Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 8 of 27
Collaborating with your supply chain and partners

Cyber attacks on your suppliers can be just as damaging as an attack on your own networks.
Introduction
Many of us rely on suppliers to deliver products, systems, and services. However, supply chains are often large and complex, which makes it difficult to know if you have enough protection in place. Whilst you might be implementing cyber security effectively within your own organisation, you’re exposed to numerous risks if your suppliers have not done the same.
In recent years there’s been a significant increase in the number of cyber attacks resulting from vulnerabilities within the supply chain. These attacks can result in devastating, expensive and long-term ramifications for affected organisations, their supply chains and their customers (as the following video explains).
Despite these risks, many companies lose sight of their supply chains. According to the Cyber security breaches survey 2024:
- 48% of large organisations reported reviewing their immediate suppliers
- yet that figures reduces to 23% for the wider supply chain

Board leadership can make an important difference, by encouraging collaborative relationships between organisations and their suppliers. The benefits of doing this includes:
- Close collaboration with suppliers and partners can greatly enhance your cyber security, is likely to reduce the chances of a damaging cyber attack, reduce your overall risk exposure, and improve your response time and ability to manage the impacts of cyber attacks should one occur.
- Understanding the cyber security of partners is essential if you are to gain assurance that threats from the supply chain are understood, and risks mitigated (the NCSC has one-stop shop that not only offers valuable insights but also grants access to essential resources related to supply chain security.)
- Where you are part of other organisations' supply chains, your ability to convey your own cyber security approach can be a driver of new business opportunities. Being able to demonstrate a good level of cyber security is increasingly a key component of supplier and provider bids, and is already a requirement for many government contracts.
The overarching goal of a supply chain cyber security assessment is to gain assurance about the cyber security of suppliers and partners, and their services and products. This should be in proportion to the level of risk, rather than expecting all suppliers and partners to be at the same level of maturity. In some cases, risks can be minimised with simple measures. In others (for instance where you are installing cyber security solutions which will have comprehensive access to your digital assets) you may need to seek extensive assurance from your suppliers that you will not be exposed to risks through them.
Essential activities
Map your suppliers
Building a clear picture of your suppliers (and working with them to establish their subcontractors) is imperative to supply chain security. You should have assurance that your organisation has a process in place for assessing suppliers, understanding the nature of your dependencies on them, the maturity of their cyber security posture, and steps to be taken to address issues.
Communicate across multiple links
Look for opportunities to enhance resilience and raise awareness by requesting that your suppliers expect similar standards from their own subcontractors or suppliers. If your customers are failing to communicate their own security needs to you, challenge them to be explicit and to provide assurance that they are happy with your arrangements.
Build cyber security into contracts and agreements
Ensure compliance with minimum cyber security requirements is mandated in your supplier contracts and ask for evidence that controls are in place. Ensure security practices are embedded throughout the contract lifecycle of new suppliers, from procurement and supplier selection through to contract closure. Your contracts should include details of what will happen in the event of an incident. If you depend upon a supplier for information about an incident, you may need to specify timelines and onward reporting responsibilities to ensure compliance with legal and regulatory requirements.
Use threat intelligence
Develop threat assessments, threat modelling and rehearsals of incident response with key suppliers and partners. Consider scenarios affecting multiple organisations and/or systems. Analyse how a breach or outage at one organisation could impact the operations of another. Joint exercises can have mutual benefits in building understanding of shared risks, as well as in sharing expertise.
Indicators of success
Success criteria should be defined, and metrics consistently reported to the board so you have visibility of the risk levels. This may include, % of suppliers/subcontractors who have been assessed, when they were last assessed, % compliant with required policy, as well as an overview of high severity issues uncovered.
If your organisation approaches cyber security in a collaborative manner, this is a good sign that you and your partners are supporting each other to enhance your cyber resilience.
If the board has visibility of critical issues in supply chain security, this is a good sign that it is being prioritised.
This should include appropriate due diligence steps when initially procuring the service, along with periodic reviews and revalidation that sufficient measures are in place. For efficiency purposes, the breadth and depth of these reviews may differ and should be proportionate to the criticality of the service and the value/sensitivity of the data involved.
There should be evidence that external data processing arrangements have been documented with steps in place to assure the security of data that has been shared (not just personal data). Critical dependencies on external services should be mapped ensuring the risk around external failure is within the board's appetite (or that there are credible measures in place for redress if a supplier lets your organisation down). Refer to the NCSC’s guidance on How to assess and gain confidence in your supply chain cyber security.


