually written into your agreement.

6

Third-Party Sub-processors

The firms your firm relies on, and the risk they pass through to you.

7

Vulnerability Management

How the firm finds and fixes weaknesses in what they run.

8

Physical & Environmental Security

How the firm secures the physical places your data and work live.

The Scoring

Rated the Same Way as Your Own Systems.

Every domain is scored with the same model NORA uses for your assets. Each domain ends in a decision — accept, mitigate, transfer, or defer — with an owner and a rationale, so the assessment turns into action. And the same principle holds throughout: if the owner can't confirm a control is working, that uncertainty counts as exposure.

Likelihood × Impact × Exposure 1–125
MonitorLowMediumHighCritical
The Method

In Plain English, From the Person Who Owns the Relationship.

You don't send a questionnaire and wait for the vendor to return it. NORA guides the person inside your organization who owns the relationship through a short, plain-English conversation — usually a confident score in three or four questions per domain — tailored to the kind of firm being assessed. No security background required, and where the owner isn't sure, that uncertainty becomes a documented exposure instead of a blank.

Defensibility

Every Vendor Score, Defensible.

Like everywhere in NORA, every vendor score traces back to the owner's own answers — no black-box rating. Uncertainty is captured, not hidden. Each domain carries a decision and an owner. And the network map keeps every score in context, so "we assessed the vendor" becomes "we know exactly what this firm can reach, and what we decided about it."

See Where Your Vendors Can Reach.