Orpheus strengthens third-party risk management with continuous outside-in monitoring of each supplier's external attack surface, informed by threat intelligence and predictive Cyber Risk Ratings. See where supplier exposure is changing and why, without relying on supplier input
Third-party risk changes faster than periodic questionnaires can capture. Orpheus gives teams responsible for procurement and cyber risk a continuous outside-in view of supplier exposure. Live threat intelligence and external attack-surface evidence inform predictive cyber risk scoring, showing where risk is changing and which suppliers need attention. The outside-in monitoring layer does not depend on supplier input, allowing organisations to assess suppliers quickly and continue monitoring them throughout the relationship.
Users can compare risk across a supplier portfolio and open an individual organisation to understand the threats and vulnerabilities influencing its score. Changes can be tracked over time, while clear risk summaries can be shared with suppliers to support remediation. This moves third-party risk management beyond point-in-time assessment and focuses effort where the evidence shows it matters.
Orpheus Cyber Risk Ratings have been independently validated by Gallagher Re using data from more than 47,000 organisations and 1,000+ cyber claims. Organisations in the highest-risk group were 3.2x more likely to suffer a ransomware incident, while high-risk scores were associated with a 2.3x greater likelihood of other cyber attacks. Orpheus is an FCA Accredited Supplier and a Bank of England CBEST Approved provider of cyber threat intelligence. Its TPRM capability can support supplier onboarding and ongoing oversight, with evidence that strengthens governance and regulatory programmes including DORA and NIS2
Highlights
Continuous third-party risk monitoring: Monitor supplier cyber risk without vendor input, with updated intelligence as exposure changes
Threat-led cyber risk scoring: Cyber Risk Ratings use threat activity and external attack-surface evidence to show where attention is most needed
Portfolio visibility with evidence for action: Compare supplier risk across the portfolio and open individual scores to see the evidence behind them. Risk summaries can also be shared with suppliers to support remediation
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing has one pricing dimension, offered at no cost. You get access to the cloud-based third-party risk management platform under a single Free usage dimension. There are no tiers, instance sizes, or usage-based add-ons to choose between. The platform continuously monitors your suppliers' external cyber risk profiles and delivers intelligence-led risk scores. Because pricing is a single free option, there is no scaling logic or quantity selection to configure at purchase.
Top-of-mind questions for buyers
What does the Free dimension include when monitoring my suppliers' cyber risk?
You get access to the cloud-based platform that monitors suppliers' external risk profiles. It delivers threat-led cyber risk scores and real-time alerts when a vendor's risk changes. The platform does not rely on input from your vendors, so it works without their participation.
Does my cost change as I add more organisations to monitor?
No. This listing has one Free dimension with no usage-based charges. The dashboard lets you add multiple organisations to monitor their cyber risk ratings. Adding more entities does not trigger tiers, quantity selection, or added software fees at this listing.
How does the platform score supplier risk, and are extra costs involved?
The platform analyses an organisation's domain and connected data points, then combines a vulnerability score with a threat score. This produces a cyber risk rating for each monitored entity. Under the Free dimension, there are no separate charges for scoring, alerts, or reports.
orpheus-cyber.com+2
Helpful?
Vendor refund policy
Please refer to Orpheus Cyber Terms and Conditions | EULA
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
SecurityScorecard is the global leader in third-party cyber risk management, with more than 12 million companies continuously rated. Our patented security ratings technology is used by organizations for enterprise risk management, third-party cyber risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight.
Thousands of customers rely on SecurityScorecard to help them move from risk identification to risk resolution, operationalize their cyber risk management program, and improve the overall cyber hygiene of their organizations.
PROD14208 Bynet ServiceNow IRM is a leading risk management & compliance solution for managing business, operational, IT and security risk.
License is by IRM Operator - any user who is part of any IRM application workflow or process in any way.
Upgrade GRC into a profit center. Save time, improve accuracy, and reduce risk with better compliance, faster security reviews, and a quantitative approach to risk management.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.