Guide Risk Management

Supply Chain Cyber Security: How to Assess and Manage Supplier Risk

Attackers now reach many organisations through a supplier: an IT provider, an outsourced helpdesk, a software vendor. Map and tier your suppliers, ask the critical ones for evidence, and write security into the contract. Depending on your sector and what the supplier handles, NIS2, DORA, ISO 27001 and UK GDPR may already require it.

9 October 2026
12 min read
Key Takeaways
  • Verizon's 2026 Data Breach Investigations Report found a third party involved in 48% of the breaches it analysed, up from 30% a year earlier.
  • Only 15% of UK businesses review the cyber risk posed by their direct suppliers, and 6% look at their wider supply chain (Cyber Security Breaches Survey 2025/2026).
  • Start by tiering suppliers on two questions: what can they access, and what stops if they go down? Put your assurance effort into the top tier.
  • Write security into the contract: incident notification times, minimum controls, a right to audit, and data return on exit.
  • NIS2, DORA, ISO 27001 and UK GDPR each require some form of supplier risk management from the organisations in their scope. The UK Cyber Security and Resilience Bill, still before Parliament, would bring managed service providers into regulation and let regulators designate critical suppliers.

Why supplier risk is rising

An attacker who breaks into one IT provider or software vendor can reach dozens of its customers through access the provider already holds.

Verizon's 2026 Data Breach Investigations Report counted a third party in 48% of the breaches it analysed. Two years earlier the figure was 15%. Verizon counts a breach as third-party when it involves partner infrastructure or a flaw in third-party software, so the risk runs through your software stack as well as your service providers.

48%
of breaches analysed in the Verizon 2026 Data Breach Investigations Report involved a third party, up from 30% in the 2025 edition

The government's Cyber Security Breaches Survey 2025/2026 found that 15% of businesses had reviewed the cyber risks posed by their immediate suppliers. Medium businesses reached 30% and large businesses 48%. Only 11% of businesses required suppliers to hold any security standard or accreditation, and 3% asked for Cyber Essentials.

Lessons from M&S and JLR

Two 2025 incidents hit from opposite ends of the supply chain.

Marks & Spencer: the attacker came in through a third party. M&S chairman Archie Norman told MPs in July 2025 that the April attack started with social engineering involving a third party. The attackers posed as one of the 50,000 people who work with M&S and persuaded a third party to reset a password. The Cyber Monitoring Centre (CMC) treated the M&S and Co-op attacks as one event and estimated the total cost at £270m to £440m.

Jaguar Land Rover: the damage spread down the supply chain. The attack halted JLR's production from 1 September 2025 for around five weeks. The CMC estimated the cost to the UK economy at £1.9bn and counted around 5,000 affected organisations, most of them in its supply chain. The government stepped in with a £1.5bn loan guarantee to steady the supply chain.

The lesson for smaller businesses

You depend on suppliers who can let attackers in, and larger customers depend on you. Expect those customers to send harder security questions, and add a major customer outage to your risk register as a cash-flow risk.

Where supplier risk comes from

Supplier risk takes four forms. Most suppliers carry one or two of them; your critical suppliers may carry all four.

  • Access: the supplier can log in to your systems. Managed IT providers, outsourced helpdesks and remote support tools sit here. An attacker who compromises them inherits their access.
  • Data: the supplier holds your customer, employee or financial data. Payroll providers, CRM platforms and marketing agencies sit here. If they suffer a breach involving your personal data, UK GDPR requires them to tell you without undue delay. You then decide whether to report it to the ICO, within 72 hours of becoming aware of it.
  • Software: code you did not write runs inside your environment. Attackers can use a compromised update or an unpatched vendor flaw to get into your environment.
  • Dependency: your operations stop if the supplier stops. Cloud platforms, payment processors and logistics partners sit here, even if they never touch your data.

Step 1: Map your suppliers

In most organisations nobody holds the full supplier list. Finance knows who gets paid, IT knows who has remote access, and teams sign up for SaaS tools that neither department sees.

Build one register. Pull accounts payable records for the last 12 months, export the list of external accounts and remote access tools from your identity platform, and check your SSO and expense data for SaaS subscriptions. For each supplier, record what they provide, who owns the relationship internally, what systems they can access, and what data they hold.

