In today’s interconnected world, organisations are not alone in their quest for digital resilience. Security risks in the supply chain have made it evident that cyber security is not only a self-centric issue but extends to all those we collaborate with, including our third-party suppliers. As a Chief Information Security Officer (CISO), it’s essential not to underestimate the importance of supplier cyber security in safeguarding your organisation’s sensitive data. So what strategies can be deployed to manage third-party information security risks effectively?
Data breaches originating from third-party suppliers have been a frequent cause for concern in recent years. According to the 2022 Data Risk & Security report, 60% of UK businesses have experienced a cyber breach caused by a third-party supplier. Notably, the UK’s GDPR and Data Protection Act 2018 hold organisations accountable for any data breaches, even if they originate from a third-party. Therefore, supplier cyber security is not a ‘nice to have’ but a mandatory requirement.
Here are some suggested strategies for monitoring, mitigating and managing supply chain risks:
Third-Party Risk Assessments: Before establishing a relationship with a supplier, it is paramount to conduct a comprehensive risk assessment. The risk assessment should focus on the supplier’s information security measures, compliance with UK regulations, and ability to respond to potential security incidents.
Security Requirements in Contracts: Legal agreements with suppliers should clearly articulate the security standards to be maintained. These agreements can include for example stipulations regarding adherence to the UK’s Cyber Essentials scheme, a government-backed initiative that outlines the fundamental elements of cyber security, or ISO 27001 standards.
Continuous Monitoring: Regular audits and reviews should be conducted to ensure third-party compliance with contractual security requirements. The use of cyber security scorecards or ratings can provide an objective view of a supplier’s cyber health.
Incident Response Planning: Collaboration with suppliers should include the development of a coordinated incident response plan should a breach occur. This plan will outline the steps to be taken if a security incident occurs, including the reporting of incidents in accordance with the UK’s GDPR and the Network and Information Systems (NIS) Regulations 2018.
Security Awareness and Training: Regular training and awareness programs can enhance your supplier’s understanding of security policies, procedures, and expectations. The National Cyber Security Centre (NCSC) provides several resources that can be incorporated into these programs and which will help align your suppliers with your own information security standards and policies.
Managing third-party information security risks is not an isolated activity. It requires a holistic, organisation-wide approach. CISOs play a critical role in embedding cyber security into the DNA of their organisation, extending it across the entire supply chain.
By embracing strategies such as rigorous risk assessments, contractual security requirements, continuous monitoring, incident response planning, and regular training, organisations can create a resilient ecosystem that effectively counters the ever-evolving threat landscape.
Remember, in cyber security, your defence is only as strong as the weakest link. Ensuring robust third-party security measures helps transform this weak link into a fortified barrier, contributing to the holistic security posture of your organisation.