Black Kite Vendor Cyber Risk

This integration is an offering provided through the Archer Exchange to enhance your existing Archer implementation. The Archer Exchange provides offerings to expand the use of Archer solutions into new business processes and address specific industry, geographic, regulatory, or technical requirements.

Black Kite provides a secure platform that spans the entirety of the third-party risk management life cycle for cyber risk professionals looking to quantify and maintain visibility of their risk exposure. This document tries to elaborate on the installation and setup process of the Black Kite Archer transporter data feed, including risk score fields and their counterpart descriptions that can be consumed.

Archer Exchange: With the Archer Exchange, the Archer team has created a broad selection of supplemental, value-added offerings to help you get your unique risk management program on the right path, right from the start. You can leverage the Archer Exchange offerings to expand the use of Archer solutions into new business processes and address specific industry, geographic, regulatory, or technical requirements.

Release notes

Release date 

Release version 

Notes 

August 2025

2024.11 (6.15.0.4.2)

  • Resolved an issue that caused the data feed to fail in Archer platform version 2025.02.01 (SaaS)

  • Re-signed JavaScript file.

New and changed features

  • Two more Black Kite vendor ratings are now supported with the data feed; Breach Index and Ransomware Index.

  • A notification text is added to the implementation guide to handle adding Black Kite CA certificate as a parameter to the data feed configuration.

  • A notification text is added to the implementation guide for JS timeout value suggestion with respect to the number of vendors monitored on the Black Kite on the IRM Archer Control Panel.

  • Support Archer SaaS environment

Fixed issues

Component

Issue ID

Description

Rate Limiting

1

Waiting periods are inserted in order to be aligned with the rate-limiting applied on the Black Kite ingress network.

Incorrect Compliance Naming Handling

2

Some of the compliance standard names conflict with the XPath queries Archer produces. Therefore, characters empty space and dots are replaced with character dash inside the compliance standard names before outputting.

Error Handling

3

Two error handlings are added to the JS code to handle expired Black Kite vendor licenses and incomplete vendor scan status.

Overview

Key features & benefits

With the offering, you will be able to:

  • Fetch and analyze various Black Kite cyber risk ratings of a Third-Party Profile under your portfolio, enhancing your 3rd party risk management.

  • Having cyber risk ratings inside the Archer platform, you will easily create workflows and reports.

Prerequisites (ODA and system requirements)

Components

Prerequisites

Archer Solution Area(s)

Archer Third Party Governance

Archer Use Case(s)

Archer Third Party Management

Archer Applications

Third Party Catalog

Uses Custom Objects

No

Requires On-Demand license

No

Archer requirements

Archer 2024.11 and later

Partner/Vendor Requirements

Valid Black Kite License is required. Additional fees may apply. Contact support@blackkite.com for more information.

Compatible use cases and applications

Application

Use case

Primary purpose(s) of the relationship

Third Party Profile

Third-Party Risk Management

Helps you track your third parties, manage the relationships, identify risks early, monitor their performance, and promptly address issues that arise.

  • You can incorporate Black Kite generated technical, compliance and financial risk ratings of a vendor into a vendor you manage, living on your Archer instance.

  • With provided links, you can also analyze more about the vendor being managed on your Black Kite tenant’s portfolio.

Components

Architecture diagram

Here are the context scope and container/component diagrams to understand the data feed integration that Black Kite provides on the Archer Platform.

The above figure depicts the high-level diagram of Black Kite’s Vendor Cyber Risk integration for the Archer Platform.

The above figure shows more detailed component level design. The architecture is quite simple. The persona is a valid both Black Kite and Archer platform user. After fetching the Black Kite’s DF package, the Black Kite API URL and API-Key for an authorized access, the user creates custom fields on the TPP application on Archer Platform and sets the layout.

Then the user creates and configures the JS Data Feed on the Archer Platform.

Depending on the configuration the JS Data Feed runs and synchronizes the custom fields on the TPP layout. After successful sync, when the user clicks on any matched vendor on the Third-Party Management module, the synced Black Kite provided rating values will appear on the Archer Platform.

Applications

The offering doesn’t contain an application. It’s a basic data feed integration targeting the Archer Third Party Profile core application.

For the list of Black Kite fields please refer the Impacted fields section.

Impacted fields

The following fields are custom Archer target fields that you may only create a subset of it under your Archer instance in Third Party Profile application and consume their values from their Black Kite’s counterpart source fields.

