Black Kite Third-Party Cyber Risk gives organizations visibility into cyber exposure across vendor portfolios and extended supply chains, from first-party posture through fifth-party exposure. It identifies suppliers, software products and geographies that may form single points of failure, and maps how risk can cascade through downstream relationships. Black Kite Monitor continuously tracks portfolios, while FocusTags connect vendors with breaches, active exploits, CVEs and dark-web exposures. Its Ransomware Susceptibility Index provides a predictive signal for vendor-specific ransomware susceptibility. Black Kite Assess uses AI to parse policies and compliance documents, map evidence to more than 25 global frameworks or a custom framework, and support vendor remediation through a shared workspace. The platform also uses open, auditable standards and Open FAIR-based analysis to express cyber exposure in dollar terms. Hybrid assessments, questionnaire libraries, framework mapping, evidence collection and workflow automation are included. Official integrations include ServiceNow, Aravo, OneTrust, Archer, Jira, Splunk, Power BI, Slack, Zapier, Microsoft Teams and others. Pricing is available on request.
Who it is for
It suits organizations managing third-party cyber risk across complex vendor or supply-chain networks. It is available on the web, with Standard and Enterprise plans that include unlimited users.
What is good
- Maps exposure through fifth-party relationships
- Connects threat signals directly to portfolio vendors
- Maps assessment evidence to global or custom frameworks
- Includes vendor remediation collaboration workspace
- Supports hybrid assessments and workflow automation
What to know first
- Pricing is available only on request
- Production customer data is stored in US-based cloud regions
Verdict
Black Kite combines supply-chain visibility, ongoing monitoring and vendor assessments with financial risk analysis. Its breadth of assessment and monitoring functions may suit teams that need to track downstream exposure and coordinate remediation.
Get started with Black Kite Third-Party Cyber Risk
- Visit the Black Kite website.
- Contact Black Kite to request pricing.
- Choose the Standard or Enterprise plan through a sales inquiry.
- Use the web platform and arrange onboarding, enablement, configuration, and environment tuning.
- Connect supported tools through the official integrations.
Questions about Black Kite Third-Party Cyber Risk
How much does Black Kite cost?
Pricing is available on request. Both listed plans have no displayed price.
What plans does Black Kite offer?
The listed plans are Standard and Enterprise. Both are described as full-featured and include onboarding, enablement, configuration, and environment tuning, with unlimited users.
Which platform does Black Kite support?
Black Kite is available on the web.
What integrations are available?
Official integrations include ServiceNow TPRM and ITSM, Aravo, LogicGate Risk Cloud, OneTrust, Archer, Splunk, Jira, Power BI, Slack, Zapier, Microsoft Teams, and an MCP Server.
Where is production customer data stored and processed?
Production customer data is stored and processed exclusively in US-based Google Cloud Platform regions.
What assessment capabilities does the platform include?
It supports hybrid assessments, questionnaire libraries, framework mapping, evidence collection, and workflow automation.
Black Kite Third-Party Cyber Risk plans and pricing
All plansCompared on third-party risk management software
- Assessment method
- hybrid
- Continuous monitoring
- Yes
- Questionnaire library
- Yes
- Framework mapping
- Yes
- Evidence collection
- Yes
- Workflow automation
- Yes




