Insight \u00b7 Supplier risk

Supply chain attack: managing supplier cyber risk

A supply chain attack is a cyber attack that reaches a business through one of its suppliers rather than directly. The attacker compromises a software vendor, IT provider or other trusted third party, then uses that access to reach the customer. For procurement teams this turns supplier selection and contract terms into a security control, not only a commercial one.

By Matt Buckley

How supply chain attacks happen

  • A software update from a trusted vendor is tampered with before release
  • A managed service provider's remote access is used to reach its clients
  • A smaller supplier with weak controls is used to send convincing invoice fraud
  • Shared data held by a supplier is stolen from the supplier's systems

Why this is a procurement issue

Security teams can protect the systems they run. They cannot directly control a supplier's systems. What procurement controls is who gets onboarded, what they must commit to in contract and how they are checked over time. That is where most of the risk reduction sits.

Controls to build into sourcing

  • Tier suppliers by the access and data they hold, not only by spend
  • Ask for Cyber Essentials or equivalent assurance for higher-risk suppliers
  • Include security, incident notification and audit clauses in contracts
  • Limit supplier access to what is needed and remove it at contract end
  • Verify bank detail changes by phone before paying, to stop invoice fraud

Linking cyber risk to supply chain resilience

Supplier cyber risk sits alongside financial, geographic and operational risk. The same supplier risk register should hold all of them. Our supply chain resilience guide and supplier performance guide cover the wider framework.

Where Caventis fits

Caventis is not a cyber security firm. We help businesses build supplier segmentation, contract terms and onboarding controls into procurement, and work alongside your IT or security advisers on the technical assessment.

Frequently asked questions

What is a supply chain attack?

A cyber attack that reaches a target organisation through a trusted supplier, such as a software vendor or IT service provider.

How can procurement reduce supply chain attack risk?

By tiering suppliers by risk, requiring security assurance and contract clauses, limiting access and checking suppliers over the life of the contract.

References

Every figure cited above is drawn from the independent sources below. Numbers in square brackets in the text link to the matching source.

  1. Supply chain security guidance — National Cyber Security Centre
  2. Cyber Essentials — National Cyber Security Centre
  3. Cyber security breaches survey — GOV.UK

Ready to find the savings hidden in your business?

Book an introductory call with Caventis to discuss your requirements.