Signal Types
LowerPlane monitors 10 categories of vendor risk signals:Breach Notification
Breach Notification
Data breach or security incident reported by the vendor. Example: vendor disclosed unauthorized access to customer data.
CVE Disclosure
CVE Disclosure
New vulnerability (CVE) affecting vendor software or infrastructure. Example: critical CVE found in vendor’s API library.
Financial Change
Financial Change
Material change in vendor’s financial status. Example: vendor’s credit rating downgraded.
News Sentiment
News Sentiment
Negative news coverage or public reports about the vendor. Example: vendor facing regulatory investigation.
Certificate Expiry
Certificate Expiry
SSL/TLS certificate or compliance certification approaching expiry. Example: vendor’s SOC 2 report expires in 30 days.
Compliance Change
Compliance Change
Change in vendor’s compliance posture or certifications. Example: vendor lost ISO 27001 certification.
Data Incident
Data Incident
Data handling incident such as leak, misuse, or unauthorized access. Example: vendor employee accessed customer data without authorization.
Acquisition
Acquisition
Vendor merger, acquisition, or ownership change. Example: vendor acquired by private equity firm.
Regulatory Action
Regulatory Action
Government or regulatory enforcement action against vendor. Example: vendor fined by ICO for GDPR violation.
Service Outage
Service Outage
Major service disruption or downtime event. Example: vendor experienced 12-hour global outage.
Signal Sources
Risk signals are collected from both automated and manual sources.Security & Vulnerability Sources
| Source | What It Monitors |
|---|---|
| NVD (National Vulnerability Database) | CVEs affecting vendor software and dependencies |
| MITRE CVE | Newly disclosed vulnerabilities across vendor technology stack |
| CISA Known Exploited Vulnerabilities | Actively exploited vulnerabilities in vendor products |
| Have I Been Pwned | Vendor domain breach exposure and credential leaks |
| SecurityScorecard / BitSight | Vendor security posture ratings and risk scores |
News & Business Intelligence Sources
| Source | What It Monitors |
|---|---|
| TechCrunch | Vendor acquisitions, funding changes, leadership changes, incidents |
| Hacker News (Y Combinator) | Community-reported vendor security issues and outages |
| The Verge / Ars Technica | Major vendor security incidents and data breaches |
| Reuters / Bloomberg | Vendor financial changes, regulatory actions, M&A activity |
| Google News | Broad vendor sentiment and coverage aggregation |
| SEC EDGAR | Public company financial filings and material event disclosures |
| PACER / CourtListener | Legal proceedings and regulatory enforcement actions |
Compliance & Certification Sources
| Source | What It Monitors |
|---|---|
| Vendor SOC 2 / ISO 27001 Reports | Certification validity, expiry dates, scope changes |
| Vendor Trust Centers | Security practice updates, subprocessor changes, policy updates |
| GDPR Enforcement Tracker | Data protection authority fines and enforcement actions |
| HHS Breach Portal | HIPAA breach notifications involving vendor organizations |
| PCI SSC | PCI-DSS compliance status and qualified assessor listings |
Operational Monitoring Sources
| Source | What It Monitors |
|---|---|
| Vendor Status Pages | Service availability, incidents, degraded performance (e.g., status.vendor.com) |
| Downdetector | Crowdsourced outage detection and service disruption reports |
| SSL Labs / Certificate Transparency | SSL/TLS certificate expiry, weak configurations, certificate changes |
| DNS Monitoring | Domain changes, DNSSEC status, MX record modifications |
| Shodan / Censys | Exposed services, open ports, and misconfigurations on vendor infrastructure |
Connected Integration Sources
| Source | What It Monitors |
|---|---|
| Vendor API Health | Response times, error rates, authentication failures from connected integrations |
| Webhook Events | Real-time change notifications from connected vendor tools |
| Sync Status | Data freshness and sync failures indicating vendor-side issues |
Manual Reporting
Team members can manually create risk signals for:- Findings from vendor security reviews and on-site audits
- Audit observations and due diligence findings
- Customer complaints about vendor performance or security
- Internal risk assessments and pen test results
- Information from vendor relationship managers
Signal Lifecycle
Each risk signal progresses through the following statuses:Severity Levels
| Severity | Action Required | Response SLA |
|---|---|---|
| Critical | Immediate response, potential vendor suspension | 4 hours |
| High | Urgent review, impact assessment required | 24 hours |
| Medium | Standard review within business cycle | 5 business days |
| Low | Monitor and track, review at next assessment | 30 days |
| Informational | Awareness only, no action required | N/A |
Integration with Vendor Risk Management
- Risk signals are linked to specific vendors in the vendor register
- Critical signals can trigger automatic risk level re-assessment
- Signal history is included in vendor risk assessment reports
- Unresolved signals are flagged during vendor review cycles
- Signal trends contribute to vendor overall risk scoring