Supply chains: an overlooked and underestimated threat

Most organisations are now aware of the importance of cyber security and have taken appropriate steps to protect their systems and data. 

However, it doesn’t matter how many vulnerabilities you’ve addressed or how often you’ve had your systems penetration tested – there is a hugely overlooked and underestimated threat that lies outside your organisation and instead, within your supply chain…

The risk posed by supply chains 

Supply chains are complex ecosystems that link manufacturers, vendors, distributors and service providers. But this interconnectivity creates a problem, because if any organisation within that supply chain hasn’t taken cyber security seriously, it could present a significant threat to everyone else within that chain. 

For instance, if a vendor providing essential services to a retail giant falls victim to a cyber breach and it has direct access to the retailer’s network or handles sensitive customer data, the repercussions could be catastrophic: despite huge investment into cyber security, the retailer has been breached through the infiltration of one of its suppliers. 

And the same goes for your organisation. If any of your customer data lies with a third party and if any of your systems or platforms can be accessed by one of your suppliers, there is the potential for your organisation to be infiltrated by attackers targeting that supplier – or one of its suppliers. Supply chains can be long and complicated and it’s challenging to achieve proper visibility of every link in your chain that could lead to a successful cyber attack. 

Supply chain security and compliance

Your supply chain doesn’t just pose a threat to your security, however. It can affect compliance too. 

For instance, with the introduction of PCI DSS V4.0, greater emphasis is being placed on the security of your suppliers, which has been recognised as a key threat to cardholder data. 

This means that if you have suppliers or service providers with access to key systems or cardholder data, they need to be compliant with PCI DSS V4.0 too – otherwise you take on that risk yourself, and should be implementing additional compensating controls within your own environment. These measures can help mitigate the risk arising from the non-compliant supplier. However, they need to be robust enough to effectively secure the sensitive data and processes affected by the supplier’s involvement.

How to mitigate supply chain security risks 

Conduct a risk assessment 

It’s important to conduct thorough risk assessments across your supply chain and identify which suppliers could pose a threat to your organisation’s security. Then, evaluating the posture of each supplier is critical, to understand where potential breaches could arise and take mitigating steps to reduce the potential impact and likelihood of them occurring. 

Contractual obligations 

Implementing stringent cyber security clauses within your supplier contracts is important to ensure it’s clear and agreed for both parties what your security standards are, the protocols around breach notifications and where responsibilities lie in terms of fortifying defences. Many larger organisations are increasingly requiring their suppliers to achieve the Cyber Essentials and Cyber Essentials Plus certifications, so they can be certain that the most fundamental cyber security basics are in place. 

Monitoring and auditing 

Regular monitoring and audits of supplier networks and security measures can help ensure ongoing compliance and swift identification of potential vulnerabilities. Ultimately, supply chains are an ecosystem and need to be treated as such, so organisations should be working together collaboratively within them to improve security across the board. 

Final thoughts 

By acknowledging the significance of securing every link in the chain, organisations can mitigate risks, safeguard sensitive data, and strengthen their resilience against the ever-evolving cyber threats. Compliance, especially within regulatory frameworks like PCI DSS, should extend beyond organisational boundaries, encompassing the entirety of the supply chain.