
Independent supplier selection and transition
Select new IT service provider
Kynexis Information Security guides you from the first decision question and the program of demands to comparison, contracting, transition and assurance. We do not sell IT management, licenses or cloud environments and do not receive commission from suppliers. That's what keeps your interest at the top of the board.
- agreements are not being properly honoured and you lack reliable reports on performance and security.
- The current environment has grown historically and responsibilities are divided among several suppliers.
- You want to extend, renegotiate or switch, but you lack an objective comparison framework.
- Migration seems necessary, while knowledge, access, documentation and continuity remain strong among the current party.
What are the risks? Without clear demands and independent direction, you can compare offers and promises. Important risks related to access, security, recovery, data ownership and departure will only be visible during an incident or migration.
Our promise of service
Independent guidance of decision-making request for a working transfer
We connect organizational goals, technical principles, information security, continuity and contractual agreements in one selection process. The choice remains yours; Kynexis Information Security ensures that the balancing is followable and feasible.
- No sale interest or supplier commission
- Comparison of requirements, evidence and risk
- Attention to contract, exit and transition
Supplier Selection
What is Supplier Selection?
Kynexis Information Security guides you from the first decision question and the program of demands to comparison, contracting, transition and assurance. We do not sell IT management, licenses or cloud environments and do not receive commission from suppliers. That's what keeps your interest at the top of the board.
When does this service fit?
When continuing, renegotiating or switching is a serious choice
This service is appropriate when cooperation is no longer self-evident, a contract expires, the organisation changes significantly or an independent re-evaluation is necessary. An audit does not automatically lead to a change. If improvement is feasible and the supplier cooperates transparently, more stringent agreements and re-examination can be sensible. When quality, trust and cooperation are structurally inadequate, a careful selection and transition process helps to reduce risks.
Selection Framework
Assessing the supplier on what your organisation really needs
The exact requirements vary from one organisation to another. In any case, we assess services, technology, security, continuity, cooperation and transferability in coherence.
Services and accessibility
Scope, service windows, support, escalation, response times and the daily collaboration model.
Engineering and architecture
Workplaces, cloud, network, identity, applications, links, standardisation and future changeability.
Information security
Access, management accounts, logging, patching, vulnerabilities, incident response and demonstrable technical operation.
Continuity and recovery
Backup responsibility, recovery targets, restoration tests, redundancy, diversion and support during disruptions.
Governance and reporting
Rolls, ownership, consultation structure, KPIs, enhancement actions, assurance and independent review.
Contract and exit
Data ownership, access, documentation, subcontractors, audit law, price changes, cancellation and transfer.
Seven moments of decision
A selection process that includes transition and assurance
A good question is important, but most risks arise in the event of unclear assumptions, contract details or actual transfer. Therefore the guidance covers the entire route.
Initiation and decision framework
Identify why you reconsider, what problems are detectable and who decides on the outcome.
Current situation
In fact, it is the processes, systems, suppliers, contracts, dependencies and bottlenecks that are identified.
Programme of requirements
Formulate must-haves, desired improvements, security requirements, service levels and transition border conditions.
Market and demand-out
Identifying appropriate suppliers and submitting the same complete, verifiable question to each party.
Review and Choose
Compare offers, calls, references, evidence and risks with a transparent score matrix.
Contract
Making agreements on performance, security, data, changes, audit, liability and exit concretely record.
Transition and collateralisation
Transfer plans, control dependencies, review acceptance criteria and periodically evaluate cooperation.
Your result
A defensible choice of suppliers and a controlled start
You do not receive standard advice for one preferred supplier. You will be given a well-founded decision-making file that will allow the board and management to see what requirements are set, how suppliers have been compared, what risks have been accepted and how contract and transition are controlled.
- Framework for decision and overview of current dependencies
- Programme of requirements with must-haves and assessment criteria
- Structured demand-out and transparent score matrix
- Risk and reference assessment of promising suppliers
- Dealers for contract, SLA, security and exit
- Transition plan with responsibilities and acceptance criteria
- Establishment for consultation, reporting and periodic evaluation
Independent role
Kynexis advises without any interest in the outcome
Kynexis Information Security does not provide IT management, licenses, hardware or cloud environments and does not receive a commission from suppliers. This prevents selection from being controlled by margin or own management proposition.
Decides and retains ownership
the board and management determine ambitions, risk appetite and final choice.
Researches, compares and guides
Kynexis Information Security makes demands, evidence, differences and risks visible and supports decision-making and transition.
Independent securing roleShows appropriateness and implementation
Candidates support how they organise services, security, continuity, cooperation and transfer.
How we work
This will create a controlled cooperation
- 01
Defining the cause and governance
Target, decision-makers, timeline, budget frameworks and possible scenarios.
- 02
Examine the current situation
Assess contracts, technology, processes, experiences and supplier dependencies.
- 03
Establish requirements and assessment model
Translate functional, technical, organisational and security requirements into testable criteria.
- 04
Guide Question
Inform suppliers, structure questions and provide comparable answers and evidence.
- 05
Review and advise
Scoring offers, calls, references and risks and administratively indicating the advantages and disadvantages.
- 06
Review contract agreements
SLA, security, restoration, data, liability, subcontractors and exit in coherence.
- 07
Transition and assurance
Monitoring transfer, acceptance, documentation, access and initial evaluation rhythm.
Choose based on your question
Which form of research suits your decision-making needs?
The routes differ in purpose, depth and the type of support you need.
Cyber Security Baseline Assessment
Compact and broad starting point for overview and priorities.
View Cyber Security Baseline Assessment →Cybersecurity Assessment
Focused floor for improvement and investment choices.
View Cybersecurity Assessment →Cyber Security Audit
Independent review of predefined criteria with traceable evidence and audit conclusion.
View Cyber Security Audit →ISO 27001 GAP Analysis
Standard diagnosis for a working and demonstrable ISMS.
View ISO 27001 GAP Analysis →NIS2 GAP Analysis
Legal diagnosis for duty of care, governance and chain.
View NIS2 GAP Analysis →NIS2 audit
Evidence-based testing of detectable NIS2 control.
View NIS2 audit →Discuss your current situation, the contract moment and the decisions needed to continue, renegotiate or change carefully.
Discuss your supplier's question →Frequently Asked Questions
Practical answers on Supplier Selection
When is it wise to select a new IT service provider?
If agreements are not met in a structural manner, transparency is lacking, the service no longer fits or a contract moment gives rise to re-evaluation. Sometimes, continuing with sharper agreements and independent re-examination is more sensible than switching.
Does Kynexis help if we might stay with the current supplier?
Yes. The trajectory can compare scenarios: continue unchanged, make improvements, distribute or change the service. The facts and risks determine the appropriate route.
Does Kynexis have preferred partners or does Kynexis receive commission?
No. Kynexis Information Security does not sell IT management, licenses or cloud environments and does not receive commission from suppliers. Specialist knowledge can be targeted, but the advisory role remains independent.
What is in a program of demands?
Scope, user and process needs, technical principles, security, continuity, support, reporting, price structure, contract terms, transition and exit.
Does Kynexis also guide the transition?
Yes. The guidance can go through planning, access transfer, documentation, data, acceptance tests, recovery controls and the initial evaluation of the new cooperation.

When choosing suppliers, technology, price, arrangement, transparency, repairability and portability count. Together they determine how much direction your organisation really keeps.