Is there a weak link in your cyber security supply chain?

Supply chain risk management is an important process involving proactively identifying, assessing, and mitigating potential disruptions and threats impacting your supply chain. 

It’s being recognised as an increasingly important part of a robust cyber security strategy, where organisations that take security seriously want to ensure they don’t have weak links in the chain that might allow attackers to access their systems and networks via a supplier that hasn’t taken enough steps to protect their organisation.

Traditionally, supply chain risk management has been managed with security questionnaires – particularly when onboarding new suppliers. However, this approach is proving to be increasingly ineffective…  

The challenge of static questionnaires

One of the biggest issues with a security questionnaire is it provides limited visibility. Even if everything was accurate and true at the moment it was completed, things change. Questionnaires only offer a one-off picture and fail to capture a supplier’s ever-changing security posture. 

It’s also very possible for suppliers to recognise what the expected or preferred answer is to any given question, and it’s not unheard of for the unscrupulous to provide inaccurate information so they can pass. 

Add to this the resource-heavy job of having to manually sift through responses, which is laborious and susceptible to human error, and you have a system with holes that could well end up leaving your organisation in a difficult spot.

That’s not to say questionnaires don’t have a role and should not be used. They play an important part in standardising onboarding processes and ensuring clear requirements around suppliers’ security. 

However, they may provide a false sense of security if they aren’t repeated regularly or aren’t complemented by other requirements that can better build an accurate and holistic picture of a supplier’s cyber security.

What can you do to better understand and improve your supply chain’s security?

1) Build strong working relationships with your suppliers 

Establishing open, trusted relationships with your suppliers – or potential suppliers – is important. Trust allows for a more transparent supply chain, and helps you to be more confident that your suppliers are using secure practices and aren’t introducing vulnerabilities.  

Having a good relationship with your suppliers also makes it much easier for you to be upfront about your needs and expectations, and it’ll likely mean that they, in turn, are more willing to explain exactly what measures they do – or don’t! – have in place. This makes it much easier for you to assess the level of risk they pose and take appropriate steps in response.

It also makes it much easier to identify and resolve problems quickly if you have a good relationship with your suppliers – if they face a potential disruption, they can alert you so you can make the necessary changes to reduce the impact, and you can work together to find solutions.

2) Make sure you’re asking each supplier the right questions 

Unfortunately, many organisations struggle to ask the right questions in their questionnaires, which makes it almost impossible for them to properly assess what cyber security measures their (potential) suppliers have in place.

One common issue we see, for example, is that questionnaires can be generic and not tailored to the specific risks associated with the supplier’s role in the supply chain. A high-risk supplier with access to sensitive data requires a deeper dive than a low-risk provider, so the questionnaire they complete should reflect this.

Another example is questionnaires that focus solely on whether policies exist, rather than how effectively they’re implemented. Having a written policy on access controls is good, but how well is this enforced?

Making sure you’re asking each supplier the right questions is vital if you want to understand exactly what level of risk they might pose to your organisation. 

3) Dig deeper where you can

Simply asking your suppliers whether they have particular measures in place with a yes/no question may make it easier for you to quickly assess them, but it can also limit your ability to understand the nuances of their cyber security posture. 

Instead, open-ended questions and requests for documentation can provide a richer picture – and help you recognise when suppliers are answering in a way that minimises their perceived risk… We would always recommend that you verify their answers to your questions, either by requesting evidence or by requiring an independent audit, so you have a more objective assessment to work with. 

We would also suggest that you consider things like scope when asking about the accreditations and certifications suppliers have in place. Yes, they might have ISO 27001, but is the service they’re providing you covered in the scope? 

4) Regularly review your suppliers’ cyber security 

If your suppliers have only ever completed one security questionnaire, it’s very unlikely that their answers are all still true now. Onboarding is a key time to understand your suppliers’ cyber security posture, but it should not be the only time you do so. 

Instead, make sure you are regularly (eg annually) asking them whether they still have the same controls in place – and take a risk-based approach in terms of how often this is done and what level of evidence you require. 

It’s also important to conduct a review whenever there is a significant change within the supplier’s organisation. For example, if they are acquired by another company or if they change to a new service provider for an area of their business that may affect your organisation, you need to understand what impact this might have and act accordingly.

In some cases, it may even be helpful to have a break clause in place, so that if your supplier makes a change that increases your risk to a level with which you are not comfortable, you can quickly move to an alternative supplier with a better cyber posture.

5) Be prepared for things to go wrong

Sadly, things do go wrong and cyber incidents do happen – even to organisations with a good cyber posture. You need to be prepared for this and make sure you have a business continuity plan in place. 

Any suppliers that provide a key function to your business pose an operational threat, should they be hit with an attack. So having a plan for what you’ll do if their service is compromised is vital.

Is your supply chain leaving you open to attack?

Supply chain due diligence isn’t an easy task – but it is increasingly important. So if you want to make sure your supply chain isn’t leaving you open to attack, get in touch with our team using the contact form below.