vCISO

Cynomi Adds TPRM Module to vCISO Platform for MSSPs, MSPs

Credit: Adobe Stock Images

Cynomi is bringing third-party risk management (TPRM) capabilities to the virtual CISO (vCISO) platform it offers to MSSPs and MSPs.

The addition of a TPRM module to the Cynomi vCISO Platform addresses a fast-growing part of the cybersecurity field that is being driven by the complex business and vendor environments of today.

The demand goes beyond supply chain security worries, according to David Primor, Cynomi’s co-founder and CEO.

"TPRM has become a top priority,” Primor told MSSP Alert. "Organizations today rely on a growing number of third-party vendors for everything from IT infrastructure to critical operations. This creates a broader attack surface and introduces operational, regulatory, and reputational risks that must be managed. Recent high-profile breaches, where attackers gained access through a vendor, have made it clear: security is only as strong as the weakest link in the vendor ecosystem.”

Additionally, there are compliance pressures to be addressed, the CEO added, emphasizing that the growing numbers of frameworks – think ISO 27001, SOC 2, HIPAA, and NIST – are putting more pressure for due diligence on third-party vendors.

AI is Key in an Evolving, Growing Market

That’s helping to fuel the expanding global market for TPRM, which is expected to rise from $7.42 billion in 2023 to $20.59 billion by 2030, according to Grand View Research analysts.

In its annual TPRM survey, global consultancy EY also outlined that the growing number of risks facing organizations calls for a greater focus on TPRM. However, there is an increasing misalignment between such risks and the traditional ways to run TPRM.

A key to solving that misalignment is AI, which the firm said "has tremendous potential to disrupt TPRM, enabling not just greater efficiencies but also a fundamentally different approach to identifying, monitoring and managing third-party risks.”

"The number of third-party relationships managed by a typical company has risen sharply in recent years, as has the complexity of these relationships,” Kapish Vanvaria, EY global risk consulting leader for EY, said in the report. "Meanwhile, an environment of lingering business uncertainty and cost pressures is creating an imperative for leaders to conduct third-party risk management in a more effective way. AI has proven to be a game changer in this arena.”

That includes not only enabling greater efficiencies but more fundamentally changing how organizations can identify, monitor, and manage third-party risks, according to the firm.

Automation and Standardization

With its new module, Cynomi is equipping MSSPs with automated and standardized TPRM capabilities instead of relying on manual processes, according to Primor. They can reuse vendor assessments that are already used across multiple customers, including pre-built templates that also save time. In addition, MSSPs and MSPs now have access to all vendor assessment data in a single, central space.

The result is that vendor assessment time has been reduced by up to 79% - from 7–16 hours per vendor to as little as 1.5 hours, according to the CEO.

"This is a game changer for MSPs and MSSPs,” he said. "This speed is not just about productivity. It’s about profitability and scale. Faster assessments mean providers can serve more clients and offer TPRM as a revenue-generating service.”

MSSPs Step Up

As reliance on third parties grows, vendor risk is becoming hard to manage. MSSP and MSP partners of the five-year-old Israeli startup can now go beyond running assessments, explain the results to customers and guide them on how to respond, Primor said.

"That kind of support goes beyond technical services,” he said. "It opens the doors for meaningful conversations about risk, compliance, and business impact. Over time, it positions the providers as trusted cybersecurity advisors, someone the clients turn to not just for tools, but for guidance. It is a natural fit, and honestly, a necessary one.”

The TPRM module is integrated with Cynomi’s vCISO platform and designed for MSSPs and MSPs. It includes capabilities such as multi-client functions, structured workflows, vendor systems, and user roles that can be reused.

In addition to Cynomi giving service providers a view of internal and external risks, the company also provides guided workflows and templates, risk heat-maps, and single-click reports, Primor said.

Demand for vCISO Services Grows

The addition of TPRM comes as demand for vCISO services grows, filling the role of a full cybersecurity organization for SMBs that lack the budget or in-house expertise to manage it themselves. In a report in July, Cynomi found that among 200 security leaders surveyed, high and moderate demand for vCISO services grew year-over-year to 96%.

Among MSSPs and MSPs, 67% said they are offering vCISO services now, a significant jump over the 21% of those surveyed in 2024. Of those that don’t, half said they will do it before the year is over and another 27% are looking add the service in 2026.

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds