# Risk Ledger Secures $32M Series B to Expand Supply Chain Security Network


British cybersecurity platform aims to transform third-party risk management through collaborative intelligence and AI automation


Risk Ledger, a London-based supply chain security platform, has closed a £24 million (approximately $32.3 million) Series B funding round led by Axiom Equity Partners, with support from existing investor Mercia Ventures. The round brings the company's total capital raised to £33.8 million (roughly $45 million), positioning the firm to accelerate its expansion into North America and deepen its AI-driven capabilities for supply chain risk assessment.


The funding marks a significant validation of Risk Ledger's network-first approach to third-party risk management—a model that stands in contrast to traditional vendor assessment platforms by emphasizing collaborative intelligence sharing across ecosystems rather than isolated point assessments.


## The Funding Round and Strategic Direction


The Series B represents a substantial investment in Risk Ledger's vision of transforming how organizations manage supplier and third-party risks. According to the company, the fresh capital will be deployed across three key strategic initiatives:


  • US market expansion — Risk Ledger will establish operations in North America, a market where third-party risk management remains fragmented and largely dependent on manual assessment processes
  • AI and automation tools — The company plans to build intelligent systems that automate security reviews and surface risk signals in real time, reducing the friction of ongoing assessment cycles
  • Network deepening — Risk Ledger intends to increase the volume and quality of intelligence flowing through its platform, making participation more valuable for existing members

  • Jonathan Organ, founding partner at Axiom Equity, framed the investment not as support for an incremental player in an existing category, but as backing for a category creator. "Risk Ledger is creating a category rather than competing in an old one," Organ said. "The network it has built is hard to replicate and grows more valuable with every organisation that joins, which is exactly the kind of business we look to back."


    This observation underscores a critical dynamic in enterprise cybersecurity: network effects. As more organizations join Risk Ledger's platform and complete standardized assessments, the value of the network compounds for all participants—suppliers gain credibility, buyers gain comprehensive visibility, and systemic risks become more transparent.


    ## The Third-Party Risk Management Crisis


    Risk Ledger's rise to prominence reflects a broader industry reality: traditional approaches to third-party risk management have failed to keep pace with the complexity and scale of modern supply chains.


    For decades, organizations have relied on vendor questionnaires, annual audits, and compliance certifications to assess supplier security posture. This approach is plagued by structural problems:


    | Challenge | Impact |

    |-----------|--------|

    | Assessment fatigue | Suppliers complete dozens of similar questionnaires annually from different buyers |

    | Staleness | Annual assessments provide a snapshot; threats emerge and shift continuously |

    | Inconsistency | Different buyers ask different questions, yielding fragmented visibility |

    | Manual burden | Assessment reviews and comparison require significant analyst time |

    | Systemic opacity | Buyers lack visibility into suppliers' own supply chains |


    The result is risk that cascades undetected. Major breaches—from SolarWinds (2020) to LastPass (2022) to MOVEit Transfer (2023)—were preceded by supply chain compromises that traditional assessment frameworks failed to surface before exploitation.


    Risk Ledger's founding in 2018 was directly motivated by these failures. The platform was designed to shift from episodic, siloed assessments toward continuous, collaborative risk visibility.


    ## The Network-First Platform Model


    Risk Ledger's operational model departs significantly from traditional vendor risk management tools. Rather than a database that organizations populate privately, Risk Ledger operates as a shared network where:


    1. Suppliers complete standardized assessments — A single, comprehensive security assessment replaces the questionnaire sprawl

    2. Assessments are maintained in real time — Suppliers update their profiles continuously, not annually

    3. Buyer organizations access shared profiles — Instead of conducting separate vendor reviews, buyers view supplier profiles within the Risk Ledger network

    4. Intelligence compounds — As more organizations join, the collective understanding of supplier posture deepens


    The platform currently connects over 16,000 organizations spanning financial services, critical national infrastructure, government agencies, and the insurance sector. This concentration in high-assurance industries reflects Risk Ledger's positioning: the platform provides the most value in sectors where supply chain compromise carries systemic consequences.


