The 3-2-1 Supplier Risk Action Model

This is a simple, practical framework to help law firms focus effort after completing a supplier risk assessment. The Model supports cyber and operational risk management only. It does not provide legal or contractual advice.

The 3-2-1 Supplier Risk Action Model

What's included in the Model?

This document introduces our 3-2-1 Supplier Risk Action Model, a practical framework designed to help law firms manage cyber and operational vendor risks.

It provides a structured way to turn risk assessments into immediate action by identifying:

  • 3 highest-risk suppliers to focus on
  • 2 priority internal improvements within your control
  • 1 quick win to complete immediately

Speak to us today

Net-Defence is committed to protecting and respecting your privacy at all times, and we’ll only use the details you give us to provide information on the products and services you request from us. By submitting this form, you confirm that you have read, understand and agree to our Privacy Policy.

Latest in Resources

Defence, protection, security. We've got you covered.

Whether you need to enhance your approach to cyber threats, overhaul your IT infrastructure or improve your communications, we’re here to help and advise. Talk to a specialist today and take the next step towards being a stronger, more resilient business.

Speak to us today

Need support? Take Control.

The button below is to be used when instructed by our technical support team. This will allow a file to be downloaded to your device for them to take control and help solve the issues you are having.

ND Take Control

exe · 7.70MB

Please note: only to be used when instructed by a member of our support team. Windows devices only.