---
title: 'TPRM Academy'
url: 'https://www.boardofcyber.io/en/resources/tprm-academy'
markdown: 'https://www.boardofcyber.io/en/resources/tprm-academy.md'
lang: en
date: '2025-11-14'
taxonomy:
  category:
    - tprm
---

Resources 

 TPRM Academy 

[TPRM Academy](https://www.boardofcyber.io/en/resources/tprm-academy)

 Testimonials 

[Testimonials](https://www.boardofcyber.io/en/resources/testimonials)

 Blog 

[Blog](https://www.boardofcyber.io/en/resources/blog)

# TPRM Academy 

 TPRM introduction 

 [ ![](https://www.boardofcyber.io/images/b/5/0/9/0/b5090ed76418f3de204a8b35e74ccb121b6edf69-cyber-security-34005551280.jpg) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-how-to-approach-a-third-party-risk-management-project)###  [TPRM - How to approach a Third-Party Risk Management project?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-how-to-approach-a-third-party-risk-management-project) 

 TPRM (Third-Party Risk Management) is part of a proactive approach to monitoring and controlling risks associated with supplier failure. In a context where companies and government agencies rely heavily on external partners (IT service providers, SaaS publishers, HR firms, etc.),… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/d/1/c/b/4/d1cb48303ed8aefb5c23a2b2ac3397bac59e6d12-tprm.jpeg) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/third-party-risk-management-master-the-risks-related-to-your-suppliers)###  [Third Party Risk Management: controlling risks associated with your suppliers](https://www.boardofcyber.io/en/resources/tprm-academy/articles/third-party-risk-management-master-the-risks-related-to-your-suppliers) 

 As a business, you rely on numerous suppliers and partners to carry out your activities. While outsourcing can be a source of agility and performance, it can also expose you to risks and lead to data loss or business interruption. And the consequences can be far-reaching, affecti… 

 ARTICLE 

 [  ](https://www.boardofcyber.io/en/resources/tprm-academy/articles?thematic=Introduction) 

 Compliance & regulation 

 [ ![](https://www.boardofcyber.io/images/6/5/c/c/2/65cc2aa96e3007d4723dcd54b69eef3bd26321da-boardofcyber-forumdescompetences.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience)###  [Board of Cyber joins the Forum des Compétences plenary session](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience) 

 Banks, insurers, and financial institutions are facing unprecedented cyber pressure. With the DORA regulation coming into force in January 2025, the NIS2 directive, and the growing wave of supply chain attacks, CISOs in the financial world are looking for benchmarks, methodologie… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/a/6/d/1/d/a6d1d4b08d3bf8be608f0806f77206a23fc47342-dora-conformite-reglementation.webp) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience)###  [DORA: Understanding European regulations on digital operational resilience](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience) 

 In June 2024, 77 entities, including 10 French banks, fell victim to a remote access Trojan called "DroidBot." Resold to cybercriminal networks, more than 776 infections were detected in Western Europe within banking organizations, cryptocurrency platforms, and financial companie… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/1/9/6/6/7/1966798cb17cb50fdc753e45869ba7aad74e78d7-pssi.webp) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/issp-understand-and-implement-an-effective-information-systems-security-policy)###  [ISSP: Understanding and implementing an effective Information System Security Policy](https://www.boardofcyber.io/en/resources/tprm-academy/articles/issp-understand-and-implement-an-effective-information-systems-security-policy) 

 In today's digital age, protecting information systems is a priority for all organizations, regardless of their size (SMEs, mid-cap companies, large corporations) and their sector of activity (banking, insurance, manufacturing, automotive, aviation, logistics, agri-food, etc.). T… 

 ARTICLE 

 [  ](https://www.boardofcyber.io/en/resources/tprm-academy/articles?thematic=Compliance%20%26%20regulation) 

 Methodology & best practices 

 [ ![](https://www.boardofcyber.io/images/7/3/4/3/e/7343eea37db398496a164ee1f93d9e9a0af040bc-10-questions-quun-rssi-doit-poser--ses-fournisseurs-saas-2.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers)###  [10 questions a CISO should ask their SaaS suppliers](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers) 

 Our dependence on service providers and SaaS applications increases every year: HR, payroll, project management, business processes... Third-party risks directly threaten business operations. The approach is now fairly well established for CISOs. For all new suppliers, it is nece… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/4/8/1/9/0/481905fc36144945e9288376c57c3f1ef015fd13-courvertureles10erreursquicompromettentvotrestrategietprm.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers)###  [10 Errors Undermining Your TPRM Strategy](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers) 

 In a digital landscape where corporate boundaries are dissolving into interconnected ecosystems, your organization's security no longer depends solely on your own ramparts, but on the strength of every link in your supply chain. Third-Party Risk Management (TPRM) has shifted from… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/3/d/d/c/9/3ddc9068541b2c5cf32ad03df665ccd34b180e9a-article7-methodes-d-evaluation-pour-evaluer-le-risque-cyber-de-vos-fournisseurs.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/7-methodes-devaluation-pour-evaluer-le-risque-cyber-de-vos-fournisseurs)###  [7 methods for assessing your suppliers' cyber risk](https://www.boardofcyber.io/en/resources/tprm-academy/articles/7-methodes-devaluation-pour-evaluer-le-risque-cyber-de-vos-fournisseurs) 

 Cyber Provider Risk: A Major Strategic Challenge The digital supply chain has become the weak link for many organizations. Recent attacks—such as those targeting Jaguar Land Rover, Marks & Spencer, or compromises via Managed Service Providers (MSPs)—have demonstrated that a vulne… 

