Guide

Inside-out vs outside-in: why the scanner misses your riskiest vendor

Practitioner guide · 6 min read · Updated July 2026

Most third-party risk programs start from the wrong end of the telescope. They grade what a vendor shows the internet, then adjust for context. But your exposure was never on the internet — so the model is blind to exactly the vendor that should worry you most.

The outside-in model, and its blind spot

External security ratings scan a vendor's internet-facing posture — open ports, expired certificates, leaked credentials, domain hygiene — and compress it into a grade. That signal is real and useful. But it answers a narrow question: how exposed is this vendor to the internet? It does not answer the question a risk owner actually has: how much of us does this vendor hold, and what happens if they're compromised?

The gap between those two questions is where incidents live. A contractor with custody of your designs, a facilities firm with badge access to your sites, an outsourcer whose staff sit inside your systems — each can carry enormous exposure with almost no internet-facing surface to grade. The scanner rates them quietly. Your classification, if it depends on that grade, does too.

Inside-out: classify by exposure

The inside-out model inverts the starting point. Instead of asking what a vendor exposes to the world, it asks what a vendor holds of yours, across six access vectors:

  • Logical data access — the data they process, store, or can reach.
  • Network connectivity — standing connections into your environment.
  • Physical & facility access — who is on your floors, and where.
  • Design & IP custody — drawings, specifications, and source in outside hands.
  • Embedded personnel — their people inside your teams and sites.
  • Product & component supply — what ships into your product and process.

Only your side of the relationship knows these values, which is precisely why they're a better foundation than anything a vendor advertises or a scanner infers. The vector profile yields a tier, and the tier decides how deep the assessment goes — full scrutiny where exposure concentrates, a signed attestation where it doesn't.

Why this is a stronger foundation

Three reasons. First, completeness: because classification is cheap and automatic, you classify the entire register rather than a shortlist you can afford to assess — so the risky vendor nobody nominated still surfaces. Second, proportionality: depth follows exposure, so scarce assessment effort lands where it matters. Third, defensibility: tiers derived from documented exposure are far easier to justify to a board or regulator than a vendor list assembled from intuition.

Where external signals still belong

Inside-out doesn't discard outside-in — it re-frames it. External scan data is excellent evidence: attach it to the vendors your classification already flags, and let it inform review and reassessment. What it shouldn't be is the verdict — the thing that decides whether a vendor gets looked at in the first place. Evidence in; not verdict out.

Putting it into practice

A workable rollout: ingest the full vendor master, classify every record by the six vectors, and let tier drive assessment depth automatically. Layer external signals onto the higher tiers as evidence. Keep the whole thing on infrastructure you control, so the tool doesn't add a new dependency to the very risk surface you're trying to manage. That is the model Polestead is built around — see Inside-Out Risk for how it works in the product.

FAQ

Quick answers.

What is inside-out TPRM?+

Classifying each vendor by the exposure they create for you — data, network, facilities, designs, people, supply — rather than by an external scan of their internet posture.

Why do external ratings miss risky vendors?+

They grade internet-facing posture. A vendor with little surface but deep access to your data, sites, or designs can rate well while carrying real risk.

Should external ratings be abandoned?+

No — use them as evidence within an exposure-based model, scoped to flagged vendors. Just don't let them be the verdict that decides scrutiny.