---
title: 'TPRM Academy'
url: 'https://www.boardofcyber.io/en/resources/tprm-academy/articles'
markdown: 'https://www.boardofcyber.io/en/resources/tprm-academy/articles.md'
lang: en
date: '2025-11-05'
---

# TPRM Academy

TPRM Academy

 TPRM Academy 

[TPRM Academy](https://www.boardofcyber.io/en/resources/tprm-academy)

 Testimonials 

[Testimonials](https://www.boardofcyber.io/en/resources/testimonials)

 Blog 

[Blog](https://www.boardofcyber.io/en/resources/blog)

  [  Back to TPRM Academy home ](https://www.boardofcyber.io/en/resources/tprm-academy) 

 [ ![](https://www.boardofcyber.io/images/7/1/f/7/4/71f746f563434a6d5e4a25148367d08b2f772253-thumb-iacono-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/en-cyberdefense-personne-ne-gagne-seul-maria-iacono-les-assises-de-la-cybersecurite)###  [In cyber defence, no one wins alone - Maria IACONO, Les Assises de la cybersécurité](https://www.boardofcyber.io/en/resources/tprm-academy/articles/en-cyberdefense-personne-ne-gagne-seul-maria-iacono-les-assises-de-la-cybersecurite) 

 Les Assises offers a unique vantage point on the cybersecurity ecosystem. Which emerging signals do you consider most important today? We have seen several major issues emerge in succession: growing awareness of our technological dependence on the United States, and the arrival o… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/b/6/8/a/2/b68a23449b6dcb7bfbafca80c703df32c61d4b83-couverturetprmetiacommentlautomatisationtransformeenfinlagestiondurisquefournisseur.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-et-ia-comment-lautomatisation-transforme-enfin-la-gestion-du-risque-fournisseur)###  [TPRM and AI: How automation is finally transforming supplier risk management?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-et-ia-comment-lautomatisation-transforme-enfin-la-gestion-du-risque-fournisseur) 

 Time-consuming questionnaires, overwhelmed vendors, limited resources: discover how AI and Board of Cyber's new solutions are transforming Third Party Risk Management. TPRM (Third Party Risk Management) has become a constant source of friction for security teams. Between sending … 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/2/f/0/c/6/2f0c678b1a6ddd03a6750c1e834dddca07f755ee-tprm.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/the-8-regulations-you-need-to-know-to-succeed-in-your-TPRM-approach)###  [The 8 regulations you need to know to succeed in your TPRM approach](https://www.boardofcyber.io/en/resources/tprm-academy/articles/the-8-regulations-you-need-to-know-to-succeed-in-your-TPRM-approach) 

 According to the 2025 TPRM Observatory conducted by CESIN and Board of Cyber, 82% of respondents now consider supplier-related cyber risk to be "important" or "very important"—a clear signal that the digital supply chain remains a major point of vulnerability. Another revealing i… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/9/0/e/d/0/90ed06ebab9939c15178634eb7ebbf6033397b2b-ia-act.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/ia-act-a-quoi-sattendre-et-comment-adapter-sa-strategie-cyber)###  [AI ACT – What to expect and how to adapt your cyber strategy?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/ia-act-a-quoi-sattendre-et-comment-adapter-sa-strategie-cyber) 

 AI Act and Supplier Risk Management: A New Challenge for TPRM Programmes Artificial intelligence is profoundly transforming supply chains and business processes across companies and public-sector organisations. Its use is becoming increasingly widespread and raises questions abou… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/4/3/a/a/5/43aa579eb1c3572aa2c0d9c7bb2dd79cd79c0862-clauses-contractuelles.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/6-clauses-contractuelles-de-securite-pour-limiter-les-risques-cyber-fournisseur)###  [6 Contractual Security Clauses to Limit Supplier Cyber Risks](https://www.boardofcyber.io/en/resources/tprm-academy/articles/6-clauses-contractuelles-de-securite-pour-limiter-les-risques-cyber-fournisseur) 

