- Verizon's 2026 Data Breach Investigations Report found a third party involved in 48% of the breaches it analysed, up from 30% a year earlier.
- Only 15% of UK businesses review the cyber risk posed by their direct suppliers, and 6% look at their wider supply chain (Cyber Security Breaches Survey 2025/2026).
- Start by tiering suppliers on two questions: what can they access, and what stops if they go down? Put your assurance effort into the top tier.
- Write security into the contract: incident notification times, minimum controls, a right to audit, and data return on exit.
- NIS2, DORA, ISO 27001 and UK GDPR each require some form of supplier risk management from the organisations in their scope. The UK Cyber Security and Resilience Bill, still before Parliament, would bring managed service providers into regulation and let regulators designate critical suppliers.
Why supplier risk is rising
An attacker who breaks into one IT provider or software vendor can reach dozens of its customers through access the provider already holds.
Verizon's 2026 Data Breach Investigations Report counted a third party in 48% of the breaches it analysed. Two years earlier the figure was 15%. Verizon counts a breach as third-party when it involves partner infrastructure or a flaw in third-party software, so the risk runs through your software stack as well as your service providers.
The government's Cyber Security Breaches Survey 2025/2026 found that 15% of businesses had reviewed the cyber risks posed by their immediate suppliers. Medium businesses reached 30% and large businesses 48%. Only 11% of businesses required suppliers to hold any security standard or accreditation, and 3% asked for Cyber Essentials.
Lessons from M&S and JLR
Two 2025 incidents hit from opposite ends of the supply chain.
Marks & Spencer: the attacker came in through a third party. M&S chairman Archie Norman told MPs in July 2025 that the April attack started with social engineering involving a third party. The attackers posed as one of the 50,000 people who work with M&S and persuaded a third party to reset a password. The Cyber Monitoring Centre (CMC) treated the M&S and Co-op attacks as one event and estimated the total cost at £270m to £440m.
Jaguar Land Rover: the damage spread down the supply chain. The attack halted JLR's production from 1 September 2025 for around five weeks. The CMC estimated the cost to the UK economy at £1.9bn and counted around 5,000 affected organisations, most of them in its supply chain. The government stepped in with a £1.5bn loan guarantee to steady the supply chain.
You depend on suppliers who can let attackers in, and larger customers depend on you. Expect those customers to send harder security questions, and add a major customer outage to your risk register as a cash-flow risk.
Where supplier risk comes from
Supplier risk takes four forms. Most suppliers carry one or two of them; your critical suppliers may carry all four.
- Access: the supplier can log in to your systems. Managed IT providers, outsourced helpdesks and remote support tools sit here. An attacker who compromises them inherits their access.
- Data: the supplier holds your customer, employee or financial data. Payroll providers, CRM platforms and marketing agencies sit here. If they suffer a breach involving your personal data, UK GDPR requires them to tell you without undue delay. You then decide whether to report it to the ICO, within 72 hours of becoming aware of it.
- Software: code you did not write runs inside your environment. Attackers can use a compromised update or an unpatched vendor flaw to get into your environment.
- Dependency: your operations stop if the supplier stops. Cloud platforms, payment processors and logistics partners sit here, even if they never touch your data.
Step 1: Map your suppliers
In most organisations nobody holds the full supplier list. Finance knows who gets paid, IT knows who has remote access, and teams sign up for SaaS tools that neither department sees.
Build one register. Pull accounts payable records for the last 12 months, export the list of external accounts and remote access tools from your identity platform, and check your SSO and expense data for SaaS subscriptions. For each supplier, record what they provide, who owns the relationship internally, what systems they can access, and what data they hold.
Include your suppliers' key subcontractors where you know them. Your managed service provider's remote management platform is part of your supply chain, even though you never signed a contract with its vendor.
Step 2: Tier by criticality
You cannot audit every supplier in depth, and you should not try. Score each one on access, data and dependency, then put your assurance effort where the score is highest. For dependency, ask how quickly you could replace the supplier, or keep operating without it.
| Tier | Typical suppliers | Assurance level |
|---|---|---|
| Tier 1: Critical | Managed IT and security providers, core cloud platforms, suppliers holding sensitive personal data, single-source operational suppliers | Detailed questionnaire, evidence review (certificates, pen test summaries), contract security schedule, annual review |
| Tier 2: Important | Business applications with limited data, professional services firms with document access, secondary logistics | Short questionnaire, certification check, standard contract clauses, review every two years |
| Tier 3: Low | Suppliers with no system access, no personal data, and easy replacement | Standard terms, no assessment beyond onboarding |
Keep Tier 1 short enough that you can review each supplier in depth every year. If most of your list lands there, check whether you scored too cautiously.
Step 3: Assess your critical suppliers
Ask for evidence. "Do you take security seriously?" tells you nothing. "Send us your current Cyber Essentials Plus certificate" gets you a document, or a gap you can act on.
The NCSC publishes a free set of supplier assurance questions aimed at SMEs. For Tier 1 suppliers, make sure your questionnaire covers at least these:
- Which certifications do you hold, and what is in scope? An ISO 27001 certificate that covers one office and excludes the service you buy proves little. Ask for the scope statement.
- How do your staff access our systems? Look for named accounts, MFA on every login, and access granted only for the task at hand.
- How do you verify identity before resetting a password or MFA method? Attackers got into M&S by talking a third party into a password reset.
- How quickly will you tell us about an incident that affects our data or service, and who will contact us?
- Which subcontractors process our data or access our systems, and where are they based?
