In conjunction with

Third-Party Risk Management and Attack Surface Monitoring for the Supply Chain

Ceeyu is a Belgian B2B SaaS vendor focused on third-party and supply chain cyber risk, aimed at organizations that must vet critical suppliers under regimes such as NIS2, DORA, and ISO 27001. The company was founded in 2020 by CEO Jimmy Pommerenke, a computer science graduate and former security engineer whose work at financial institutions and EY exposed how manual and expensive supplier assessment had become. It is headquartered in Antwerp, Belgium, and explicitly courts smaller teams priced out of enterprise risk suites.

The platform pairs two disciplines that are usually bought separately. A questionnaire engine builds assessments from standards-based templates drawing on CIS, NIS, NIST, and ISO frameworks, then routes them to suppliers through a dedicated portal that captures answers, supporting evidence, and a Q&A chat thread, with scores calculated automatically once completeness rules are satisfied. Running alongside it, passive and active external scans map servers, domains, IP addresses, websites, cloud storage, exposed data, and lookalike phishing sites from an attacker's vantage point.

Cross-referencing subjective questionnaire responses against objective scan findings is the central design choice, letting an assessor test what a supplier claims about its posture against what its perimeter actually exposes. Results land in a dashboard where findings are triaged as accepted, false positive, or remediated with permanent history, raw scan data is exportable to other tools, and ratings can be shared back with vendors for joint remediation. Managed services covering day-to-day TPRM administration are offered for teams without in-house capacity.

Market Segments:

Third-Party Risk ManagementThreat Exposure Management

Categories:

OP - Attack Surface Management