 Companies and public-sector organisations are now fully dependent on their supply chain for almost all their activities. This is because it is impossible to operate efficiently without relying on tools and experts to run every department within an organisation: IT, HR, logistics,… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/3/d/d/c/9/3ddc9068541b2c5cf32ad03df665ccd34b180e9a-article7-methodes-d-evaluation-pour-evaluer-le-risque-cyber-de-vos-fournisseurs.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/7-methodes-devaluation-pour-evaluer-le-risque-cyber-de-vos-fournisseurs)###  [7 methods for assessing your suppliers' cyber risk](https://www.boardofcyber.io/en/resources/tprm-academy/articles/7-methodes-devaluation-pour-evaluer-le-risque-cyber-de-vos-fournisseurs) 

 Cyber Provider Risk: A Major Strategic Challenge The digital supply chain has become the weak link for many organizations. Recent attacks—such as those targeting Jaguar Land Rover, Marks & Spencer, or compromises via Managed Service Providers (MSPs)—have demonstrated that a vulne… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/6/2/5/1/3/62513c978b2649bfadb028377fc898f6dd6175d9-observatoire-tprm-2025---site-web.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-observatory-2025-cyber-risk-management-for-suppliers)###  [TPRM Observatory 2025](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-observatory-2025-cyber-risk-management-for-suppliers) 

 Managing cyber risk associated with suppliers is now a strategic issue for all organisations. In this third edition of the Supplier Cyber Risk Observatory, Board of Cyber and CESIN give a voice to more than 170 CISOs, CIOs, CTOs and compliance directors based in France. Their fee… 

 E-BOOK 

 [ ![](https://www.boardofcyber.io/images/4/a/f/7/f/4af7f3de10d6623c9864e40ad898daf29163bd5a-observatoire-2024.webp) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/observatory-2024-cyber-risk-related-to-suppliers)###  [2024 Observatory: Suppliers cyber risk](https://www.boardofcyber.io/en/resources/tprm-academy/articles/observatory-2024-cyber-risk-related-to-suppliers) 

 CESIN and Board of Cyber unveil the 2024 Observatory on Cyber Risks Linked to Suppliers This second edition surveyed more than 100 cybersecurity leaders, members of CESIN, from organizations of all sizes and sectors, about how they manage supplier-related cyber risk — methods, to… 

 E-BOOK 

 [ ![](https://www.boardofcyber.io/images/e/7/8/6/1/e7861457c5fac13a69323d38807e2f5d55245658-due-diligence-fournisseur.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/supplier-due-diligence-key-steps-to-secure-your-partnerships)###  [Supplier Due Diligence: Key steps to secure your partnerships](https://www.boardofcyber.io/en/resources/tprm-academy/articles/supplier-due-diligence-key-steps-to-secure-your-partnerships) 

 The due diligence process, also known as reasonable diligence, is an essential in-depth investigation that companies must perform before establishing business relationships with third parties, particularly suppliers. This process often includes a supplier due diligence to assess … 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/a/6/d/1/d/a6d1d4b08d3bf8be608f0806f77206a23fc47342-dora-conformite-reglementation.webp) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience)###  [DORA: Understanding European regulations on digital operational resilience](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience) 

 In June 2024, 77 entities, including 10 French banks, fell victim to a remote access Trojan called "DroidBot." Resold to cybercriminal networks, more than 776 infections were detected in Western Europe within banking organizations, cryptocurrency platforms, and financial companie… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/1/9/6/6/7/1966798cb17cb50fdc753e45869ba7aad74e78d7-pssi.webp) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/issp-understand-and-implement-an-effective-information-systems-security-policy)###  [ISSP: Understanding and implementing an effective Information System Security Policy](https://www.boardofcyber.io/en/resources/tprm-academy/articles/issp-understand-and-implement-an-effective-information-systems-security-policy) 

 In today's digital age, protecting information systems is a priority for all organizations, regardless of their size (SMEs, mid-cap companies, large corporations) and their sector of activity (banking, insurance, manufacturing, automotive, aviation, logistics, agri-food, etc.). T… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/1/c/9/8/3/1c983f1afc5e91856cc69c96ff5a934d8cd67f38-thumb-iso27001.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/iso-27001-understanding-the-information-systems-security-standard)###  [ISO 27001: everything you need to know about the information security standard](https://www.boardofcyber.io/en/resources/tprm-academy/articles/iso-27001-understanding-the-information-systems-security-standard) 

