Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 7 of 29

Step 3: Understand how your organisation evaluates risk

Effective cyber security has to be appropriate to your systems, your processes, your staff, your culture, and the level of risk you are willing to take. Therefore the way you assess cyber security in your supply chain will depend upon understanding how you organisation works, its function, and what its risk appetite is. There is not one approach to this activity, and businesses will usually have their own methods of dealing with risks. Start by understanding your organisation’s appetite for supply chain risk vs the resourcing required to manage that risk:

  • If you have little to no experience of assessing supply chain cyber security, you can review the steps in Stage 2 do this
  • If your organisation already has an approach for managing cyber security risk, then you should use it to help you understand and manage the cyber security risks associated with your supply chain.

Published

Reviewed

Version

1.0