Recorded Future has launched six new capabilities inside its Third-Party Risk product, uniting threat intelligence and risk ratings into a single workflow. The goal is a single product, one that treats third-party risk as an intelligence operation. It combines the contextual threat intelligence that surfaces active exposures with the continuous monitoring and risk ratings that can give those exposures business context.
The third-party risk market has historically been split into two separate categories. Threat intelligence platforms on one side. Risk ratings tools on the other. Generally, customers have had to choose between them, run both in parallel, or stitch them together on their own. Neither approach solved the core problem. Ratings tools tell you how a vendor maintains their defenses but go silent on what is actively happening to them. Threat intelligence tells you who is being targeted but lacks the continuous vendor monitoring and hygiene foundation that risk programs often require.
That era is over.
Recorded Future brings together the threat intelligence and risk ratings layers in a single product, enabling cyber threat intelligence (CTI) and third-party risk management (TPRM) analysts to work from the same data, the same findings, and the same workflow, so organizations can be ahead of vendor compromises, not catching up to them. This marks a deliberate shift toward a premium, intelligence-led product where threat intelligence and risk ratings work together rather than alongside each other.
What Just Launched
Recorded Future AI for Third-Party Risk
Analysts managing large vendor portfolios often spend too much time assembling intelligence and not enough time acting on it. Recorded Future AI is now available directly in the Third-Party Risk workflow, delivering on-demand vendor summaries grounded in and informed by the Intelligence Graph. Analysts can ask questions about specific vendors, surface relevant threat context, and get remediation guidance, all from the Intelligence Card. Coverage will deepen as additional data sources are integrated.

Figure 1: Recorded Future AI for Third-Party Risk
Threat Pressure and Enhanced CSP Rating
Threat Pressure surfaces Recorded Future threat intelligence metrics directly on the vendor Security Profile, so active targeting signals and threat exposure appear alongside security ratings in a single view. No more cross-referencing two platforms.
Enhanced CSP Rating addresses a longstanding problem with how cloud and internet service providers get scored. Standard asset attribution models have historically misclassified shared infrastructure as belonging to the provider, inflating risk scores and making them hard to defend. The updated methodology better accounts for scaled asset analysis, alternative attribution modeling, and transparent visibility into what is included or excluded.
Both of these capabilities draw on the trust and track record built by RiskRecon over more than a decade of security ratings expertise, and are also available within the RiskRecon product line for customers who use it as their primary ratings platform.
Where We Are Going
There is more coming. Future releases will bring Daily Technology and Vulnerability Scanning, a full Security Profile, and Dark Web Playbook Alerts, capabilities that will help further widen the gap between what Recorded Future delivers and what pure-play ratings vendors can offer. When configured, those Alerts notify your team when a vendor appears on ransomware extortion sites, dark web markets, or Telegram, with recommended next steps included.
The organizations getting ahead of third-party risk are often the ones treating it as an intelligence operation.
Learn more about Recorded Future Third-Party Risk or request a demo to see it in action.
Frequently Asked Questions
1. What is Recorded Future Third-Party Risk?
Recorded Future Third-Party Risk combines continuous vendor monitoring, risk ratings, and real-time threat intelligence in a single product. It helps inform you how a vendor maintains their defenses and surfaces signals when those defenses are actively being tested, often before the vendor is aware of them.
2. Who is this for?
- For CTI teams using Third-Party Intelligence: this release adds hygiene ratings visibility into the same platform. You can now see how exposed a vendor actually is, not just that they are being targeted.
- For GRC and TPRM teams using risk ratings as your foundation: you now have threat intelligence metrics alongside those ratings. You can better see what is actively happening to your vendors, not just a view of how well they maintain their defenses.
- For organizations running both programs today: your CTI and TPRM teams can work from the same platform, the same data, and the same prioritization framework.
3. What was just launched?
This release includes Recorded Future AI for Third-Party Risk, the Risk Priority Matrix, Compliance framework indicators, Threat Pressure, Enhanced CSP Rating, and Risk Comparison. Together they bring threat intelligence and risk ratings closer to a single workflow for security and GRC teams.
4. How is this different from the risk ratings tool we already use?
Ratings tools tell you how a vendor maintains their defenses. They do not tell you when those defenses are actively being tested. Customers have reported detecting vendor compromises through Recorded Future before the vendor notified them, sometimes before the vendor knew themselves. That pre-notification window is where most of the damage in third-party incidents usually happens.
5. Does this replace our existing TPRM workflow or integrate with it?
It integrates. Recorded Future connects with ServiceNow and Archer, so alerts and evidence route into the workflows your team already uses. Existing customers will find the capabilities they rely on are now available directly in the Recorded Future Intelligence Card.
6. Is every new capability available to all customers?
Availability varies by feature and license tier. Recorded Future AI for Third-Party Risk is available to Third-Party Intelligence and Third-Party Risk customers. The Risk Priority Matrix, Compliance indicators, Threat Pressure, Enhanced CSP Rating, and Risk Comparison are available to Third-Party Risk customers only. Speak to your account team for details specific to your configuration.
7. What is coming next?
More is coming. Upcoming releases will bring Daily Scanning, a full Security Profile, and Dark Web Playbook Alerts.
8. Where can I learn more?
You can request a demo to see how intelligence-driven third-party risk works in practice.

