How to assess and gain confidence in your supply chain cyber security
Pages
Page 2 of 29
Understanding the threat
Many organisations rely upon suppliers to deliver products, systems, and services. Supply chains are often large and complex, and effectively securing the supply chain can be hard because vulnerabilities can be inherent, introduced or exploited at any point within it. This makes it difficult to know if you have enough protection across the entire supply chain.
In recent years there’s been a significant increase in the number of cyber attacks resulting from vulnerabilities within the supply chain. These attacks can result in devastating, expensive and long-term ramifications for affected organisations, their supply chains and their customers.
Despite these risks, many companies lose sight of their supply chains. In fact, according to the 2022 Security Breaches Survey, just over one in ten businesses review the risks posed by their immediate suppliers (13%) and the proportion for the wider supply chain is half that figure (7%).
Whilst the problem is understood, the interconnected and distributed nature of the supply chain can make it difficult to know how your suppliers are managing and maintaining their cyber security. Organisations with limited resources may face challenges such as:
- low recognition or understanding of the risk that poor supply chain cyber security can pose
- lack of investment to protect against supply chain risks
- limited visibility into supply chains
- insufficient tools and expertise to evaluate suppliers' cyber security
- not knowing what you should be asking your suppliers to do
The NCSC has produced this guidance to help ease these challenges. It complements existing NCSC guidance which should be read in conjunction:
-
NCSC Risk Management guidance
-
-