 Facing the digitalization of their activities, companies must now deal with a growing risk of cyber threats. Financial losses, theft of sensitive data, damage to brand image… the impacts of an incident are numerous. In 2024, the French National Cybersecurity Agency (ANSSI) observ… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/a/7/c/b/7/a7cb7171f9d429ce2fbf6821975beb07346e4c6b-easm.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/external-attack-surface-management-assess-prioritize-remediate)###  [External Attack Surface Management: assess, prioritise, remediate](https://www.boardofcyber.io/en/resources/tprm-academy/articles/external-attack-surface-management-assess-prioritize-remediate) 

 External Attack Surface Management (EASM): assess, prioritize, remediate External Attack Surface Management (EASM) encompasses the practices, procedures, and tools aimed at mapping, monitoring, and securing all of a company’s digital assets exposed on the Internet. It provides or… 

 ARTICLE 

###  [Cyber security ratings and cyber insurance: what insurers really assess](https://www.boardofcyber.io/en/resources/tprm-academy/articles/cyber-insurance-understand-evaluate-and-choose-the-best-cyber-insurance-for-your-business) 

 When a company applies for or renews cyber insurance, the insurer does not simply check whether it has antivirus software or a security policy in place. It seeks to answer a more practical question: what is the organisation's actual level of exposure, and how well can it limit th… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/6/1/d/7/4/61d74443912a774c3c76c9e32866407816346b68-hds.jpg) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/hds-all-you-need-to-know-about-health-data-hosting-and-certification)###  [HDS: Everything you need to know about healthcare data hosting and certification](https://www.boardofcyber.io/en/resources/tprm-academy/articles/hds-all-you-need-to-know-about-health-data-hosting-and-certification) 

 In the healthcare sector, the security and confidentiality of personal data are essential issues. With this in mind, the Healthcare Data Hosting (HDS) certification was introduced to meet these requirements. HDS certification aims to strengthen the protection of health data and e… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/4/8/1/9/0/481905fc36144945e9288376c57c3f1ef015fd13-courvertureles10erreursquicompromettentvotrestrategietprm.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers)###  [10 Errors Undermining Your TPRM Strategy](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers) 

 In a digital landscape where corporate boundaries are dissolving into interconnected ecosystems, your organization's security no longer depends solely on your own ramparts, but on the strength of every link in your supply chain. Third-Party Risk Management (TPRM) has shifted from… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/b/5/0/9/0/b5090ed76418f3de204a8b35e74ccb121b6edf69-cyber-security-34005551280.jpg) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-how-to-approach-a-third-party-risk-management-project)###  [TPRM - How to approach a Third-Party Risk Management project?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-how-to-approach-a-third-party-risk-management-project) 

 TPRM (Third-Party Risk Management) is part of a proactive approach to monitoring and controlling risks associated with supplier failure. In a context where companies and government agencies rely heavily on external partners (IT service providers, SaaS publishers, HR firms, etc.),… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/2/9/1/f/e/291fe78572eea34449819e570d777bd3173bd458-capture-dcran-2025-07-09-155915.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/cyber-risk-management-for-suppliers-its-companies-facing-the-dual-challenge-of-compliance-and-performance)###  [Cyber risk management for suppliers: digital service providers face the dual challenge of compliance and performance](https://www.boardofcyber.io/en/resources/tprm-academy/articles/cyber-risk-management-for-suppliers-its-companies-facing-the-dual-challenge-of-compliance-and-performance) 

 Cyber risk management for suppliers: digital service providers face the dual challenge of compliance and performance With the rise in cyberattacks and the introduction of new European regulations (NIS2, DORA, CRA), digital services companies (DSCs) are facing a strategic challen… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/2/6/8/8/c/2688ca2141d945806bd90ae5acfd898436a8fb65-thumb-nis2.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/nis2-and-local-authorities)###  [NIS2 & Local Authorities: How to assess and secure your suppliers to ensure compliance?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/nis2-and-local-authorities) 

 NIS2 and Local Authorities: Towards concrete and shared compliance The NIS2 directive, expected to be transposed into French law in September 2025, would impose new obligations on local and regional authorities, particularly those with more than 30,000 inhabitants. It would invol… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/d/1/c/b/4/d1cb48303ed8aefb5c23a2b2ac3397bac59e6d12-tprm.jpeg) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/third-party-risk-management-master-the-risks-related-to-your-suppliers)###  [Third Party Risk Management: controlling risks associated with your suppliers](https://www.boardofcyber.io/en/resources/tprm-academy/articles/third-party-risk-management-master-the-risks-related-to-your-suppliers) 