    For participating suppliers, the model offers efficiency gains—one comprehensive assessment, rather than dozens of custom questionnaires. For buyers, it provides breadth and depth unavailable through bilateral vendor assessments. For the ecosystem, it creates transparency that historically only existed within individual buying organizations' risk functions.


    ## The Road Ahead: AI, Automation, and Scale


    Risk Ledger's stated use of Series B funding to build AI-driven automation tools reflects an industry-wide recognition that manual security assessment cannot scale to the complexity of modern supply chains.


    The company is positioning AI automation in two critical areas:


    Automated risk signal detection — Rather than relying on analysts to flag concerning patterns in supplier assessment data, AI systems can identify anomalies, risk signals, and behavior changes in real time and escalate them for human review.


    Assessment acceleration — AI-assisted questionnaire completion and data collection can reduce the burden on suppliers completing assessments, lowering friction and encouraging broader network participation.


    For buyers, automation promises to shift human analyst attention from routine data collection toward strategic decision-making about which risks warrant escalation, remediation, or supplier engagement.


    The company's expansion into the US market is both strategic and necessary. While supply chain risk management has gained compliance traction in Europe (driven by NIS Directive updates and sector-specific regulations), the US market remains fragmented, with no dominant incumbent and significant regulatory momentum building (driven by CISA guidance, SEC disclosure requirements, and executive orders on critical infrastructure security).


    ## Market Implications and Competitive Landscape


    Risk Ledger's funding round arrives amid a broader wave of capital flowing into supply chain and third-party risk management platforms. Recent competitors and adjacent players include:


  • Oak (raised $60M in Series A, stealth-mode vendor risk management)
  • Valarian (raised $50M for sovereign infrastructure control)
  • Quantifind (raised $200M for AI-native risk intelligence)
  • Straiker (raised $64M for AI security platforms)

  • Yet Risk Ledger's network-effects model—where value compounds with participation—creates defensibility that point-product competitors cannot easily replicate. A software tool that assesses vendor risk can be sold individually; a network that aggregates industry-wide supplier security data cannot.


    This dynamic suggests Risk Ledger's primary competition is not other software vendors, but organizational inertia and fragmentation—the tendency of large enterprises to maintain proprietary vendor assessment processes rather than joining a shared ecosystem.


    ---


    ## HackWire Analysis


    Risk Ledger's funding and market momentum reflect a critical inflection point in cybersecurity: the shift from compliance-theater third-party risk management toward operationalized, continuous intelligence.


    What distinguishes this moment is timing and urgency. Supply chain attacks have moved from theoretical threat to routine exploitation vector. The past three years have seen sustained, sophisticated attacks through SolarWinds, MOVEit, 3CX, and dozens of smaller suppliers. Regulatory bodies—from CISA to the SEC—are now explicitly holding organizations accountable for supply chain security visibility. Risk Ledger's timing allows it to ride both industry maturation and regulatory mandates.


    The hidden risk others miss: network-based risk platforms create transparency, but transparency itself creates strategic value asymmetry. Organizations with early access to real-time supplier risk intelligence gain advantage over competitors who rely on manual assessment. This could accelerate a bifurcation where sophisticated enterprises gain disproportionate supply chain resilience while smaller organizations remain exposed. Risk Ledger's value proposition to mid-market organizations—the ability to punch above their weight through network intelligence—may be its most powerful feature, yet one that deserves scrutiny around fair access and potential gatekeeping.


    For defenders and security leaders: the inflection point here is that manual third-party risk management is no longer defensible. Teams should expect audits and regulatory pressure to shift away from "show me your vendor assessment spreadsheet" toward "show me your continuous supplier risk visibility." Risk Ledger and peers are providing the tooling for that shift—but adoption requires recognizing that vendor security is no longer an annual checkbox, it's an operational imperative.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)