ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Nth-party risk and cyber security

Phil Robinson at Prism Infosec considers whether organisations need to assess the wider supply chain when managing third party cyber risk

 

Large businesses are finally starting to get to grip with supply chain security, according to the UK government’s Cyber Security Breaches Survey 2023 which revealed that, for the first time, the majority are now assessing third party risk.

 

However, only a third (34%) are assessing the wider supply chain and the figure plummets further if SMEs are brought into the picture to just 8%. What’s more, only 22% of organisations have faith today in their third party risk management processes to mitigate Nth party risks, according to the Ponemon 2022 Study: Data risk in the third-party ecosystem.

 

So why aren’t businesses assessing fourth or Nth suppliers and should they be doing so?

 

The wider supply chain can be described as the sub-contractors that suppliers then use to fulfil their contractual requirements. Determining who these are will require the business to map its suppliers and those they work with, which aside from being time intensive can be highly complex.

 

As the National Cyber Security Centre (NCSC) states in its advice on the matter, there are numerous considerations here, such as: how far you go, which elements of the business have been subcontracted, criticality to the end business, and the value of the information versus the cost of obtaining it. 

 

Mapping the supply chain

The NCSC has just launched two e-learning modules on mapping supply chain risk that can help in this respect and it’s also possible to evaluate supplier risk using technology such as by looking at the risk exposure of supplier systems and processes online. But it’s still necessary to obtain some information direct.

 

It’s therefore worth building into the procurement process a supplier questionnaire and clauses in the contract outlining what information you expect on their risks and those of their subcontractors, to provide your business with assurance. 

 

The NCSC emphasises that businesses should always start by mapping their direct contractors before looking at the wider supply chain because of the complexity involved.

 

But it’s also worth remembering that the longer the supply chain is, the greater the risk as the invested parties all potentially provide an entry point to the attacker. Therefore, knowing precisely what parties constitute your extended supply chain can pay dividends.

 

To start with, mapping the chain can give the business insights into security issues that could be enforced within the contract, for example, providing added legal protection that can dovetail with compliance requirements.

 

It also makes it easier to respond in the event of a breach by virtue of the fact it then becomes easier to coordinate response and control impact. It sets a precedent and repeatable processes that can be used to build confidence in and nurture long term relationships with suppliers.

 

And it reduces the likelihood of a cyber-attack, as risks are routinely assessed, and measures put in place to mitigate them.

 

Just 32% of businesses claim to have a comprehensive inventory of all of their third parties, however, according to the Ponemon report, and this is merely the start of the process. 

 

Mapping also involves showing the links and co-dependencies between suppliers and their sub-contractors, documenting the product or service being delivered and its importance to the business, information flows between all parties, contacts for liaison, audit information on scheduled assessments and actions, as well as any relevant certifications which stipulate supply chain risk management, such as Cyber Essentials or ISO 27001. 

 

Don’t forget the data

Even with all of this in place, there is another important consideration and that’s the data supply chain. Inventorying the software in use and flow of data are important particularly in the light of software supply chain attacks which saw a 633% increase last year. 

 

The “Apache Log4j” vulnerability, for instance, saw exploitable Java code embedded within applications throughout the supply chain and those that were able to pinpoint where it was used could patch far more quickly.

 

Yet the Ponemon report found only 44% audit and assess supplier data handling practices and even less (35%) monitor Nth parties. Moreover, only 36% were notified when third parties shared their data with Nth parties.

 

The recent exploitation of the MOVEit file transfer software also illustrates how widespread the impact can be from a trusted application. The ransomware operator, Clop, has so far listed 103 targets on its website that were compromised in the attack, all of whom now need to establish whether their partners will be affected by the extortion campaign if their data was housed on the application.

 

Such examples reveal how inter-dependent businesses are becoming while macro factors such as the pandemic, geo-political unrest, and supply chain focused cyber attacks are now increasing pressure on the business to create a more resilient supply chain.

 

Knowing who your suppliers are, who they sub-contract to and the threat both might pose to your ability to continue with Business as Usual (BAU) therefore must become a higher priority. 

 


 

Phil Robinson is Principal Consultant at Prism Infosec

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543