GEN-TPRM: An OSINT-Driven Risk Assessment Model for Third-Party Organizations

Harika Asili*, Şerif Bahtiyar

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Recently, organizations supplies many ingredients of their products from third-party organizations, where security of the third-party organizations is a crucial for the success of the product. This circumstance makes, the rapid risk assessment of the organizations a challenging task. This paper introduces GEN-TPRM, a third-party security risk assessment model that uses open-source intelligence (OSINT), LLM-based question answering, and scoring aligned with ISO/IEC 27001:2022 and Gartner risk thresholds. It integrates publicly verifiable indicators like breach disclosures, CVEs, and regulatory penalties into risk-specific directional QA replies and a standardized risk index. The model integrates a retrieval-augmented LLM layer with a logistic regression classifier trained on historical security cases. The approach was validated through a real-world case study of 100 well-known vendors. The model generates transparent outputs without requiring internal access to vendor environments, offering a lightweight, scalable solution for lifecycle-based third-party pre-risk management.

Original languageEnglish
Title of host publication2025 15th International Conference on Advanced Computer Information Technologies, ACIT 2025 - Conference Proceedings
PublisherInstitute of Electrical and Electronics Engineers
Pages497-500
Number of pages4
ISBN (Electronic)9798331595432
DOIs
Publication statusPublished - 2025
Event15th International Conference on Advanced Computer Information Technologies, ACIT 2025 - Hybrid, Sibenik, Croatia
Duration: 17 Sept 202519 Sept 2025

Publication series

NameProceedings - International Conference on Advanced Computer Information Technologies, ACIT
ISSN (Print)2770-5218
ISSN (Electronic)2770-5226

Conference

Conference15th International Conference on Advanced Computer Information Technologies, ACIT 2025
Country/TerritoryCroatia
CityHybrid, Sibenik
Period17/09/2519/09/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Keywords

  • augmented generation
  • large language model
  • security
  • source intelligence
  • TPRM

Fingerprint

Dive into the research topics of 'GEN-TPRM: An OSINT-Driven Risk Assessment Model for Third-Party Organizations'. Together they form a unique fingerprint.

Cite this