- When did you last test your backups and your incident response plan?
- Can you share a summary of your most recent penetration test and the status of its findings?
Keep it short enough that a supplier can finish it in an afternoon, and ask for documents on the questions that matter most.
Cyber Essentials, ISO 27001 and SOC 2 reports tell you a supplier has a baseline. They do not tell you how the supplier protects your account. For your most critical suppliers, ask how their controls apply to the service they deliver to you.
Step 4: Write security into the contract
Once a contract is signed, your leverage drops. Agree security terms before signature, or at renewal for existing suppliers. For Tier 1 suppliers, attach a security schedule that covers:
- Minimum controls: MFA on all access to your systems and data, patching timeframes, encryption, and maintained certifications.
- Incident notification: a fixed window, such as 24 hours from detection, and a named contact on both sides. If you fall under NIS2 or DORA, align the window with your own reporting deadlines.
- Right to audit: the right to assess the supplier's controls, or to receive independent audit reports in place of an on-site audit.
- Subcontractors: notice before the supplier adds a subcontractor that handles your data, with the same obligations flowing down.
- Exit: return and verified deletion of your data, removal of all access, and enough transition support that you can switch provider.
Where the supplier processes personal data for you, UK GDPR Article 28 already requires a written processing agreement with set terms. Check that yours exists and matches what the supplier actually does.
Step 5: Control supplier access
Technical controls limit what an attacker can do with a supplier's access, whatever the contract says.
- Give every supplier engineer a named account. With shared logins you cannot trace who did what.
- Enforce MFA on all supplier access, including remote management tools and VPNs.
- Grant the minimum access needed, and time-limit privileged access where your platform supports it.
- Log supplier sessions and review them. Alert on supplier logins outside agreed hours.
- Remove access the day a supplier contract or an individual engagement ends. That covers named accounts, VPN access, remote management tools, API keys, service accounts and any credentials the supplier’s subcontractors hold.
Treat your managed service provider's tools as part of your attack surface. A compromised remote monitoring platform gives an attacker the same reach as your provider's engineers. A zero trust approach limits how far that access extends.
Step 6: Monitor, reassess and plan for failure
A supplier that passed assessment last year may have changed ownership, lost key staff or suffered a breach since. Review Tier 1 suppliers at least annually, and again after any of these triggers: a reported incident, a merger or acquisition, a major change in the service, or a lapsed certification.
Plan for the day a critical supplier goes down. For each Tier 1 supplier, answer three questions in your incident response plan: how will we know, what do we switch off, and how do we keep operating? Some JLR suppliers warned they could collapse without government support. Keep data exports and contact lists somewhere that does not depend on the failed supplier. Test a data export at least once: check that you can open it and load it into another system. A contract clause promising your data back does not make the file usable.
What the regulations require
| Framework | Supplier requirement | Who it affects |
|---|---|---|
| NIS2 Article 21(2)(d) | Supply chain security, including security in relationships with direct suppliers and service providers. Entities must consider each supplier's vulnerabilities and security practices. | EU essential and important entities. UK businesses that supply them will see these duties flow down through contracts. |
| UK Cyber Security and Resilience Bill | Would bring medium and large managed service providers into the NIS regime and let regulators designate critical suppliers to regulated organisations. | MSPs, data centres, and suppliers to operators of essential services. The Bill is currently in the House of Lords. |
| DORA Articles 28 to 30 | ICT third-party risk strategy, a register of information covering all ICT contracts, and mandatory contract terms. | EU financial entities and their ICT providers. In force since 17 January 2025. |
| ISO 27001:2022 Annex A 5.19 to 5.23 | Supplier relationships, security in supplier agreements, ICT supply chain, monitoring of supplier services, and cloud services. | Any organisation certified or seeking certification. |
| UK GDPR Article 28 | Use only processors that give sufficient guarantees, under a written contract with set terms. | Any organisation that shares personal data with a supplier. |
One supplier risk process covers all five if you design it with the strictest framework in mind. For more detail, see our NIS2 compliance guide and our article on the Cyber Security and Resilience Bill.
When you are the supplier
Expect more security questionnaires from your customers, especially from those in finance, healthcare and critical infrastructure. Many of them must assess their suppliers under NIS2, DORA or their sector regulator. Build the answers once and reuse them:
- Get Cyber Essentials at minimum, and Cyber Essentials Plus if you hold customer data or access customer systems. Our comparison of Cyber Essentials and ISO 27001 covers which suits you.
- Keep a standard security pack: certificates with scope statements, a summary of your security controls, your incident notification process, and a list of subprocessors.
- Name one person to own customer security questions, so answers stay consistent across sales and delivery.
Many large buyers score supplier security during procurement, so a fast answer backed by documents helps you win the work.
Sources
- Verizon: 2026 Data Breach Investigations Report
- GOV.UK: Cyber Security Breaches Survey 2025/2026
- Infosecurity Magazine: M&S chair details ransomware attack to MPs
- Infosecurity Magazine: CMC classifies M&S and Co-op hacks as a single cyber event
- Express & Star: Jaguar Land Rover cyber attack cost the UK £1.9 billion
- NCSC: Supply chain security guidance
- NCSC: Supplier assurance questions
- UK Parliament: Cyber Security and Resilience Bill
- EUR-Lex: Directive (EU) 2022/2555 (NIS2)
Ryland has delivered cybersecurity, compliance, and IT management programmes for regulated organisations across the UK and the Netherlands for over 20 years. View full profile