 As a business, you rely on numerous suppliers and partners to carry out your activities. While outsourcing can be a source of agility and performance, it can also expose you to risks and lead to data loss or business interruption. And the consequences can be far-reaching, affecti… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/1/6/e/7/4/16e7492389c22ac88743a5c1ee1635536d8ded61-thumb-ericcaen-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-cybersecurite-nest-pas-un-frein-a-la-valeur-cest-ce-qui-la-rend-durable-eric-caen-skema-business-school)###  [Mutualising supplier assessments to strengthen collective resilience - Bernard GIRY, Île-de-France Region](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-cybersecurite-nest-pas-un-frein-a-la-valeur-cest-ce-qui-la-rend-durable-eric-caen-skema-business-school) 

 In the age of interconnected AI, how can we reconcile innovation with risk management? Generative AI is a disruption comparable to the arrival of the Internet, yet it is being introduced into information systems that are often heterogeneous, poorly documented, and built for a dif… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/4/0/d/5/1/40d5152d20e95d23179bd22d8b3761fa9d101e4f-thumbmarion-buchetcv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-notation-cyber-nous-a-permis-de-passer-a-l-echelle-marion-buchet-cert-aviation)###  [Cyber rating has allowed us to scale up - Marion BUCHET, CERT Aviation](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-notation-cyber-nous-a-permis-de-passer-a-l-echelle-marion-buchet-cert-aviation) 

 Why is cyber risk particularly critical in aviation? The aviation sector is considered highly critical because the operational impact of an incident can be immediate and dramatic. If planes can no longer take off or land, the consequences extend far beyond the affected company: a… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/1/9/9/d/d/199ddb7651b5b163667ffc6c62a0e066cf8a084a-thumb-thierry-piton-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/les-dirigeants-de-pme-sont-peu-conscients-de-leur-niveau-reel-dexposition-cyber-thierry-piton-axa-france)###  [SME managers are largely unaware of their actual level of cyber exposure - Thierry PITON, AXA France](https://www.boardofcyber.io/en/resources/tprm-academy/articles/les-dirigeants-de-pme-sont-peu-conscients-de-leur-niveau-reel-dexposition-cyber-thierry-piton-axa-france) 

 Why has supplier risk become a major cybersecurity issue? Supplier risk is significant, but it does not fully describe the challenges currently facing businesses. At AXA France, we mainly support SMEs and mid-cap companies, which are less focused on managing their supply chain th… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/7/0/8/3/a/7083ac14e775d69cc5b6273132752e425c928873-thumb-cyril-roger-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/faire-de-la-cybersecurite-un-levier-de-dialogue-avec-les-fournisseurs-cyril-roger-groupe-credit-agricole)###  [Making cybersecurity a lever for dialogue with suppliers - Cyril Roger, Crédit Agricole Group](https://www.boardofcyber.io/en/resources/tprm-academy/articles/faire-de-la-cybersecurite-un-levier-de-dialogue-avec-les-fournisseurs-cyril-roger-groupe-credit-agricole) 

 How do you assess the cyber maturity of your supply chain? Crédit Agricole has several thousand suppliers who do not all have the same level of cyber maturity. Large companies have anticipated and are following regulatory developments such as DORA, which establishes principles bu… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/f/c/5/c/0/fc5c0e3eda45dab6b41d2bb284515354ead83d02-thumb-samuel-bafourd-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/pour-un-fonds-la-notation-cyber-va-devenir-une-norme-samuel-bafourd-seven2)###  [Cyber ratings will become standard practice for funds - Samuel BAFOURD, SEVEN2](https://www.boardofcyber.io/en/resources/tprm-academy/articles/pour-un-fonds-la-notation-cyber-va-devenir-une-norme-samuel-bafourd-seven2) 

