Skip to main content
Guidance

Connected Places Cyber Security Principles

Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.

Page 7 of 19

#4 Understanding your suppliers' role within your connected place

You cannot outsource your accountability to your suppliers, as you are the overall risk owner for your connected place. There may be areas of split responsibility within your connected place that you may have with your suppliers, but it is still up to you to make sure the supplier fulfils this. You need to consider the role your suppliers have in building and operating your connected place. You should incorporate your suppliers' roles as part of your overall risk assessment process. This should include:

  • What needs to be protected within your connected place, including systems assets and your citizens' privacy (and the level of protection required).
  • How to communicate the minimum security requirements to your suppliers, how they will meet them, and what action will be taken in response to significant breaches of these requirements.
  • Where operational technological capabilities are provided by the supplier to support bespoke business outcomes. This will bring bespoke risks with them which need to be analysed separately, as they will not fall within your minimum security requirements baselines. Further mitigations must also be implemented to deal with these bespoke risks.
  • What assurance requirements need to be built into your connected place supply chain, and how these are going to be reported to you and your suppliers. Suppliers should be accountable for their security obligations as part of the contractual process.
  • How your connected place supply chain is going to continuously improve its security, and build trust with your supplier.
  • How your suppliers will report any suspicious or malicious activity, and assist you when needed.
  • How readily you can change suppliers, should the need arise, and the level of support required to do so.
  • What your exit strategy looks like (even if you hope not to use it).

Finally, you need to understand how you deal with risks associated with suppliers. This needs to include:

  • Understanding the maturity of your suppliers' security protections. Will these protections meet your security requirements that will make compromise difficult, and reduce the impact of compromise to the threats you may face?
  • Understanding the maturity of your suppliers' people security arrangements. Are your suppliers’ staff security educated to an acceptable level, with the awareness to spot suspicious activity, or potential physical or cyber attacks that you may face?
  • Understanding the potential exploits and impacts that can occur from insider threats. Has your supplier performed risk assessments to understand their insider threat? Is there a plan to deal with insider risk ? Have they implemented effective controls to mitigate these insider risks? Have you considered implementing Privileged Access Management (PAM) to help support you?

Some countries seek to obtain sensitive commercial and personal data from overseas, including from the UK. Suppliers that are part of corporate groups based in these countries may be subject to influence from those governments to access and exfiltrate data from UK connected places, in support of those countries’ security and intelligence services. Such suppliers may also be used as a vector for an attempt to take down an essential service through denial of service methods to affect its availability, or through poisoning of the service through data manipulation or malicious code injection that could affect the integrity and availability of the service.

Methods by which a foreign government may be able to influence a supplier include the following:

  • Ownership

    Broadly, the greater the percentage of ownership of a supplier held by a foreign corporate group, the larger the influence that group will have on the affairs of the supplier. For example, for suppliers that are UK companies, a shareholding of 75% is required to pass certain important shareholder actions that require a 'special resolution' under the UK Companies Act 2006. The presence of intermediary companies in the chain of ownership between an overseas parent company and a supplier may dilute the extent of control.

  • Board representation

    Foreign nationals on the board of a supplier may be directly subject to legal obligations in their country of citizenship to support that country’s security and intelligence agencies, which they may feel pressure to comply with. It is important to note that these individuals will also be subject to countervailing obligations under UK law and/or the law of the supplier’s place of incorporation (if it is not a UK company), for example data protection legislation.

  • Workforce

    Foreign nationals in the workforce of a supplier may be directly subject to legal obligations in their country of citizenship to support that country’s security and intelligence agencies, which they may feel pressure to comply with. It is important to note that these individuals will also be subject to countervailing obligations under UK law and/or the law of the supplier’s place of incorporation (if it is not a UK company), for example data protection legislation.

  • Data hosting and routing

    If UK connected place data is hosted in or routed through a foreign country, the government of that country may be able to influence the supplier to provide it with access to that data, or it may be able to access that data directly under national security and intelligence laws.

  • Supplier relationship

    If the foreign corporate group is the manufacturer of products used by the supplier, that foreign corporate group will have influence over the supplier.

  • Provision of corporate services, knowledge or finance by corporate group

    If a foreign corporate group provides corporate services to the supplier, the corporate group may be able to directly view or access certain data held by the supplier. The foreign corporate group may also provide knowledge to the supplier, which could be vital for that supplier’s operations.

  • Investors

    The same considerations outlined above with respect to suppliers also apply to the choice of investors in your connected places. You should consider the level of influence that a particular investor has over your connected places programme (including the ability to access and exfiltrate data or control essential services), and the risk that any investor may be subject to influence from a foreign government to act in a particular way

Published

Reviewed

Version

1.0