Safeguard
Tag

tprm

Safeguard articles tagged "tprm" — guides, analysis, and best practices for software supply chain and application security.

30 articles

Regulatory Compliance

NAIC Insurance Data Security Model Law compliance for sof...

What NAIC model law software vendor compliance means for insurtech and SaaS vendors, and how insurer TPRM programs are enforcing it in contracts today.

Aug 10, 20268 min read
Compliance

Medtronic and AdaptHealth: The Third Party Was the Vulnerability

3.8 million people notified by Medtronic. PII, PHI and insurance billing credentials exfiltrated at AdaptHealth after social engineering against a third-party contractor. Neither breach needed a software vulnerability — both needed a trusted outsider with a session.

Jul 28, 20266 min read
Buyer's Guides

Best third-party and vendor risk management (TPRM) tools

A practical buyer's guide comparing six named third-party risk management tools — strengths, limitations, and where software supply chain visibility fills the gaps they miss.

Jul 15, 20268 min read
Compliance

DORA Register of Information: Lessons From the First Submission

The 30 April 2025 ESA deadline forced banks and insurers to inventory every ICT contract against 105 prescribed data points — and exposed structural gaps in third-party data.

May 10, 20268 min read
Best Practices

Vendor Questionnaire Fatigue And How To End It

Security questionnaires have ballooned into 400-row spreadsheets that nobody reads carefully. Here is how to replace the ritual with evidence ingestion that actually changes vendor risk decisions.

Apr 12, 20267 min read
Best Practices

Continuous Vendor Monitoring vs Annual Review

Annual vendor reviews discover problems eleven months too late. Continuous monitoring closes the gap, but only if your TPRM tooling can ingest and normalize signals at vendor scale.

Apr 8, 20267 min read
Best Practices

Vendor Incident Coordination In The 72-Hour Window

Most vendor incidents go badly because the first 72 hours are spent figuring out who to call. A pre-built coordination playbook turns chaos into a rehearsed response.

Apr 4, 20267 min read
Incident Analysis

Okta 2023 Customer Support Breach: Implications for Identity Supply Chain

The Okta customer support breach of October 2023 exposed HAR files containing session tokens for major customers. The structural lessons run deeper than the incident.

Apr 3, 20265 min read
Best Practices

TPRM Vendor Tiering By Blast Radius Not Spend

Most TPRM programs tier vendors by spend. That misses the vendors who are cheap but catastrophic when they fail. Tiering by blast radius is the fix.

Mar 30, 20267 min read
Best Practices

Flowing Down CMMC And CRA Clauses To Vendors

CMMC 2.0 and the EU Cyber Resilience Act both require obligations to flow down through your supply chain. Here is how to write the clauses and verify the compliance.

Mar 25, 20267 min read
Product

Introducing Safeguard TPRM: Evidence-Based Third-Party Risk Management

Safeguard's new TPRM module replaces vendor questionnaires with SBOM-driven, continuous third-party risk assessment.

Mar 22, 20267 min read
Best Practices

Evaluating Vendor Attestations: SOC 2 / FedRAMP

A SOC 2 report does not mean the vendor is secure. Here is how to read attestations carefully, what FedRAMP actually proves, and how to ingest both at scale.

Mar 20, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

tprm — Safeguard Blog