Supply chain compliance and cyber security accreditation for new business and procurement – ultimate UK guide

supply chain compliance and cyber security accreditation for new business and procurement

Supply chain compliance requirements are becoming the norm for many UK businesses. Clients are demanding cyber security accreditations from suppliers that want to pitch for their projects, retain their business or take part in their procurement processes. 

In specific cases, this is most likely to mean Cyber Essentials or Cyber Essentials Plus, ISO 27001, or Payment Card Industry DSS (PCI) compliance. In other cases, suppliers may be required to undertake a cyber security audit including vulnerability or penetration testing of their networks. Others will require their suppliers to have a Managed Detection and Response (MDR) solution in place, such as a Security Information and Event Manager (SIEM) solution. This is especially likely for those involved in the Critical National Infrastructure (CNI). For others, a demonstration of staff awareness and training, to recognise phishing attacks, for example, may be needed.

If you are in this position, or looking to future proof your business, this article will help you find the most efficient way of achieving the accreditations you need.

Supply chain compliance and cyber security accreditation – why is it required?

A company’s supply chain can present significant risks in terms of compliance and cyber security risk. If a company and its supplier share data, that data is at risk if the supplier has not adequately protected themselves, or if they are operating without putting in place appropriate controls. No matter how secure the client company is and no matter how robust their systems and processes might be, all that could be pointless if a supplier provides a weak link and important data is breached through that supplier.

Should such a data breach occur, the client company will suffer disruption to their business, reputational damage and potential sanctions. This is the case even if they weren’t the source of the breach.

Even if confidential data is not lost, a supplier’s ability to fulfil their contract with a client could be jeopardised if, for example, they were to suffer a cyber security breach, get hacked, face a ransomware attack and so on.

Companies are therefore increasingly likely either to undertake a 3rd party cyber security/risk assessment or (more likely) require their suppliers to have in place recognised cyber security accreditations. Typically, this might include Cyber Essentials, Cyber Essentials Plus, ISO 27001 or PCI (DSS) compliance.

Supply chain compliance – which cyber security accreditation and why?

Cyber Essentials

Cyber Essentials is a great first step towards making your systems more secure. It also helps you prove to suppliers that you are taking cyber security seriously. The National Cyber Security Centre and the ICO support the government-backed certifications, which are accredited through IASME.

Cyber Essentials helps you guard against 80% of the most common forms of cyber-attacks and includes automatic cyber liability insurance.

Cyber Essentials consists of a simple self-assessment questionnaire that asks you about what you have in place to protect your business from cyber threat. The five controls (or measures you can take) that Cyber Essentials looks at are: ensuring all your devices’ operating systems and applications are up-to-date; having effective anti-malware protection in place; managing who has access to data and systems; making sure your your device and software settings are secure and using a firewall to secure your internet connection

We’ve been helping businesses achieve Cyber Essentials certification since 2015. We know how to make the process painless. The scheme is suitable for organisations of all sizes.

For more information visit our Cyber Essentials page

See also: Cyber Essentials – the ultimate user guide

Cyber Essentials Plus

Cyber Essentials Plus is like the grown-up big brother to Cyber Essentials, when an additional level of compliance needs to be demonstrated. However, it’s more robust, because a qualified third party or Certification Body (such as Securious) verifies the information submitted.

Increasingly, therefore, supply chain compliance will specify the Cyber Essentials Plus level rather than the basic Cyber Essentials. Upgrading from one to the other should be very straightforward for most organisations.

Securious is an IASME Certification Body, and can help you achieve accreditation quickly and efficiently.

For more information visit our Cyber Essentials and Cyber Essentials Plus page

ISO 27001

ISO 27001 is the international standard for Information Security required where a high level of compliance is demanded.

It provides a framework for an information security management system. It enables organisations to manage the security of assets like finance information, intellectual property, employee details or information entrusted by third parties.

Securious has helped numerous organisations achieve their ISO 27001 accreditation. We are the pioneers of the ISO 27001 Academy, which helps businesses get ready for the assessment quickly and efficiently.

For more information visit our ISO 27001 information page or our ISO 27001 Academy page

PCI DSS compliance

Payment Card Industry (PCI) Data Security Standard (DSS) compliance is a mandatory requirement for any organisation that takes card payments (credit card or debit card). The standard protects cardholder data by implementing thorough controls around how that cardholder data is stored, transmitted and processed.

If you suffer a data breach and you aren’t PCI compliant, you may be subject to fines and liable for the fraud losses incurred against the card data lost.

