Risk Ledger Raises $32M Led by Axiom Equity to Take Its Supply Chain Security Network to the US
Summary
Risk Ledger, a London-based cybersecurity company, has secured a £24 million (\$32 million) Series B funding round, led by Axiom Equity with participation from existing investor Mercia Ventures. This capital will be used to expand its UK customer base, develop AI tools leveraging its network data, and facilitate entry into the United States, the world's largest third-party risk market. The company challenges the traditional questionnaire-based third-party risk management (TPRM) model, which it argues is ineffective given that third-party involvement in data breaches doubled from 15% to 30% in a single year, costing an average of \$4.91 million per incident. Risk Ledger's platform replaces individual questionnaires with a single, standardized, living security profile for each supplier, shared across its network of over 16,000 organizations. This network-centric approach aims to address supply chain security as a coordination problem, offering a collective defense mechanism.
Key takeaway
For CISOs and procurement leads evaluating third-party risk management solutions, recognize that traditional questionnaire-based approaches are structurally inadequate and costly. Your current methods likely provide stale data and fail to capture nth-party dependencies. Instead, consider adopting a network-based platform like Risk Ledger, which offers a single, continuously updated supplier security profile shared across your ecosystem. This approach can significantly reduce assessment overhead, improve data reliability, and provide collective defense against evolving supply chain threats.
Key insights
Supply chain security is a network coordination problem, best addressed by collective defense and shared, living supplier profiles.
Principles
- Replace point-in-time questionnaires with continuous, shared profiles.
- Shift defense from individual organizations to a collaborative network.
- Free supplier onboarding drives network growth and data richness.
Method
Suppliers complete a single, standardized assessment covering twelve security domains, maintaining it as a living profile visible to all connected clients.
In practice
- Implement a single, validated supplier security profile for all clients.
- Explore network-based platforms for shared threat intelligence.
- Utilize AI on aggregated, validated data for automated risk review.
Topics
- Supply Chain Security
- Third-Party Risk Management
- Cybersecurity Networks
- AI Security
- Venture Capital
- SaaS Business Model
Best for: CTO, Executive, Entrepreneur, AI Security Engineer, Director of AI/ML, Investor
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by HackerNoon.