On 19 September 2024, Digital Transformation host Kevin Crane was joined by Chuck Brooks, Adjunct Professor, Georgetown University; Stuart Frost, Head of Enterprise Security & RIsk Management, Department for Work & Pensions; and Andy Grayland, CISO, Silobreaker.
A security vendor’s poll revealed that, in the UK, 53% of respondents had succumbed to ransomware over the past year, up from 38% in the 2023 report. Of these, more than half (59%) claimed that they’d paid a ransom, while 74% of British respondents said that they would do the same if victimized by ransomware actors and just 7% of UK respondents ruled out paying, despite the fact that two-thirds (66%) apparently have clear rules not to pay. Paradoxically, companies that can’t afford cyber security controls can pay a similar amount as ransom when they have no other choice to recover their data, while, globally, 80 % of companies that have paid were targeted again. The figures of the article give a good indication, but some of the figures must be taken with a pinch of salt. Recently, a middle way has been emerging between resource intensive – high pay off and low hanging fruit – low pay off attacks, where cyber criminals attack big companies through their weak supply chain links. For infosecurity to be more effective, more security professionals are needed with strong interpersonal and communication skills who can sell infosecurity and the value it creates.
When assessing 3P risks, businesses should start with their vendors by setting standards that they expect their 3Ps to meet. In the UK, currently just 11% of companies are looking at the risks of their first tier suppliers, and still less look beyond first tier. A new way of tiering by the amount and criticality of the data that a supplier has access to may be very useful here. After identifying critial suppliers, they should be audited and subjected to continuous risk management. When this is completed, you can ask your most important suppliers to report on their business critical suppliers.
However, an argument against audits, especially outsourced ones, can be that they are often only tick-the-box exercises. The most thorough audit a business can have is the one carried out by independent auditors – usually once a year. One of the major problem with companies due diligence procedures is the lack of consistency – even within the same platform, let alone in spreadsheets. Security is just one party involved in awarding a contract – there are business, operational and commercial considerations as well. But security should always be involved in the pre-contract stage. As due diligence processes are expensive to implement, big companies have a kind of responsibility to give out some of their expertise to their small and medium size suppliers.
Trust building is also an important factor. Reporting should be decoupled from the stigma of being responsible for a breach, because it’s more important for the community to know that an incident did take place than who was at fault. There are plenty of information sharing software out there (CTI is an open source one), but they need to be populated first. The speed at which the sophistication of attacks is increasing calls for cooperation between governments and the private sector. Remember that threat intelligence must be made relevant by providing context including vulnerability and business impact information. But no threat intelligence will work without a foundation of internal security controls and an info security management system (ISMS). In the UK, an SME can start its security journey, while in the US NIST is a great tool when creating a risk management strategy. Although NIST is quite heavy for some industries, a business can implement only certain aspects of it.
Businesses should seek to find a security partner that is targeted to the risks that you have identified within your organisation – without identifying those risks you won’t be able to find the right solution. 3P security platforms offer dashboards that will tell you about the new threats that the most recent incidents detected on the dark web present for your supply chain. Even small companies may be able to take advantage of such a tool. That said, you also need analysts to make the most of these tools and to avoid false positives. A much cheaper version can be for SMEs to set up a Google alert with keywords for security breaches and other incidents – although that won’t take the cyber security of the company too far. Security controls are not the only criteria to look out for when selecting suppliers, as the level of their resilience is also key, i.e., how long they take to recover from an incident. The future of infosecurity is ZeroTrust, where you have visibility of who accesses your network and what level of access they have.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543