Include your suppliers' key subcontractors where you know them. Your managed service provider's remote management platform is part of your supply chain, even though you never signed a contract with its vendor.

Step 2: Tier by criticality

You cannot audit every supplier in depth, and you should not try. Score each one on access, data and dependency, then put your assurance effort where the score is highest. For dependency, ask how quickly you could replace the supplier, or keep operating without it.

TierTypical suppliersAssurance level
Tier 1: CriticalManaged IT and security providers, core cloud platforms, suppliers holding sensitive personal data, single-source operational suppliersDetailed questionnaire, evidence review (certificates, pen test summaries), contract security schedule, annual review
Tier 2: ImportantBusiness applications with limited data, professional services firms with document access, secondary logisticsShort questionnaire, certification check, standard contract clauses, review every two years
Tier 3: LowSuppliers with no system access, no personal data, and easy replacementStandard terms, no assessment beyond onboarding

Keep Tier 1 short enough that you can review each supplier in depth every year. If most of your list lands there, check whether you scored too cautiously.

Step 3: Assess your critical suppliers

Ask for evidence. "Do you take security seriously?" tells you nothing. "Send us your current Cyber Essentials Plus certificate" gets you a document, or a gap you can act on.

The NCSC publishes a free set of supplier assurance questions aimed at SMEs. For Tier 1 suppliers, make sure your questionnaire covers at least these:

  • Which certifications do you hold, and what is in scope? An ISO 27001 certificate that covers one office and excludes the service you buy proves little. Ask for the scope statement.
  • How do your staff access our systems? Look for named accounts, MFA on every login, and access granted only for the task at hand.
  • How do you verify identity before resetting a password or MFA method? Attackers got into M&S by talking a third party into a password reset.
  • How quickly will you tell us about an incident that affects our data or service, and who will contact us?
  • Which subcontractors process our data or access our systems, and where are they based?
  • When did you last test your backups and your incident response plan?
  • Can you share a summary of your most recent penetration test and the status of its findings?

Keep it short enough that a supplier can finish it in an afternoon, and ask for documents on the questions that matter most.

Certificates are a starting point

Cyber Essentials, ISO 27001 and SOC 2 reports tell you a supplier has a baseline. They do not tell you how the supplier protects your account. For your most critical suppliers, ask how their controls apply to the service they deliver to you.

Step 4: Write security into the contract

Once a contract is signed, your leverage drops. Agree security terms before signature, or at renewal for existing suppliers. For Tier 1 suppliers, attach a security schedule that covers:

  • Minimum controls: MFA on all access to your systems and data, patching timeframes, encryption, and maintained certifications.
  • Incident notification: a fixed window, such as 24 hours from detection, and a named contact on both sides. If you fall under NIS2 or DORA, align the window with your own reporting deadlines.
  • Right to audit: the right to assess the supplier's controls, or to receive independent audit reports in place of an on-site audit.
  • Subcontractors: notice before the supplier adds a subcontractor that handles your data, with the same obligations flowing down.
  • Exit: return and verified deletion of your data, removal of all access, and enough transition support that you can switch provider.

Where the supplier processes personal data for you, UK GDPR Article 28 already requires a written processing agreement with set terms. Check that yours exists and matches what the supplier actually does.

Step 5: Control supplier access

Technical controls limit what an attacker can do with a supplier's access, whatever the contract says.

  • Give every supplier engineer a named account. With shared logins you cannot trace who did what.
  • Enforce MFA on all supplier access, including remote management tools and VPNs.
  • Grant the minimum access needed, and time-limit privileged access where your platform supports it.
  • Log supplier sessions and review them. Alert on supplier logins outside agreed hours.
  • Remove access the day a supplier contract or an individual engagement ends. That covers named accounts, VPN access, remote management tools, API keys, service accounts and any credentials the supplier’s subcontractors hold.

Treat your managed service provider's tools as part of your attack surface. A compromised remote monitoring platform gives an attacker the same reach as your provider's engineers. A zero trust approach limits how far that access extends.

Step 6: Monitor, reassess and plan for failure

A supplier that passed assessment last year may have changed ownership, lost key staff or suffered a breach since. Review Tier 1 suppliers at least annually, and again after any of these triggers: a reported incident, a merger or acquisition, a major change in the service, or a lapsed certification.

Plan for the day a critical supplier goes down. For each Tier 1 supplier, answer three questions in your incident response plan: how will we know, what do we switch off, and how do we keep operating? Some JLR suppliers warned they could collapse without government support. Keep data exports and contact lists somewhere that does not depend on the failed supplier. Test a data export at least once: check that you can open it and load it into another system. A contract clause promising your data back does not make the file usable.

What the regulations require

FrameworkSupplier requirementWho it affects
NIS2 Article 21(2)(d) Supply chain security, including security in relationships with direct suppliers and service providers. Entities must consider each supplier's vulnerabilities and security practices. EU essential and important entities. UK businesses that supply them will see these duties flow down through contracts.
UK Cyber Security and Resilience Bill Would bring medium and large managed service providers into the NIS regime and let regulators designate critical suppliers to regulated organisations. MSPs, data centres, and suppliers to operators of essential services. The Bill is currently in the House of Lords.
DORA Articles 28 to 30 ICT third-party risk strategy, a register of information covering all ICT contracts, and mandatory contract terms. EU financial entities and their ICT providers. In force since 17 January 2025.
ISO 27001:2022 Annex A 5.19 to 5.23 Supplier relationships, security in supplier agreements, ICT supply chain, monitoring of supplier services, and cloud services. Any organisation certified or seeking certification.
UK GDPR Article 28 Use only processors that give sufficient guarantees, under a written contract with set terms. Any organisation that shares personal data with a supplier.

One supplier risk process covers all five if you design it with the strictest framework in mind. For more detail, see our NIS2 compliance guide and our article on the Cyber Security and Resilience Bill.

When you are the supplier

Expect more security questionnaires from your customers, especially from those in finance, healthcare and critical infrastructure. Many of them must assess their suppliers under NIS2, DORA or their sector regulator. Build the answers once and reuse them:

  • Get Cyber Essentials at minimum, and Cyber Essentials Plus if you hold customer data or access customer systems. Our comparison of Cyber Essentials and ISO 27001 covers which suits you.
  • Keep a standard security pack: certificates with scope statements, a summary of your security controls, your incident notification process, and a list of subprocessors.
  • Name one person to own customer security questions, so answers stay consistent across sales and delivery.

Many large buyers score supplier security during procurement, so a fast answer backed by documents helps you win the work.

Sources

About the author
Ryland Deakin
Lead Consultant, Cyvra · CISM · CompTIA Security+ · MCP

Ryland has delivered cybersecurity, compliance, and IT management programmes for regulated organisations across the UK and the Netherlands for over 20 years. View full profile

Frequently asked questions

What is supply chain cyber security?

Supply chain cyber security is the process of managing the risks that come from suppliers who can access your systems, hold your data, supply your software, or keep your operations running. It covers identifying those suppliers, assessing their security, setting contract terms, controlling their access, and planning for their failure.

How do you assess a supplier's cyber security?

Tier your suppliers first, then focus on the critical ones. Send a short questionnaire that asks for evidence: certificates with scope statements, how staff access your systems, incident notification times, and recent test results. The NCSC publishes a free set of supplier assurance questions you can start from.

Should we require suppliers to hold Cyber Essentials?

For suppliers with access to your systems or data, yes. Cyber Essentials is a low-cost baseline and Cyber Essentials Plus adds independent testing. Only 3% of UK businesses currently require it of suppliers, according to the Cyber Security Breaches Survey 2025/2026, against 26% of large businesses.

Does the Cyber Security and Resilience Bill affect our suppliers?

It may. The Bill brings medium and large managed service providers into the NIS regime and lets regulators designate critical suppliers to regulated organisations. Once the Bill becomes law, a designated supplier faces security and incident reporting duties even if it would otherwise sit outside scope.

Supply Chain Cyber Security

Know which suppliers could take you down

We map your suppliers, assess the ones that matter, and give you contract terms and access controls you can put in place this quarter.

Disclaimer: This article is for general informational purposes only and does not constitute legal, regulatory, or professional advice. Cyvra makes no warranty as to the accuracy or completeness of this content, which may not reflect the most current regulatory developments. Readers should seek independent legal and regulatory advice appropriate to their specific circumstances. Cyvra accepts no liability for any loss arising from reliance on this content.