Risk Ledger Raises $32M to Replace Supply Chain Security Questionnaires

Risk Ledger's $32M Series B funds its AI-powered supply chain security network, replacing outdated questionnaires. Plans US entry with 16,000+ organizations.

lunes, 27 de julio de 2026 • 5 min read • Q2BSTUDIO Team

Red colaborativa de ciberseguridad busca expandirse a EE.UU.

The landscape of corporate cybersecurity has shifted dramatically in recent years. Protecting the organizational perimeter is no longer enough: attackers have discovered that the weakest link is often in the supply chain. A compromised supplier can open the door to dozens of clients, and the average cost of such an incident exceeds $4.9 million, according to recent studies. In this context, British startup Risk Ledger has announced a $32 million Series B round ( £24 million) led by Axiom Equity with participation from Mercia Ventures, aiming to transform how organizations manage third-party risk. The proposal is radical: replace the traditional security questionnaire —a document filled out hundreds of times a year and obsolete the next day— with a collaborative network where each supplier maintains a single, up-to-date profile shared with all its clients. This approach, which the company calls 'collective defense,' promises to end the inefficiency of a system that, according to its founders, generates an invisible cost of billions of lost hours worldwide.

To understand the magnitude of the problem, look at the data. Verizon's 2025 Data Breach Investigations Report revealed that third-party involvement in confirmed breaches doubled in a single year, from 15% to 30%. Attacks like MOVEit, which exploited a vulnerability in file-transfer software, showed how a single point of failure can affect hundreds of organizations simultaneously. The traditional risk management methodology —static questionnaires, point-in-time assessments, reliance on annual certifications— is simply not designed for a threat that moves in hours. This is where Risk Ledger proposes a network-based solution: each supplier completes a single standardized assessment covering twelve security domains and maintains it as a living profile. Connected clients see the same updated information, eliminating duplication and obsolescence. The platform already counts more than 16,000 organizations in the UK, spanning financial services, critical infrastructure, and public administration, including deployments in the NHS and police.

Risk Ledger's technological bet relies on artificial intelligence and the cloud to scale the model. The company plans to build AI tools on the network's data, capable of automating manual profile reviews and detecting risk signals that only emerge in connections: a software dependency quietly running under forty suppliers at once, or a sub-processor shared by several critical clients. For this intelligence to function, robust and reliable cloud infrastructure is needed. Here, companies like Q2BSTUDIO, a specialist in custom software development, can add value. Many organizations wishing to integrate with platforms like Risk Ledger or build their own security solutions need customized applications that connect internal systems to the network, automating control data collection and report generation. Furthermore, deploying AI agents to continuously monitor supplier status and alert on suspicious changes requires a solid cloud foundation, whether AWS or Azure, and a business intelligence approach to transform data into decisions.

The market Risk Ledger targets is enormous. According to Mordor Intelligence, third-party risk management software will reach $20.7 billion by 2031, but the company aims for something bigger: becoming the default infrastructure for security verification between organizations, competing not only with external rating providers like BitSight or SecurityScorecard, but also with workflow suites like OneTrust and ProcessUnity. The key is the network: the more suppliers join, the more valuable the platform becomes for clients, and vice versa. This network effect is hard to replicate, especially because the validated control data residing on the platform cannot be obtained from outside. Competitors attempting to imitate the model face the dilemma of cannibalizing their own per-client subscription revenues.

However, expansion into the United States —the world's largest third-party risk market— presents a major challenge. Risk Ledger will have to build network density from nearly zero, competing with incumbents established for a decade. The strategy involves capturing large federated buyers (such as government or healthcare entities) and letting mandatory supplier onboarding do the rest. US regulatory pressure, with SEC cybersecurity disclosure rules and other guidelines, is creating demand that incumbents cannot quickly meet. In this context, having technology partners capable of implementing cloud and AI solutions agilely is crucial. Q2BSTUDIO, with its expertise in cybersecurity and pentesting, can help companies audit their own internal controls and prepare to integrate into trust networks like Risk Ledger, ensuring that the profiles they share accurately reflect their security posture.

The funding round also reveals an interesting trend: capital discipline. Risk Ledger raised only £9.8 million in prior capital to reach 16,000 organizations, contrasting with the hundreds of millions received by competitors. This indicates an efficient business model, where supplier acquisition is virtually free (they join invited by clients) and growth relies on network effects. For a development company like Q2BSTUDIO, this presents an opportunity: offering consulting and integration services so that organizations can fully leverage these platforms' capabilities, whether through custom applications that automate control data synchronization or via Power BI dashboards that visualize aggregated supply chain risk.

In conclusion, Risk Ledger's bet on network-based collective defense represents a paradigm shift in corporate cybersecurity. The underlying technology —shared profiles, artificial intelligence, cloud infrastructure— requires a strong partner ecosystem. Q2BSTUDIO, with its focus on custom software development, cloud AWS/Azure, AI, cybersecurity, and BI, is well positioned to help companies navigate this transition. The question is no longer whether the questionnaire model will disappear, but how quickly organizations will adopt a collaborative approach that, according to data, is the only way to stay ahead of threats. The next eighteen months will be crucial to see if Risk Ledger's network reaches critical mass in the US; if so, it could completely redefine the supply chain security industry.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.