 ARTICLE 

 [  ](https://www.boardofcyber.io/en/resources/tprm-academy/articles?thematic=Methodology) 

 TPRM trends 

 [ ![](https://www.boardofcyber.io/images/6/2/5/1/3/62513c978b2649bfadb028377fc898f6dd6175d9-observatoire-tprm-2025---site-web.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-observatory-2025-cyber-risk-management-for-suppliers)###  [TPRM Observatory 2025](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-observatory-2025-cyber-risk-management-for-suppliers) 

 Managing cyber risk associated with suppliers is now a strategic issue for all organisations. In this third edition of the Supplier Cyber Risk Observatory, Board of Cyber and CESIN give a voice to more than 170 CISOs, CIOs, CTOs and compliance directors based in France. Their fee… 

 E-BOOK 

 [ ![](https://www.boardofcyber.io/images/1/9/9/d/d/199ddb7651b5b163667ffc6c62a0e066cf8a084a-thumb-thierry-piton-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/les-dirigeants-de-pme-sont-peu-conscients-de-leur-niveau-reel-dexposition-cyber-thierry-piton-axa-france)###  [SME managers are largely unaware of their actual level of cyber exposure - Thierry PITON, AXA France](https://www.boardofcyber.io/en/resources/tprm-academy/articles/les-dirigeants-de-pme-sont-peu-conscients-de-leur-niveau-reel-dexposition-cyber-thierry-piton-axa-france) 

 Why has supplier risk become a major cybersecurity issue? Supplier risk is significant, but it does not fully describe the challenges currently facing businesses. At AXA France, we mainly support SMEs and mid-cap companies, which are less focused on managing their supply chain th… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/7/0/8/3/a/7083ac14e775d69cc5b6273132752e425c928873-thumb-cyril-roger-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/faire-de-la-cybersecurite-un-levier-de-dialogue-avec-les-fournisseurs-cyril-roger-groupe-credit-agricole)###  [Making cybersecurity a lever for dialogue with suppliers - Cyril Roger, Crédit Agricole Group](https://www.boardofcyber.io/en/resources/tprm-academy/articles/faire-de-la-cybersecurite-un-levier-de-dialogue-avec-les-fournisseurs-cyril-roger-groupe-credit-agricole) 

 How do you assess the cyber maturity of your supply chain? Crédit Agricole has several thousand suppliers who do not all have the same level of cyber maturity. Large companies have anticipated and are following regulatory developments such as DORA, which establishes principles bu… 

 ARTICLE 

 [  ](https://www.boardofcyber.io/en/resources/tprm-academy/articles?thematic=TPRM%20trends) 

 TPRM trends 

 [ ![](https://www.boardofcyber.io/images/6/2/5/1/3/62513c978b2649bfadb028377fc898f6dd6175d9-observatoire-tprm-2025---site-web.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-observatory-2025-cyber-risk-management-for-suppliers)###  [TPRM Observatory 2025](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-observatory-2025-cyber-risk-management-for-suppliers) 

 Managing cyber risk associated with suppliers is now a strategic issue for all organisations. In this third edition of the Supplier Cyber Risk Observatory, Board of Cyber and CESIN give a voice to more than 170 CISOs, CIOs, CTOs and compliance directors based in France. Their fee… 

 E-BOOK 

 [ ![](https://www.boardofcyber.io/images/1/9/9/d/d/199ddb7651b5b163667ffc6c62a0e066cf8a084a-thumb-thierry-piton-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/les-dirigeants-de-pme-sont-peu-conscients-de-leur-niveau-reel-dexposition-cyber-thierry-piton-axa-france)###  [SME managers are largely unaware of their actual level of cyber exposure - Thierry PITON, AXA France](https://www.boardofcyber.io/en/resources/tprm-academy/articles/les-dirigeants-de-pme-sont-peu-conscients-de-leur-niveau-reel-dexposition-cyber-thierry-piton-axa-france) 

 Why has supplier risk become a major cybersecurity issue? Supplier risk is significant, but it does not fully describe the challenges currently facing businesses. At AXA France, we mainly support SMEs and mid-cap companies, which are less focused on managing their supply chain th… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/7/0/8/3/a/7083ac14e775d69cc5b6273132752e425c928873-thumb-cyril-roger-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/faire-de-la-cybersecurite-un-levier-de-dialogue-avec-les-fournisseurs-cyril-roger-groupe-credit-agricole)###  [Making cybersecurity a lever for dialogue with suppliers - Cyril Roger, Crédit Agricole Group](https://www.boardofcyber.io/en/resources/tprm-academy/articles/faire-de-la-cybersecurite-un-levier-de-dialogue-avec-les-fournisseurs-cyril-roger-groupe-credit-agricole) 

 How do you assess the cyber maturity of your supply chain? Crédit Agricole has several thousand suppliers who do not all have the same level of cyber maturity. Large companies have anticipated and are following regulatory developments such as DORA, which establishes principles bu… 

 ARTICLE 

 [  ](https://www.boardofcyber.io/en/resources/tprm-academy/articles?thematic=TPRM%20trends) 

 [ View more  ](https://www.boardofcyber.io/en/resources/tprm-academy/articles)

---

## Navigation

- Parent: [Resources](https://www.boardofcyber.io/en/resources.md)
- Previous: [TPRM Observatory 2025](https://www.boardofcyber.io/en/resources/tprm-observatory-2025-cyber-risk-management-suppliers.md)
- Next: [Client experiences](https://www.boardofcyber.io/en/resources/testimonials.md)
- Children:
  - [TPRM Academy](https://www.boardofcyber.io/en/resources/tprm-academy/articles.md)
