How to assess and gain confidence in your supply chain cyber security
Pages
Page 20 of 29
Step 2: Risk assess and prioritise your contracts
Risk assess and prioritise existing contracts, with focus on critical business functions and areas of high cyber risk. Conduct an assessment of those contracts in priority order until you are confident that the core contingent of suppliers have been assessed.
Supplier risk assessment steps
- Create a team capable of assessing supplier contracts for cyber security risks to the organisation. The team involved in the risk evaluation may vary, for instance different data owners will have a view on their own areas of expertise.
- Assemble a list of all tier 1 suppliers that you currently engage with. Determine which business units may have engaged with suppliers in conjunction with procurement and commercial teams.
- Create a register of suppliers and integrate this into the organisational process so that new suppliers are added to it automatically.
- Carry out an initial filter and concentrate on meaningful areas of risk. If the contracted work requires little or no data, is a purely goods type contract, has very limited time left to run, or is not the type of IT service or delivery that might be associated with a cyber attack, these can be filtered out from requiring a thorough cyber security risk assessment.
- Provide each supplier with an initial risk rating, based upon criteria determined when specifying risk levels to aid prioritisation. For more information on risk levels, see Stage 2 Develop an approach to assess supply chain cyber security.
- Risk assess the organisations in priority order and conduct the assessment of that supplier in accordance with its risk profile, checking that the supplier conforms to the controls expected at this risk level.
- For any new contracts, determine the risk level of the supplier and carry out an assessment as part of the procurement decision making process.
A supply chain vulnerability could exist anywhere within the supply chain, not just the immediate suppliers who are most visible. Here are some steps you can take to apply a focused approach to understanding systemic risks in your supply chain.
Identify your immediate suppliers and what they do for you
No matter how large or small your organisation, knowing who you have direct contracts with, what products and services they provide for you and what information they have access to is absolutely crucial. If this is not already known, make this a top priority task to complete. Knowing what your suppliers do and what they have access to will provide an initial indication of how important they are to your organisation’s security.
Work with your suppliers to build a bigger picture
Ask your immediate suppliers to both identify their suppliers, and pass down the request to them to identify other relevant suppliers. Provide clear instructions to guide them on how far they are expected to go and what the scope of the risk assessment is. Update your supply chain map as more information is revealed.
Conduct risk analysis on the suppliers identified
Now that you’ve identified and prioritised the suppliers you care about in your extended supply chain, you can determine the appropriate method and frequency of assessment that is proportionate to the risk posed, as you would with your immediate suppliers.
Specify supply chain mapping activities into supplier contracts
Due to the level of commitment that this task will likely take, your supply chain mapping requirements should be specified and articulated within the contracts that you form with an immediate supplier. This requires some upfront consideration of the need to obtain information vs the cost of acquiring it:
- Do you need to know the names of the subcontractors and suppliers within the chain, and what their level of compliance is? How far down the supply chain do you need to go? This may be driven by whether work being done for the organisation has been subcontracted out. What exactly has been subcontracted, and what is its criticality taking into consideration the organisation’s risk criteria?
- Do you just need confirmation that subcontractors and suppliers further down the chain have met the necessary cyber security controls (without disclosing the details of who they are)? Some immediate suppliers may be hesitant to disclose who their subcontractors or suppliers are, as this may pose a commercial disadvantage.
- How should all this information be provided to you? How will you know when it is done? Where is it stored? How often will you check for changes?
Understanding the constraints, defining your requirements upfront, and specifying (where necessary) within your contracts the stipulation will allow you to define a process that works for your organisation.
| Note: Carrying out this activity will have resourcing implications for both your organisation and your suppliers. It is also heavily dependent on cooperation from your suppliers to carry out the assessment and mapping of their suppliers. A collaborative approach and an understanding that this is mutually beneficial is key. It may be better to stipulate the request within new contracts going forward rather than relying on good will. |
There are two key factors that may impact the use of extended supply chains; concentration risk and resilience risk.
Concentration risk: the risk created by reliance on a single provider, sector or location. Having built a list of your supply chain of critical suppliers, model the most likely risk outcomes.
For any suppliers deemed to be a high concentration risk, what would be the impact if the risk were to materialise? If it would have a significant impact on your ability to operate, it might be of benefit to ask the supplier about how they manage their resilience risk, or seek a portfolio of alternative suppliers.
Resilience risk: can a business adapt to disruptions whilst maintaining continuous business operations, for instance after a cyber attack?
Check with your supplier what plans they have in place for possible adverse conditions, some examples might include:
- cyber incident response plan / IT incident management process
- cyber-compromised data recovery plan
- disaster recovery plan
- emergency response plan (incorporating pandemic management, severe weather, seasonal preparedness plans)
- third party supply chain / disruption plans
A vendor may be considered high risk for various reasons. These include:
- strategic position/scale within the UK market
- quality and transparency of the vendor's engineering practices/cyber security controls
- past behaviours and considerations relating to the ownership and operating location of the vendor
- a vendor may be under investor or state influence and may follow domestic laws which conflict with UK law
It is important to understand if you have any vendors that may be considered higher risk from this perspective and create a risk management approach for them explicitly.



