Supply chain attack: managing supplier cyber risk
By Matt Buckley
How supply chain attacks happen
- A software update from a trusted vendor is tampered with before release
- A managed service provider's remote access is used to reach its clients
- A smaller supplier with weak controls is used to send convincing invoice fraud
- Shared data held by a supplier is stolen from the supplier's systems
Why this is a procurement issue
Security teams can protect the systems they run. They cannot directly control a supplier's systems. What procurement controls is who gets onboarded, what they must commit to in contract and how they are checked over time. That is where most of the risk reduction sits.
Controls to build into sourcing
- Tier suppliers by the access and data they hold, not only by spend
- Ask for Cyber Essentials or equivalent assurance for higher-risk suppliers
- Include security, incident notification and audit clauses in contracts
- Limit supplier access to what is needed and remove it at contract end
- Verify bank detail changes by phone before paying, to stop invoice fraud
Linking cyber risk to supply chain resilience
Supplier cyber risk sits alongside financial, geographic and operational risk. The same supplier risk register should hold all of them. Our supply chain resilience guide and supplier performance guide cover the wider framework.
Where Caventis fits
Caventis is not a cyber security firm. We help businesses build supplier segmentation, contract terms and onboarding controls into procurement, and work alongside your IT or security advisers on the technical assessment.
Frequently asked questions
What is a supply chain attack?
A cyber attack that reaches a target organisation through a trusted supplier, such as a software vendor or IT service provider.
How can procurement reduce supply chain attack risk?
By tiering suppliers by risk, requiring security assurance and contract clauses, limiting access and checking suppliers over the life of the contract.
References
Every figure cited above is drawn from the independent sources below. Numbers in square brackets in the text link to the matching source.
- Supply chain security guidance — National Cyber Security Centre
- Cyber Essentials — National Cyber Security Centre
- Cyber security breaches survey — GOV.UK
Related insights
More practical reading on procurement, cost and supply chain.
Strong sectors, the UK-Vietnam trade agreement and what to check when importing from Vietnam.
Strong sectors, trade rules and supplier checks for importing from India to the UK.
Sectors, trade rules and when nearshoring to Turkey beats sourcing from Asia.
Ready to find the savings hidden in your business?
Book an introductory call with Caventis to discuss your requirements.