24/7 Support Available
Skip to main content
Intermediate
2 to 4 weeks

Supply Chain Security Assessment

A structured way to manage third party cyber risk: know who your suppliers are, sort them by the risk they carry, check the important ones properly, and keep watching the relationships that matter.

Prerequisites

  • A complete list of your suppliers, including the smaller software tools individual teams have signed up for.
  • An understanding of what data each supplier holds and what systems they can reach.
  • A standard security questionnaire, or an accepted framework you can point suppliers to.
  • Contract owners who can build security requirements into agreements at renewal.

Step-by-Step Instructions

Build a complete supplier inventory

You cannot manage risk from suppliers you have forgotten about. Pull together a full list, including the cloud tools that teams have adopted without going through procurement, since these often hold real data. For each one, record what data they hold, what systems they connect to, and how central they are to your operation.

Sort suppliers by risk

Not every supplier deserves the same scrutiny, so tier them. A provider that hosts your customer data or connects directly into your network is high risk and needs close attention. A supplier with no access to your systems or data is low risk. This sorting lets you spend your effort where a failure would actually hurt.

Tip

Some of your biggest exposure sits with small suppliers that have deep access, such as an IT support firm or a niche software tool. Judge suppliers by the access and data they hold, not by their size.

Assess the ones that matter

For your higher risk suppliers, ask for evidence rather than assurances. A recognised certification such as Cyber Essentials, ISO 27001 or a SOC 2 report shows an independent assessor has checked their controls. Where none exists, a focused security questionnaire covering access control, encryption, patching and incident response gives you a useful picture.

Put requirements in the contract

A questionnaire is a snapshot, but a contract sets ongoing expectations. Build security clauses into agreements: the standards the supplier must meet, their duty to tell you about a breach that affects your data, and your right to review their controls. Renewal is the natural moment to raise the bar for suppliers already on your books.

Limit and monitor their access

Give each supplier the least access their service needs, and no more. Remove standing access they do not use, prefer time limited access for support work, and log what they do in your systems. If a supplier is compromised, tight access is what stops their problem becoming yours.

Keep watching and plan for failure

Supplier risk is not a one off check. Reassess your important suppliers regularly, watch for news of breaches among them, and know what you would do if a critical one went down or was compromised. The most damaging incidents often arrive through a trusted supplier, so the relationships worth the most attention are the ones you depend on daily.

Every organisation is different, and a playbook can only take you so far. If you would like a second pair of eyes, or you would rather we handled the work, our penetration testing team is here to help. Talk to us about your requirements.