Black Kite Third-Party Cyber Risk is a web platform for monitoring and assessing cyber exposure across vendor portfolios and extended supply chains. It provides visibility from first-party posture through fifth-party exposure, identifies concentration risks and maps how downstream impact can move through suppliers. Black Kite Monitor continuously tracks vendor portfolios, while FocusTags connect breaches, active exploits, CVEs and dark-web exposures to vendors. Its Ransomware Susceptibility Index is a vendor-specific predictive signal. Black Kite Assess parses policies and compliance documents and maps evidence to more than 25 global frameworks or a custom framework; a shared workspace supports gap sharing, remediation requests and follow-up with vendors. Findings are grounded in open, auditable standards, and Open FAIR-based analysis expresses cyber posture as dollar-denominated exposure. Integrations include ServiceNow TPRM and ITSM, Aravo, LogicGate Risk Cloud, OneTrust, Archer, Splunk, Jira, Power BI, Slack, Zapier, Microsoft Teams and an MCP Server. Pricing is on request. Production customer data is stored and processed exclusively in US-based Google Cloud Platform regions.
Who it is for
Black Kite suits organizations that need to monitor vendor cyber posture and trace risk through extended supply chains. Its assessment and vendor collaboration tools may also suit teams mapping evidence to compliance frameworks and following up on remediation.
What is good
- Tracks supply-chain exposure through fifth parties.
- FocusTags link threat exposures to portfolio vendors.
- Assess maps evidence to over 25 frameworks or a custom one.
- Open FAIR-based analysis quantifies exposure in dollars.
- Official integrations include ServiceNow, OneTrust and Splunk.
What to know first
- Pricing is available on request.
- Production customer data is restricted to US-based Google Cloud regions.
Verdict
Black Kite combines continuous portfolio monitoring with document-based assessments, framework mapping and vendor follow-up. Its US-only production data residency is a key consideration for organizations with location requirements.
Black Kite Third-Party Cyber Risk plans and pricing
All plansCompared on third-party risk management software
- Assessment method
- hybrid
- Continuous monitoring
- Yes
- Questionnaire library
- Yes
- Framework mapping
- Yes
- Evidence collection
- Yes
- Workflow automation
- Yes