 Has cyber risk become a top-tier risk for an investment fund like Seven2? Today, cyber risk is a major industrial risk. A mismatch between the level of risk and the resources deployed can lead to a serious incident. Action must therefore be taken on two levels: daily operations a… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/b/d/b/7/b/bdb7b2f62bc403d5695710797d7b78f0d7753817-thumb-cristiantracci-cv-1.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/eviter-la-fragmentation-du-marche-europeen-pour-renforcer-la-resilience-cyber-collective-cristian-michael-tracci-ecso)###  [Preventing European Market Fragmentation to Strengthen Collective Cyber Resilience - Cristian Michael Tracci, ECSO](https://www.boardofcyber.io/en/resources/tprm-academy/articles/eviter-la-fragmentation-du-marche-europeen-pour-renforcer-la-resilience-cyber-collective-cristian-michael-tracci-ecso) 

 How can we prevent fragmentation of the European market during the implementation of NIS 2? Fragmentation can be mitigated first through EU coordination. The NIS Cooperation Group, where Member States sit together with ENISA and the Commission, is the formal venue to align interp… 

 ARTICLE 

 [ ![](https://www.boardofcyber.io/images/d/2/b/2/7/d2b27beaede3fa232c2749243bd70b2b2d8e2c4a-thumb-faridapoulain-cv.png) ](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-souverainete-cest-maitriser-ses-dependances-non-les-subir-farida-poulain-campus-cyber)###  [Sovereignty is about mastering your dependencies, not being subject to them – Farida POULAIN, CAMPUS CYBER](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-souverainete-cest-maitriser-ses-dependances-non-les-subir-farida-poulain-campus-cyber) 

 How do you define cyber sovereignty in a globalized ecosystem? Sovereignty is not autarky: it is not about cutting oneself off from the world, but about having the power to choose. Being sovereign means choosing one's technological dependencies, partners, and standards; mastering… 

