To protect your organisation’s critical assets from security threats, you implement measures to tighten and secure your cyber defences. But do you know if your supply chain are doing the same?
Each time you onboard a supplier, you add potential risks to your business information. Whether that be a manufacturer, accountant, or even cleaner, each supplier has the potential to damage your business.
Onboarding Suppliers
With increasing demand and competition pushing organisations to expand further and deliver quickly, it is no surprise that organisations are becoming increasingly dependent on suppliers to streamline processes and enter new markets. But to protect yourself, you need to understand the types of risk associated with each of your suppliers.
Do you have robust contracts and service level agreements in place? Have you ensured your suppliers are onboarded correctly, with the appropriate policies outlining the type and amount of information that can be accessed? How often are you revisiting suppliers after they’re onboarded? And what processes do you hold to manage supplier risks?
Many organisations believe responsibility transfers to suppliers, but you remain accountable for the way a supplier handles your information, and the associated risks. That’s why ensuring correct security practices are used across your supply chain is crucial for the security of your business. Checking your supply chain security cannot just be done once a year anymore.
Threat actors can target your supply chains to gain access to your information. The IBM 2026 Threat Intelligence Index reported that compromises within supply chain and third parties have almost quadrupled in the last 5 years, making them prime targets for threat actors, especially if your supplier works with other organisations, and they could access yours and others’ information within a single attack.
Therefore, you need to have confidence your suppliers are doing all they can to keep your information safe. Even with tightened cyber security, have you considered their physical security? Are your suppliers checking the identity of contract workers, or other staff? Do they have control on who enters and leaves the building? And are the technologies they use secure and running with the latest software update?
To properly manage your supplier security, your organisation should follow a supplier onboarding policy which includes:
By following an onboarding process, you can manage where information is, who has access to it, and be confident that your suppliers know what security controls to follow, to keep your business information secure.
Offboarding Suppliers
When your relationship with a supplier ends, there are data access and contractual obligations to manage and resolve, as well as other dependencies that may be outstanding. Careful consideration should be taken, as any unmanaged risks could result in data breaches, unauthorised access, or reputational damage and financial loss.
The most important consideration is access control. During your working relationship, your supplier may have access to key information, IT systems and physical sites, which need to be quickly revoked to prevent misuse or unauthorised access. The data your suppliers hold may be highly confidential, and lead to significant breaches or reputational damage if not removed or deleted effectively. This includes any company equipment given to the supplier, such as laptops and hard drives, which need to be accounted for and returned to you. Relevant data should also be backed up to prevent loss during the process.
Alongside these, you should also be aware of any compliance and human factors which may impact your offboarding, including abiding by compliance requirements, and malicious intent or third-party risks. Offboarding needs to account for all these risks, so clear communication and records of each dependency should be documented and monitored for your reference as they are removed.
Assessing Your Supply Chain
There is a lot to consider when it comes to supply chain security, so we know it can be overwhelming. We have worked with many organisations to address this, and depending on the security requirements of your business, there are frameworks that can help you create a structured approach to evaluating your supplier security.
ISO 27001 is a globally recognised, risk-based standard that takes a business wide approach. It highlights the importance of integrating third‑party risk management with your overall information security objectives.
The IASME Cyber Assurance standard consists of cyber security controls and practices, organised into fourteen themes. In theme 2, it asks organisations to set clear service level agreements and contracts with third party suppliers, to define security expectations. Agreements should be based on risks assessments, and regularly reviewed in line with security needs.
The Defence Cyber Certification has been developed by IASME and the MOD to provide assurance that third parties working in your supply chain meet the security requirements of the project they are working on. It is a comprehensive, organisation-wide cyber security certification for suppliers in the defence sector.
If you would like to have a chat about managing your supply chain security, please get in touch with our team.
