According to the UK Government Cyber Security Breaches Survey 2022, “only 13% of businesses assessed the risks posed by their immediate suppliers, with organisations saying that cyber security was not an important factor in the procurement process.”
When it comes to Cyber Security, the majority of our efforts are usually focused on what we can do internally to protect our organisations. However, as the finding above demonstrates, supply chains are a key area of consideration when it comes to minimising your organisation's attack vectors.
As supply chains grow, evolve and become more complex, the need to secure your supply chain increases. The larger and more complex your supply chain becomes, the easier it is for vulnerabilities to be introduced and the harder it becomes to detect them.
To provide clearer oversight of your supply chain and help you establish control, SES has laid out a simple 4 step process:
It is important to understand the risk your external suppliers present to minimise it. Some questions to answer include:
Once you have an in-depth understanding of your supply chain, you will be able to analyse where the potential risks lie and gain control. This will involve:
Setting and documenting minimum security standards for your suppliers to adhere to will help you maintain your security posture and ensure you remain compliant with relevant regulations.
It is essential that your suppliers, along with anyone they subcontract to understand their responsibility to provide appropriate protection for your information, products and services and the implications of failing to do so. Producing guidelines for the suppliers you intend to onboard will provide them with a security benchmark they need to achieve to work with you. Prospective suppliers should also provide evidence of their approach to security and their ability to meet the minimum security requirements you have established.
In addition to providing clear guidelines on security standards for organisations which are part of your supply chain, it is also important to check that these arrangements are being followed correctly. This can be achieved in several ways.
As your organisation grows and your supply chain evolves, your security must evolve alongside it.
Whilst it is important to allow time for your current suppliers to make the necessary improvements to their security to avoid ruining existing relationships. It is also important that your suppliers provide timescales and plans on how they intend to make the required changes. In some instances, they may need your assistance to help them implement the necessary changes.
Provide advanced warning of any changes you are planning to make to your products and services and encourage existing suppliers to continue improving their security arrangements, emphasising how this might enable them to compete for and win future contracts with you. This will also help you to grow your supply chain and choice of potential suppliers.
This article is intended as a simple guide which will help you improve the security of your organisation's supply chain and improve your organisation's overall security against malicious threats. To speak to our specialists about how you can implement the points featured in this article or discuss any other security queries you may have, please get in touch to speak to one of our specialists.
© SES Secure Limited and ses-escrow.co.uk, 2022. Unauthorised use and/or duplication of this material without express and written permission from this site’s author and/or owner is strictly prohibited. Excerpts and links may be used, provided that full and clear credit is given to SES Secure Limited and ses-escrow.co.uk, with appropriate and specific direction to the original content