The Vendor Monitoring page provides continuous visibility into vendor-related security events, compliance changes, and business risks. Risk signals are aggregated from multiple sources and presented in a unified timeline for review and action.

Signal Types

LowerPlane monitors 10 categories of vendor risk signals:
Data breach or security incident reported by the vendor. Example: vendor disclosed unauthorized access to customer data.
New vulnerability (CVE) affecting vendor software or infrastructure. Example: critical CVE found in vendor’s API library.
Material change in vendor’s financial status. Example: vendor’s credit rating downgraded.
Negative news coverage or public reports about the vendor. Example: vendor facing regulatory investigation.
SSL/TLS certificate or compliance certification approaching expiry. Example: vendor’s SOC 2 report expires in 30 days.
Change in vendor’s compliance posture or certifications. Example: vendor lost ISO 27001 certification.
Data handling incident such as leak, misuse, or unauthorized access. Example: vendor employee accessed customer data without authorization.
Vendor merger, acquisition, or ownership change. Example: vendor acquired by private equity firm.
Government or regulatory enforcement action against vendor. Example: vendor fined by ICO for GDPR violation.
Major service disruption or downtime event. Example: vendor experienced 12-hour global outage.

Signal Sources

Risk signals are collected from both automated and manual sources.

Security & Vulnerability Sources

SourceWhat It Monitors
NVD (National Vulnerability Database)CVEs affecting vendor software and dependencies
MITRE CVENewly disclosed vulnerabilities across vendor technology stack
CISA Known Exploited VulnerabilitiesActively exploited vulnerabilities in vendor products
Have I Been PwnedVendor domain breach exposure and credential leaks
SecurityScorecard / BitSightVendor security posture ratings and risk scores

News & Business Intelligence Sources

SourceWhat It Monitors
TechCrunchVendor acquisitions, funding changes, leadership changes, incidents
Hacker News (Y Combinator)Community-reported vendor security issues and outages
The Verge / Ars TechnicaMajor vendor security incidents and data breaches
Reuters / BloombergVendor financial changes, regulatory actions, M&A activity
Google NewsBroad vendor sentiment and coverage aggregation
SEC EDGARPublic company financial filings and material event disclosures
PACER / CourtListenerLegal proceedings and regulatory enforcement actions

Compliance & Certification Sources

SourceWhat It Monitors
Vendor SOC 2 / ISO 27001 ReportsCertification validity, expiry dates, scope changes
Vendor Trust CentersSecurity practice updates, subprocessor changes, policy updates
GDPR Enforcement TrackerData protection authority fines and enforcement actions
HHS Breach PortalHIPAA breach notifications involving vendor organizations
PCI SSCPCI-DSS compliance status and qualified assessor listings

Operational Monitoring Sources

SourceWhat It Monitors
Vendor Status PagesService availability, incidents, degraded performance (e.g., status.vendor.com)
DowndetectorCrowdsourced outage detection and service disruption reports
SSL Labs / Certificate TransparencySSL/TLS certificate expiry, weak configurations, certificate changes
DNS MonitoringDomain changes, DNSSEC status, MX record modifications
Shodan / CensysExposed services, open ports, and misconfigurations on vendor infrastructure

Connected Integration Sources

SourceWhat It Monitors
Vendor API HealthResponse times, error rates, authentication failures from connected integrations
Webhook EventsReal-time change notifications from connected vendor tools
Sync StatusData freshness and sync failures indicating vendor-side issues

Manual Reporting

Team members can manually create risk signals for:
  • Findings from vendor security reviews and on-site audits
  • Audit observations and due diligence findings
  • Customer complaints about vendor performance or security
  • Internal risk assessments and pen test results
  • Information from vendor relationship managers

Signal Lifecycle

Each risk signal progresses through the following statuses:
1

New

Signal detected and awaiting review. Appears in the monitoring feed with severity badge.
2

Acknowledged

Reviewed by a team member. The reviewer is recorded along with the timestamp.
3

Investigating

Active investigation or remediation in progress. Impact assessment may be added.
4

Resolved / Dismissed

Resolved: Issue addressed and risk mitigated. Resolution notes are recorded. Dismissed: Signal determined to be non-applicable or false positive.

Severity Levels

SeverityAction RequiredResponse SLA
CriticalImmediate response, potential vendor suspension4 hours
HighUrgent review, impact assessment required24 hours
MediumStandard review within business cycle5 business days
LowMonitor and track, review at next assessment30 days
InformationalAwareness only, no action requiredN/A

Integration with Vendor Risk Management

  • Risk signals are linked to specific vendors in the vendor register
  • Critical signals can trigger automatic risk level re-assessment
  • Signal history is included in vendor risk assessment reports
  • Unresolved signals are flagged during vendor review cycles
  • Signal trends contribute to vendor overall risk scoring