Blog

Risk Management
2025 Review: How many vendors actually meet their SLAs?
We analyzed vendor SLA performance across 2025 and discovered that over half experienced outages, vendor-reported downtimes often don't match reality, and that we could all use some better New Year's resolutions come 2026.
Nick Gavin
December 10, 2025
Product Update
Risk Management
Vendor-Reported SLAs: Tracking your vendors’ non-uptime promises
Your non-SaaS vendors make promises beyond uptime—response times, resolution rates, satisfaction scores, etc. Custom Vendor-Reported SLAs let you track these commitments so you can see who's excelling and who's just barely meeting the bar.
Jacob Crofts
November 20, 2025

Product Update
Clarative has a new look, and it's not just about aesthetics
We've redesigned Clarative from the ground up—and while you'll notice the fresh interface right away, the real story is what's happening beneath the surface, and why we made the change.
Regina Yan
October 30, 2025

Operational Risk
Risk Management
What today’s AWS outage reveals about the rest of your vendors
Today's AWS us-east-1 outage affected a significant portion of the tech ecosystem, and the cascading failures we observed through our continuous vendor performance monitoring revealed something important about how concentration risk actually works in modern vendor portfolios.
Tony DiPadova
October 20, 2025

Operational Risk
Beyond SLAs: Why Service Level Agreements Don't Guarantee Service Level Reality
Your vendor's SLA promises 99.9% uptime, but your users are experiencing frequent issues. Discover why the gap between contractual commitments and actual performance is wider than most organizations realize and what you can do about it.
Chris Sallen
October 10, 2025

Operational Risk
Risk Management
Why Security Isn't Enough: The Evolution of Third-Party Risk
The CrowdStrike outage grounded planes and shut down hospitals. This didn’t happen because of a security breach; it happened because of a bad software update. This global outage exposed the dangerous blind spot in security-focused TPRM programs and showed why operational risk management is just as critical as cybersecurity assessment.
Nick Gavin
October 9, 2025