 ARTICLE

---

## Navigation

- Parent: [TPRM Academy](https://www.boardofcyber.io/en/resources/tprm-academy.md)
- Children:
  - [6 Contractual Security Clauses to Limit Supplier Cyber Risks](https://www.boardofcyber.io/en/resources/tprm-academy/articles/6-clauses-contractuelles-de-securite-pour-limiter-les-risques-cyber-fournisseur.md)
  - [7 methods for assessing your suppliers' cyber risk](https://www.boardofcyber.io/en/resources/tprm-academy/articles/7-methodes-devaluation-pour-evaluer-le-risque-cyber-de-vos-fournisseurs.md)
  - [10 questions a CISO should ask their SaaS suppliers](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers.md)
  - [Board of Cyber joins the Forum des Compétences plenary session](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience.md)
  - [Cyber Insurance: Understanding, Assessing, and Choosing the Best Cyber Insurance for Your Business](https://www.boardofcyber.io/en/resources/tprm-academy/articles/cyber-insurance-understand-evaluate-and-choose-the-best-cyber-insurance-for-your-business.md)
  - [DORA: Understanding European regulations on digital operational resilience](https://www.boardofcyber.io/en/resources/tprm-academy/articles/dora-understand-the-european-regulation-on-digital-operational-resilience.md)
  - [Supplier Due Diligence: Key steps to secure your partnerships](https://www.boardofcyber.io/en/resources/tprm-academy/articles/supplier-due-diligence-key-steps-to-secure-your-partnerships.md)
  - [In cyber defence, no one wins alone - Maria IACONO, Les Assises de la cybersécurité](https://www.boardofcyber.io/en/resources/tprm-academy/articles/en-cyberdefense-personne-ne-gagne-seul-maria-iacono-les-assises-de-la-cybersecurite.md)
  - [Preventing European Market Fragmentation to Strengthen Collective Cyber Resilience - Cristian Michael Tracci, ECSO](https://www.boardofcyber.io/en/resources/tprm-academy/articles/eviter-la-fragmentation-du-marche-europeen-pour-renforcer-la-resilience-cyber-collective-cristian-michael-tracci-ecso.md)
  - [External Attack Surface Management: assess, prioritise, remediate](https://www.boardofcyber.io/en/resources/tprm-academy/articles/external-attack-surface-management-assess-prioritize-remediate.md)
  - [Making cybersecurity a lever for dialogue with suppliers - Cyril Roger, Crédit Agricole Group](https://www.boardofcyber.io/en/resources/tprm-academy/articles/faire-de-la-cybersecurite-un-levier-de-dialogue-avec-les-fournisseurs-cyril-roger-groupe-credit-agricole.md)
  - [Cyber risk management for suppliers: digital service providers face the dual challenge of compliance and performance](https://www.boardofcyber.io/en/resources/tprm-academy/articles/cyber-risk-management-for-suppliers-its-companies-facing-the-dual-challenge-of-compliance-and-performance.md)
  - [HDS: Everything you need to know about healthcare data hosting and certification](https://www.boardofcyber.io/en/resources/tprm-academy/articles/hds-all-you-need-to-know-about-health-data-hosting-and-certification.md)
  - [AI ACT – What to expect and how to adapt your cyber strategy?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/ia-act-a-quoi-sattendre-et-comment-adapter-sa-strategie-cyber.md)
  - [ISO 27001: everything you need to know about the information security standard](https://www.boardofcyber.io/en/resources/tprm-academy/articles/iso-27001-understanding-the-information-systems-security-standard.md)
  - [Mutualising supplier assessments to strengthen collective resilience - Bernard GIRY, Île-de-France Region](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-cybersecurite-nest-pas-un-frein-a-la-valeur-cest-ce-qui-la-rend-durable-eric-caen-skema-business-school.md)
  - [Cyber rating has allowed us to scale up - Marion BUCHET, CERT Aviation](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-notation-cyber-nous-a-permis-de-passer-a-l-echelle-marion-buchet-cert-aviation.md)
  - [Sovereignty is about mastering your dependencies, not being subject to them – Farida POULAIN, CAMPUS CYBER](https://www.boardofcyber.io/en/resources/tprm-academy/articles/la-souverainete-cest-maitriser-ses-dependances-non-les-subir-farida-poulain-campus-cyber.md)
  - [The 8 regulations you need to know to succeed in your TPRM approach](https://www.boardofcyber.io/en/resources/tprm-academy/articles/the-8-regulations-you-need-to-know-to-succeed-in-your-TPRM-approach.md)
  - [10 Errors Undermining Your TPRM Strategy](https://www.boardofcyber.io/en/resources/tprm-academy/articles/10-questions-a-ciso-should-ask-their-saas-suppliers.md)
  - [SME managers are largely unaware of their actual level of cyber exposure - Thierry PITON, AXA France](https://www.boardofcyber.io/en/resources/tprm-academy/articles/les-dirigeants-de-pme-sont-peu-conscients-de-leur-niveau-reel-dexposition-cyber-thierry-piton-axa-france.md)
  - [NIS2 & Local Authorities: How to assess and secure your suppliers to ensure compliance?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/nis2-and-local-authorities.md)
  - [Cyber security ratings and cyber insurance: what insurers really assess](https://www.boardofcyber.io/en/resources/tprm-academy/articles/cyber-insurance-understand-evaluate-and-choose-the-best-cyber-insurance-for-your-business.md)
  - [2024 Observatory: Suppliers cyber risk](https://www.boardofcyber.io/en/resources/tprm-academy/articles/observatory-2024-cyber-risk-related-to-suppliers.md)
  - [TPRM Observatory 2025](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-observatory-2025-cyber-risk-management-for-suppliers.md)
  - [Cyber ratings will become standard practice for funds - Samuel BAFOURD, SEVEN2](https://www.boardofcyber.io/en/resources/tprm-academy/articles/pour-un-fonds-la-notation-cyber-va-devenir-une-norme-samuel-bafourd-seven2.md)
  - [ISSP: Understanding and implementing an effective Information System Security Policy](https://www.boardofcyber.io/en/resources/tprm-academy/articles/issp-understand-and-implement-an-effective-information-systems-security-policy.md)
  - [Third Party Risk Management: controlling risks associated with your suppliers](https://www.boardofcyber.io/en/resources/tprm-academy/articles/third-party-risk-management-master-the-risks-related-to-your-suppliers.md)
  - [TPRM - How to approach a Third-Party Risk Management project?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-how-to-approach-a-third-party-risk-management-project.md)
  - [TPRM and AI: How automation is finally transforming supplier risk management?](https://www.boardofcyber.io/en/resources/tprm-academy/articles/tprm-et-ia-comment-lautomatisation-transforme-enfin-la-gestion-du-risque-fournisseur.md)
