Most businesses rely on an extensive supply chain to deliver for their customers – you probably have a number of suppliers yourself. Supply chains can be long and complex, with suppliers who are visible, and some that aren’t. Since the introduction of GDPR, businesses are more aware of the importance of a rigorous cybersecurity approach within their own IT systems, however business owners need to stop and think about whether they are doing the same thing with their suppliers, and can they be sure of the rigour those suppliers take with theirs?
A number of high-profile attacks has demonstrated that attackers can, and will, exploit the weakest link of the supply chain. Last year, Npower admitted a data breach in which the names, addresses, payment amounts and FIT reference numbers of around 5,000 of its customers were received through the post by the wrong people, leaving customers considerably concerned about identity fraud. Npower had used a fulfilment partner to send the postal mailing on their behalf. Ticketmaster were also the subject of a data breach in 2018 when malware was found in a third-party customer support service, underlining the importance of supply chain security.
These attacks stress that the supply chain is only as cyber secure as its weakest link, and in turn, the cybersecurity of a business is only as strong as the cybersecurity of all the suppliers it entrusts with its data. In short, a business could be risking the trust of its customers and its reputation if it doesn’t take every precaution to ensure members of its supply chain have a robust approach to cybersecurity.
Ian Kennedy-Compston, CEO of EnterpriseRed says “The procurement due diligence process should cover cybersecurity checks to satisfy companies but it should not be a “one and done” process. It’s important that suppliers are closely monitored to ensure they use the right tools and support to predict, prevent and detect vulnerabilities to protect customers and others in the supply chain.”
As a minimum, the initial procurement process should ask for proof of recent penetration testing by suppliers. However, EnterpriseRed suggests that it should also be a case of checking whether employees are given appropriate and regular cybersecurity training to reduce vulnerability to attack or breach.
Furthermore, such checks should be ongoing through the life-cycle of a contract with a supplier: an organisation that conducts regular penetration tests and strengthens their team’s cybersecurity training stands a greater chance of blocking cyber-attacks which could affect not only their own business but that of others in the supply chain.
EnterpriseRed offers a range of penetration testing and cybersecurity training and assessment services to help you identify vulnerabilities in your network and supply chain and strengthen your team.
If you would like to predict, prevent and detect cyber attacks on your business, get in touch today to find out more about our tools and support to help you protect your business.