Archer target field

Black Kite source field

Black Kite Last Status

LastStatus

Black Kite Company Name

CompanyName

Black Kite Domain

CompanyDomain

Black Kite Dashboard Link

DashboardLink

Black Kite FocusTags

FocusTags

Black Kite Technical Rating (%)

RiskScore_GradeOver100

Black Kite Technical Rating Letter

RiskScore_GradeLetter

Black Kite Ransomware Index (RSI)

RansomwareIndex

Black Kite Data Breach Index (DBI)

BreachIndex

Black Kite Technical Dashboard Link

N/A

BK Patch Management

PatchManagement_GradeOver100

BK DNS Health

DNSHealth_GradeOver100

BK Email Security

EmailSecurity_GradeOver100

BK Application Security

ApplicationSecurity_GradeOver100

BK CDN Security

CDNSecurity_GradeOver100

BK DDoS Resiliency

DDoSResiliency_GradeOver100

BK Website Security

WebsiteSecurity_GradeOver100

BK Network Security

NetworkSecurity_GradeOver100

BK SSL/TLS Strength

SSLTLSStrength_GradeOver100

BK Brand Monitoring

BrandMonitoring_GradeOver100

BK Credential Mgmt.

CredentialMgmt_GradeOver100

BK IP Reputation

IPReputation_GradeOver100

BK Hacktivist Shares

HacktivistShares_GradeOver100

BK Fraudulent Apps

FraudulentApps_GradeOver100

BK Social Network

SocialNetwork_GradeOver100

BK Fraudulent Domains

FraudulentDomains_GradeOver100

BK Information Disclosure

InformationDisclosure_GradeOver100

BK Web Ranking

WebRanking_GradeOver100

BK Attack Surface

AttackSurface_GradeOver100

Black Kite Compliance Rating (%)

ComplianceValueAvgOver100

Black Kite Compliance Confidence (%)

ComplianceConfidenceAvgOver100

Black Kite Compliance Completeness (%)

ComplianceCompletenessAvgOver100

Black Kite Compliance Dashboard Link

N/A

Black Kite FAIR Annualized ($)

FairAnnualLossExposureAvg

Black Kite FAIR Min ($)

FairAnnualLossExposureMin

Black Kite FAIR Max ($)

FairAnnualLossExposureMax

Black Kite FAIR Loss Magnitude ($)

FairLossMagnitude

Black Kite FAIR Loss Event Frequency

FairLossEventFrequency

Black Kite FAIR Dashboard Link

N/A

Personas and Access Roles

The following table describes the functions that make up the application’s organization roles. Depending on the organization of your company, these functions and responsibilities may vary.

Function

Description

Configuration

  • A valid user with DataFeed creation/configuration role on the Archer portal (possibly sysadmin) and Control Panel.

Auditor

  • A valid user having access to Third Party Management application (User Groups: Third Party Management, Third Party: Read Only, Third Part: Administrator, etc).

Installing Black Kite Vendor Cyber Risk Package

Installing Black Kite Vendor Cyber Risk Integration

Using Black Kite Vendor Cyber Risk Integration

The Data Feed that the Black Kite provides synchronizes the cyber risk ratings of a matching vendor on the Third Party Profile page.

Assume you both have defined google.com as both a vendor in Black Kite and on Archer. In order to see cyber risk ratings of Google just open vendor page as shown in Figure below.

Figure – Synchronized ratings on the TPP page

Let’s say that you are sure that you monitor the same vendor both on the Archer and Black Kite but no data is presented on the Black Kite related fields. If you used ‘Black Kite Domain’ as the Key Field Definition instead of the Third Party Name, then you can Edit the vendor and update the Black Kite Domain field value to match the vendor you monitor on the Black Kite portal. After the update and next successful synchronization, the values will be synchronized and appear on the Archer page.

Figure – Using Black Kite Domain as the Key Field under the Data Feed settings

The default setting for the Key Field is ‘Third Party Name’. When you use ‘Black Kite Domain’ instead, just like above, the matching of vendors will be done using the domains, not the name of the vendor.

Certification environment

Date tested: August 2025

Product name

Version information

Operating system

Archer Suite

2024.11.02, 2025.02.01, 2025.08

Virtual Appliance

Black Kite

NA

NA