However, many vendors assume they do not themselves need to be PCI compliant, because they use a payment provider such as Stripe or Sage Pay. However, while it may lower the bar, it does not make them exempt from their compliance requirements.

Within the supply chain, expect clients to check that suppliers have the correct level of PCI DSS compliance.

If you take card payments and want to ensure you are compliant for supply chain or due diligence purposes, contact us now. We are a PCI Qualified Security Assessor (QSA) company, meaning the PCI Council has authorised us to assess you for compliance.

See our ultimate UK guide to PCI compliance

For more information visit our PCI DSS compliance page

Supply chain compliance and assurance – other potential requirements

Cyber Security Audits

Rather than asking you for formally recognised cyber security accreditations, some supply chains or procurement processes may require you to undertake a bespoke cyber security audit. Whereas others will require you to complete a lengthy cyber security questionnaire.

The precise requirements will depend on the particular audit that is being conducted. They may have particular specifications depending on the nature of the product or services being supplied.

Securious offers a series of cyber security audits aimed at company boards and senior leadership teams. They are designed to help businesses understand whether their cyber security is fit for purpose. A typical audit will look at systems and controls and provide a prioritised plan of action.

For more information visit our Cyber Security Audits page

Pentesting (Penetration testing)

A penetration test is an attempt to safely exploit your IT systems to determine whether they’re vulnerable to attack. They are most effective when the tester carries out both external and internal tests.

We increasingly undertake pentests that clients require as part of a supply chain or procurement requirement. They are normally a part of the PCI DSS compliance process.

When Securious undertakes a pentest, we provide insight and guidance around any vulnerabilities and the likelihood of a breach within your organisation.

For more information visit our Pentesting (Penetration Testing) page

Vulnerability scans

Vulnerability scans investigate potential weaknesses on a network and the devices linked to it. They can quickly identify areas such as unpatched software where vulnerabilities will exist and present a set of required remediations.

Often, formal cyber security accreditations require vulnerability scans. This is the case with Cyber Essentials Plus, ISO 27001 and PCI compliance but can be conducted on a standalone basis too.

Clients require some suppliers to undertake regular (eg quarterly) vulnerability scans in order to be part of the supply chain.

For more information visit our Pentesting (Penetration Testing) page

SIEM: Security Information and Event Management

A Security Information and Event Management system combines information logs from multiple sources across your network. It identifies any anomalies that require further investigation, as well as helping identify attacks on a network. SIEM solutions can also record all log files and provide invaluable for forensic analysis.

SIEM solutions enable compliance with a number of regulatory requirements, including PCI compliance.

Securious has its own SIEM solution – Monikal – which provides enterprise-level capabilities for mid-level organisations.

For more information visit our SIEM Solution page

SOC: Security Operations Centre

A Security Operations Centre (SOC) service would normally work in conjunction with a SIEM (see above). They respond to the information and events identified as anomalous or requiring attention by the SIEM.

Some larger organisations handle their SOC in-house, while others take advantage of managed service offerings.

Supply chains involved in the critical national infrastructure (CNI) are increasingly requiring SOC and SIEM solutions.

Securious offers a managed SOC service in conjunction with our Monikal SIEM solution. We tailor this for the needs of mid-level organisations.

For more information visit our SOC Security Operations Centre Page

See the National Cyber Security Centre’s Security operations centre (SOC) buyers guide

MDR: Managed Detection & Response

Managed Direction and Response services monitor your organisation’s network and devices and identify potential vulnerabilities. They then help contain breaches and respond to threats.

MDRs are effectively a combined SIEM and SOC solution.

For more information see our SOC and SIEM Solutions page

NIST Cybersecurity Framework

The US Government NIST (National Institute of Standards and Technology) Cyber Security Framework aims to ‘integrate industry standards and best practices to help organizations manage their cybersecurity risks.’

This is a UK-based guide, the NIST Framework is becoming more popular in the UK and the rest of Europe.

As well as following best practices for UK cyber security and compliance, Securious can help audit your business and working practices against the NIST Framework.

Learn more on the NIST website

Or read: NIST Cybersecurity Framework for businesses in the UK

Supply chain compliance – what should I do next?

If you need a cyber security accreditation or service in order to pitch for a new client, we can help. Whether it’s to participate in a procurement exercise, or to future-proof your business.

If you want to understand what is possible and best for you, just call us on 01932 247 110. Otherwise, you can send us a message in the form below

See our own cyber security accreditations and qualifications here