Guidance
How to assess and gain confidence in your supply chain cyber security
Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 15 of 29
A one-off assessment will not be sufficient to ensure your cyber security standards are being met. Monitoring vulnerabilities in your supplier’s cyber resilience on a regular basis will help you to identify where there are shortfalls and to work with your suppliers to address them (before they are exploited and become an issue).
Maintaining a regular dialogue with your suppliers so they inform you of changes will help ensure standards are maintained, and identify any issues that need addressing. During these regular cyber security reviews, you could gather the following information from your supplier:
Examining your own organisation’s assets is also a good way to confirming supplier security is being maintained. This might include:
Consider using third party tools to continuously monitor your suppliers.
There are a range of commercial tools available which can review and access your suppliers' public facing traffic and attempt to make an assessment of vulnerabilities in any of the packets of data being sent. Although this might not represent a precise test of your suppliers' capabilities, the automated and real time nature of the reporting could alert to significant changes, which might prompt a conversation with the supplier concerned.
You may wish to formalise how your supplier demonstrates it is meeting the controls that it has agreed to have in place, as part of any Service Level Agreement. These should be measurable, with automation applied as much as possible. These should be defined in contractual obligations and may include:


