Supplier assurance questions
Questions to ask your suppliers that will help you gain confidence in their cyber security.

Security governance
You should understand who has responsibility for cyber security at the supplier organisation. Knowing who the risk owners are is a key part of gaining confidence in your supplier.
Your supplier should have policies in place which are accessible to everyone affected. Ideally, feedback mechanisms should be in place to identify whether policies are followed in practice, and if not, to help explain why not.
Having people in security roles with appropriate skills and experience is also essential. Appropriate skills and experience can vary depending on the business context, but can be through a combination of professional training, hands-on experience, and certification. The NCSC offers a range of certified training and has developed the Certified Professional scheme, which sets the standard for UK cyber security professionals.
- Does the supplier have people and processes in place that are responsible for cyber security?
- Are the people occupying security roles suitably skilled and experienced?
- Are senior decision makers aware of their cyber security responsibilities?
Managing and recovering from incidents
Data breaches are common. Just because one hasn’t happened to you yet, doesn’t mean it never will. So, reducing the potential harm that a breach can cause is key.
There are good business reasons for thinking about incident response ahead of time, including service availability and share price.
Organisations should learn from an incident and adapt. For example, if one of your suppliers suffered a ransomware attack because they didn’t have separate back-ups, have they now backed up critical data, or are they still just as susceptible? Knowing when someone in your supply chain has been breached is really important.
- Does the supplier have plans and processes in place to cope with an incident and recover from it?
- Has the supplier suffered any material security breaches or compromises which they need to declare?
- What business continuity / disaster recovery plan does the supplier have for maintaining minimum service levels to you, should they suffer an incident (e.g. a ransomware attack)?
- Does your contract with the supplier clearly state requirements for managing and reporting incidents, including reporting timescales, who to report to, and expected actions?
Note: GDPR timescales for reporting breaches of personal data are 72 hours from discovery of the incident, where feasible.
Useful links:
- Blog post: Offline backups in an online world
- Blog post: Cyber resilience - nothing to sneeze at
- Blog post: Updating our malware & ransomware guidance
- Guidance collection: Incident management
Protecting their network
You should understand how, and be satisfied that, a supplier protects its network from external and internal harms.
Basic cyber hygiene, such as up-to-date antivirus and patching, along with understanding and control of who has access to a network, can go a long way to protecting an organisation from the Internet and other untrusted networks. The same cyber hygiene protects against internal vulnerabilities, whether exploited accidentally or deliberately.
If a supplier uses Cloud services in its service to you, that still forms part of its network.
- How does the supplier protect their network from the Internet or other untrusted networks?
- How has the supplier configured and protected their Cloud services (if used)?
- Does the supplier know what devices connect to their network and who has access to them?
- Do they have processes in place to control which users have privileged access to their networks?
- Do their users have the minimum level of access to data and networks required to do their job and no more?
- Does the supplier secure remote connections to its network, with a robust process for identifying and authenticating remote users?
- Are all users properly authenticated before being given access to networks or services?
- If the supplier uses bespoke or in-house developed software applications in their service to you, how are these secured?
- If they allow Bring-Your-Own-Device (BYOD), how do they protect their networks from potential harms on BYOD devices?
Useful links:
- Guidance collection: Cloud security
- Guidance: Introduction to identity and access management
- Blog post: Protect your management interfaces
- Blog post: Protecting system administration with PAM
- Guidance collection: 10 steps to cyber security - Managing user privileges
- Guidance collection: Secure development and deployment guidance
Protecting data
You should understand how a supplier protects the data on their networks. Basic controls can go a long way to mitigating many of the harms that could befall data on a network.
- Do they encrypt data on portable devices such as laptops, mobile phones, tablets and removable media, in case of loss or theft?
- Does the supplier securely wipe or destroy all storage media prior to disposal or re-use?
- If they allow BYOD, how do they protect data on BYOD devices?
- Do they have processes in place to detect and prevent unauthorised or unusual (e.g. very large) data transfers from their network?
- Do they use secure email and secure data connections to their network, to protect data in transit?
- How do they constrain access to sensitive data?
Useful links:
- Guidance collection: Mobile Device Guidance
- Guidance: Secure sanitisation of storage media
- Guidance collection: Email security and anti-spoofing - Protect email in transit
Offshoring
It's important that you know if any of the supplier's services to you are offshored and if so, how those services meet relevant information security controls.
You should understand if any of the supplier's services to you are subject to other countries' jurisdictions - for example, laws which protect the collection and storage of personal data. Where other jurisdictions are involved, you must be clear whether the data protection standards of the country in question are equivalent to the UK’s requirement for protection, and whether this equivalence is formally recognised.
In the EU and UK, under GDPR, there is provision to ensure that organisations processing and storing personal data adequately protect it and that any transfer of such data outside the EU/UK is handled in an appropriate way.
You need to be aware of the ownership and control of the suppliers you use, and that some countries have laws which aim to exert influence extra-territorially.
- Does the supplier offshore any components of their service to you, such as data storage, data processing, support, development or maintenance of services?
• If so, in which locations and what security controls are in place around those offshore components?
• Will they notify you if any of the locations change, or if they change any of their offshore subcontractors?
• Will any of your personal data be subject to offshore storage or processing?
