Live Webinar:

Third Party Risk Under NIS2 and the EU AI Act

What Irish organisations are being asked to prove about their suppliers, and how to prove it


Tuesday 15th September | 11AM

 
 

Supplier risk you can see, evidence and act on

A questionnaire arrives from a customer. Sixty questions, half of them about suppliers, and a return date two weeks away. Somebody has to find out who the suppliers are, what risk they carry, and whether anything has changed since the last review. That scenario is now routine across Irish organisations and public bodies.

Most Irish organisations depend on suppliers they have very little visibility of. NIS2 and the EU AI Act have both landed on that fact, and each one asks a version of the same question: who are the suppliers, what risk do they carry, and how does anyone know? NIS2 puts supplier oversight into Article 21 and makes the board answerable for it. Neither is fully in force in Ireland yet, and that has made little difference in practice. The legislation is still working its way through the Oireachtas while the questions arrive through customers, insurers and procurement teams, usually with a deadline attached. The organisations feeling it most are rarely the ones with the biggest security budgets.

Most organisations still answer with a spreadsheet and an annual questionnaire, which describes a supplier as it was six months ago rather than as it is this morning. This session looks at what a better answer involves. SecurityScorecard and Renaissance walk through where the obligations actually sit, what boards and insurers are asking to see, and how continuous monitoring gives a live picture of supplier risk instead of a snapshot. The focus is practical throughout, aimed at anyone who has to answer these questions.

Key Takeaways:

In this session, you will learn:

  • What NIS2 Article 21 and the EU AI Act actually require on suppliers, in plain terms.
  • Which obligations apply in Ireland today and which are still ahead.
  • The supplier questions now appearing in customer questionnaires and insurance renewals.
  • Why an annual supplier review no longer holds up, and what replaces it.
  • How to spot which suppliers are at real risk today rather than which ones scored well six months ago.
  • How to explain supplier risk to a board in terms it will act on.
  • What partners can do when customers forward these questions to them.

Agenda:

11:00 – Business Introduction, Norman Newell, Renaissance

11:05 – Third Party Risk Under NIS2 and the EU AI Act, Nadji Raib, SecurityScorecard

11:45 – Q&A

12:00 – Close

Register Now

Eliminate blind spots across the supply chain

Speakers

Norman Newell

Chief Commercial Officer, 

Renaissance

Nadji Raib

Senior Area Director EMEA North,

SecurityScorecard

Proactively manage and reduce third-party risk with threat-informed TPRM

Resources

 

Supplier risk has become one of the harder questions Irish organisations are asked to answer, and the teams handling it well have stopped relying on an annual review. SecurityScorecard rates the security of organisations from the outside in, so supplier risk can be seen as it stands today rather than as it looked at the last assessment. The resources below explain how that works and what a modern programme looks like.

SecurityScorecard is the global leader in threat-informed third-party risk management (TPRM), securing the world’s supply chains. The company delivers a modern, threat-informed approach to TPRM that enables organisations to drive out risk at the source. Through continuous visibility, AI-accelerated intelligence, and predictive insights, the platform transforms third-party risk into a competitive advantage, empowering organisations to proactively reduce risk before incidents occur and respond with confidence when they do, delivering measurable supply chain resilience. Trusted by over 3,300 organisations, including 70% of the Fortune 100, and recognised as a trusted resource by the U.S. Cybersecurity & Infrastructure Security Agency (CISA). Backed by Evolution Equity Partners, Silver Lake Partners, Sequoia Capital, Google Ventures, NGP Capital, Intel Capital, and Riverwood Capital, SecurityScorecard delivers end-to-end supply chain cybersecurity that safeguards business continuity. Protect the supply chain behind your business. Learn more.

We work with our partners to deliver solutions and services to make your clients’ and customers’ IT environments more secure and compliant and future proof these solutions by tailoring these to suit their needs and requirements. Renaissance and our suite of security vendors and partners are ideally placed to work with organisations to help analyse current security systems, design a way to improve them, and deliver the improvements over time, starting with the most critical systems and vulnerabilities. Learn more.

Renaissance Contingency Services Ltd 
Unit 8, Leopardstown Business Centre, Ballyogan Road, Dublin 18, Ireland Eircode D18wd62
Tel: +353 (1) 2809410      Email: info@renaissance.ie