ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Sussing out suppliers

Abdullah Mirza at CTM360 shares insights into how businesses can evaluate third party risk before and during the contract

 

Third parties are rapidly becoming the Achilles heel of the business as initiatives such as Zero Trust kick in, making it harder to compromise the network.

 

Gartner estimates that 45% of organisations worldwide will have experienced attacks on their software supply chains by 2025 and supply chain attacks were up 633% last year. As a result of this increased threat, there is now a 70% chance that a cyber-security incident will be caused by an organisation’s suppliers. 

 

Yet, despite supplier risk reaching crisis levels, only 13% of UK businesses assess the risks posed by their immediate suppliers and the proportion of those reviewing the wider supply chain is even less at 8%.

 

Even among those that subscribe to the NCSC’s 10 Steps to Cyber Security, which lists supply chain security as a requirement, only 14% said they monitored risks from suppliers or the wider supply chain. Just 38% carry out a formal assessment. So why aren’t businesses doing more?

 

The Cyber Security Breaches Survey 2022 found many did not believe cyber-security was an important factor in the procurement process, so do not assess suppliers before engaging them. Once they had taken on a supplier, many did not carry out any extensive due diligence or measurement of KPIs, nor were risks reviewed during the span of the contract.

 

Fast forward a year and the same survey found post-procurement was still challenging. Many felt they just had to trust suppliers to follow contracts and that it was difficult to extract further information if suppliers were not forthcoming.

 

Obstacles to risk management

The main reasons given for this failure to undertake a formal review of supplier or supply chain risk was lack of time and money (32%) and an inability to get the information necessary from suppliers in order to carry out the checks (31% up from 28% the previous year). Others said they didn’t know what to check (25%) or felt they lacked the skills to do so (18%).

 

But failing to detect supply chain risks can prove costly, with 83% of legal and compliance leaders detecting third party risks after they had onboarded suppliers, according to Gartner.

 

Clearly there’s a need to address this issue by making it easier to assess the risk posed by a supplier before and during the lifespan of the contract. But lacking both the resource and information necessary to do so means businesses are having to make uninformed decisions or to accurately determine their risk exposure when trading with a supplier. Consequently, they can’t hold that supplier to the terms and conditions of the Service Level Agreement (SLA). 

 

Advances in External Attack Surface Management (EASM), Digital Risk Protection (DRP) and Cyber-Threat Intelligence (CTI) mean it’s now possible to assess and score the supplier’s digital infrastructure without any requests needing to be made.

 

The convergence of these three technologies into a single offering has been dubbed External Risk Mitigation and Management (ERMM) by analyst house, Frost and Sullivan, who see it as an emerging field in cyber-security.

 

Taking a hacker’s eye view

ERMM enables automatic searches to be carried out which inventorises the third party’s digital presence across the internet, effectively providing a hacker’s eye view of any exploitable weaknesses. 

 

A portfolio is created for each supplier within which the risk score is calculated based on the vulnerabilities, level of exposure, IT hygiene and misconfiguration detected from the supplier’s website, IP address and domain.

 

As this search can be performed without deployment or configuration of any software and without the need for input from the supplier, organisations can avoid the problem of extracting information from the supplier.

 

The external inventory can be updated on a daily basis in real-time to give a continuous risk score. Regular monitoring can also be used to determine how the supplier is managing and maintaining their security posture and to detect any changes.

 

Ideally, this risk score assessment should then be supplemented with an assessment of the supplier’s internal security which can be obtained via a questionnaire. 

 

A growing problem

Addressing third party risk management is a growing problem, with 71% of organisations seeing an uptick in the number of third parties under contract over the past three years. That growth is predicted to continue due to outsourcing and the introduction of new services, but security isn’t keeping pace.

 

Alongside this, many are routinely failing to spot risk, with 84% reporting misses that then led to operational disruption, adverse financial impact, increased regulatory scrutiny, reputational impact or the need to take regulatory action, states Gartner. 

 

Mitigating these impacts means the approach to assessing supplier risk must change. The most resilient business can only ever be as secure as the weakest supplier in its supply chain, making it imperative to monitor and manage supply chain security.

 

Relying on goodwill and asking the right questions in lengthy security questionnaires is no longer sufficient. We must look to make risk assessment real-time and responsive in order to improve supply chain security as a whole. 

 


 

Abdullah Mirza is a Director at CTM360

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543