Useful links:
Personal data
The UK and EU are subject to GDPR. Under this legislation, personal data is information that relates to an identified or identifiable individual. It only includes information relating to natural persons who can be identified, or who are identifiable, directly from the information in question, or who can be indirectly identified from that information in combination with other information.
Information about a deceased person does not constitute personal data and therefore is not subject to the GDPR.
The GDPR has a set of security principles for the protection of personal data. In brief, these are Lawfulness; Fairness and Transparency; Purpose limitation; Data minimisation; Data Accuracy; Storage limitation; Integrity and confidentiality (security); and Accountability.
- Does the supplier handle or process any personal data as part of their service to you, and if so, does it meet the GDPR security principles?
• Is their use of personal data lawful, fair and transparent?
• Is it only used for the purposes it was collected for and nothing else?
• Do they only collect the minimal amount of personal data required?
• Is the personal data accurate, up to date, protected and deleted when no longer required?
Useful links:
- Guidance: GDPR security outcomes
- Guidance collection: Protecting bulk personal data
Personnel security
Understanding what personnel security controls are in place is part of gaining confidence in your supplier.
This doesn’t just cover pre-employment checks and in-house personnel security controls, it also covers things like security awareness training and importantly, cultural considerations. Rolling out awareness training is more than just ticking a box to show this has been done, it is also about understanding whether it has had any effect and looking to address any underlying cultural issues that may be driving unsafe behaviours, or causing employees to develop security workarounds to do their job.
For UK government departments and CNI, the Centre for the Protection of National Infrastructure (CPNI) provides advice on personnel and physical security.
- Does the supplier carry out suitable background checks on employees and have processes in place for in-house personnel security controls?
- Does the supplier have security awareness training, covering common attacks on users, such as phishing and other means of enticing users to disclose sensitive information, or download unauthorised code?
- Does the supplier encourage a positive security culture? For example, do they encourage users to report suspected or actual incidents promptly in a no-blame environment?
- Has the supplier performed a risk assessment to understand their insider threat?
Useful links:
- Blog post: Growing positive security cultures
- https://www.cpni.gov.uk/personnel-and-people-security
- https://www.cpni.gov.uk/employment-screening
- https://www.cpni.gov.uk/personnel-security-maturity-model
- Guidance collection: You shape security
- https://www.cpni.gov.uk/insider-risk-assessment
- https://www.cpni.gov.uk/system/files/documents/63/29/insider-data-collection-study-report-of-main-findings.pdf
- https://docs.microsoft.com/en-us/microsoft-365/compliance/insider-risk-management-plan?view=o365-worldwide
Physical security
You should understand how your supplier physically protects its premises, data and assets. This will help you to gain confidence in their approach to security.
Physical controls include things such as perimeter defences, management of visitors on site and controls for more sensitive areas, such as data centres or sites where servers are located, and secure destruction and disposal of printed information.
Controls should be proportionate to the risk. For UK government departments and CNI, CPNI provides advice on personnel and physical security.
- Does the supplier have suitable physical controls in place to protect data, networks and premises?
- Do they securely dispose of sensitive printed information?
Useful links:
Independent testing and assurance
You should understand how the supplier is gaining confidence that their security controls are working in practice.
Security is a continuous, ever evolving process, so it’s important that the supplier is aware of how well their own security measures are performing.
An independent testing and assurance programme, for example, will give you some useful perspective on security controls. There are various options here, including the CHECK or CREST schemes.
Companies accredited by the NCSC under its CHECK scheme can analyse the systems or networks you rely on by conducting tests designed to identify publicly known vulnerabilities and common configuration faults.
CREST (The Council for Registered Ethical Security Testers) provides internationally recognised accreditations for organisations and individuals providing penetration testing, cyber incident response, threat intelligence and Security Operations Centre services.
- Does the supplier conduct any independent security tests, such as penetration tests of their internal and external IT infrastructure and remediate any findings?
Other contractual considerations
There are several other important considerations, so it’s worth thinking about whether your contract with the supplier should include any of the following:
- Are there any specific risk mitigations or controls in your contract with the supplier which must be passed down to all subcontractors?
- Would you wish to be informed if the supplier changes subcontractors?
- Does the supplier hold (or would you require them to hold) any cyber security certifications, such as Cyber Essentials, Cyber Essentials Plus or ISO27001?
• If so, does the scope of the certifications cover the parts of the service you will be using and how you will be using it?
- Will the supplier (or any subcontractors employed by the supplier) connect, or have access to, your data, IT network or premises?
• If so, how will this be limited, controlled, and monitored?
• For any remote access to your data or IT network, (for example in cases of outsourced IT support), do you have a remote access support agreement in place?
• Do you log their remote access sessions on your systems, with logs captured to reflect the work done?
- Contract exit – what provisions are in the contract for secure deletion or return of your data/assets at contract exit, including transfer of services, data or assets to another supplier?
- How will you monitor for changes in the information risk profile of the supplier over time? This can occur, for example, when the volume of data being processed by the supplier significantly increases, when different types of data are introduced (e.g. personal data or commercially sensitive data), or when new technology is introduced (e.g. mobile access platforms).
- Should you include a “right to audit” and/or regular reporting on security in your contract with the supplier? Should you require your supplier to build in a “right to audit” into contracts with their suppliers/subcontractors, where this affects the service to you?
Useful links:
- Guidance collection: Supply chain security guidance


