Supply chain risk

Supply chain risk, assessed and mitigated.

Supply chain risk is the exposure an organisation carries through the third parties it depends on — the chance that a supplier’s failure, compromise or disappearance becomes your outage, your breach or your regulatory problem. This page covers what supply chain risk management is, how to run a supply chain risk assessment, what belongs in a supply chain risk management plan, and the mitigation that works once you accept the uncomfortable premise: you are accountable for risk you do not control.

What is supply chain risk management?

Supply chain risk management is the discipline of identifying, assessing and reducing the risk that reaches you through your suppliers rather than through your own estate. It spans the traditional concerns — a single-source component, a supplier’s insolvency, a geographic concentration — and the security concerns that now dominate: a supplier compromised, a shared platform breached, a software dependency poisoned upstream.

The structural problem is straightforward and does not go away. Your own security is something you can change. Your suppliers’ security is something you can only influence, usually through a contract signed before you knew what you would find. Everything below is about narrowing that gap.

Four properties make this risk class behave differently from internal risk:

  • It is transitive. Your supplier’s suppliers are also your exposure, and you have no contractual relationship with them at all.
  • It is concentrated in ways that are hard to see. Forty vendors can turn out to be four hosting providers and one identity provider.
  • It changes without telling you. A supplier is acquired, moves region, ships a new internet-facing service or loses its security lead — none of which generates a notification to you.
  • It is increasingly regulated. NIS2, DORA and the UK’s Cyber Security and Resilience Bill all place supplier duties on the buyer.

How to run a supply chain risk assessment

A risk assessment for a supply chain differs from an internal one in a specific way: most of the evidence belongs to someone else. The sequence below is built around that.

  1. Establish what the supply chain actually is
    Not the vendor list from procurement — the list of parties who hold your data, connect to your network, or whose failure stops you delivering. These are usually three different lists, and the union of them is larger than anyone expects. Start from accounts payable and integration logs rather than the contracts register.
  2. Tier by impact, not by spend
    Spend is a poor proxy for exposure. A £4,000-a-year tool with an API token into your CRM outranks a £2 million facilities contract. Tier on what the supplier can reach and what breaks without it.
  3. Establish inherent risk before asking anyone anything
    Data classification, access level, criticality to your service, jurisdiction, and whether they are a fourth-party route into you. This determines the depth of assessment each supplier warrants and stops you sending a 200-question document to a stationery supplier.
  4. Gather evidence from both directions
    Inside-out: questionnaires, certifications, policies, audit reports. Outside-in: what their external attack surface actually looks like, breach history, and public record. Each catches what the other misses — a questionnaire records intent, a scan records reality.
  5. Reconcile the two, and treat the gaps as findings
    The interesting output of a supply chain risk assessment is rarely a low score. It is the supplier who answered “yes, MFA everywhere” while an external view shows an exposed legacy portal. That contradiction is worth more than either source alone.
  6. Map the concentrations
    Aggregate the estate by hosting provider, identity provider, region and fourth-party dependency. Concentration risk is invisible supplier by supplier and obvious in aggregate.

What belongs in a supply chain risk management plan

A plan that survives contact with an auditor states decisions, owners and thresholds rather than intentions.

  • Scope and definitions
    What counts as a supplier, what counts as critical, and where the boundary sits between this plan and business continuity.
  • Tiering model with explicit criteria
    The rules that place a supplier in each tier, written so two people applying them reach the same answer.
  • Assessment cadence per tier
    How often each tier is reassessed, what triggers an off-cycle reassessment, and what continuous monitoring covers in between.
  • Risk acceptance thresholds and who may sign
    The single most-skipped section. If nobody has defined what is acceptable, every finding escalates and nothing gets closed.
  • Contractual security requirements
    Right to audit, incident notification windows that let you meet your own regulatory deadlines, subcontractor disclosure, and data destruction at exit.
  • Remediation workflow with SLAs
    Who chases, on what timetable, and what happens when a supplier does not respond.
  • Offboarding
    Access revocation, data destruction and evidence of it. Most registers quietly accumulate suppliers who left years ago and still hold credentials.

Supply chain cyber security: where the failures come from

Supply chain security incidents cluster into a small number of shapes. Knowing them shortens the assessment.

Compromise of a trusted supplier with access

A supplier with legitimate remote access or an API integration is compromised, and the attacker inherits that access. Managed service providers, remote-support tools and monitoring agents are the recurring examples, because the access is broad by design and rarely time-bound.

Compromise of software you install

A build pipeline or update mechanism is subverted and the malicious artefact arrives signed and trusted. This is the failure mode that produced software bill of materials requirements: you cannot reason about a dependency you cannot enumerate.

Shared-platform concentration

Many suppliers, one underlying platform. The individual assessments look fine and the aggregate exposure is a single point of failure that no per-supplier review surfaces.

Operational technology and physical supply

Where the supply chain reaches into plant and industrial control systems, third-party remote access is the leading breach vector and the consequences are physical. OT security deserves treatment on its own terms rather than as an IT problem with different acronyms.

Fourth parties

Your supplier’s supplier, with whom you have no contract, no questionnaire and no leverage. The mitigations here are disclosure obligations in the contract and discovery from the outside.

Supply chain risk mitigation that works

The difference between a programme that reduces risk and one that produces documents is mostly about what happens between assessments.

Common
Periodic assurance
  • Annual questionnaire to every supplier at the same depth
  • Certificates collected and filed, scope unread
  • Findings tracked in a spreadsheet with no SLA
  • Concentration never analysed in aggregate
  • Nothing observed between assessment cycles
Effective
Continuous assurance
  • Assessment depth set by inherent risk and access
  • Questionnaire answers reconciled against outside-in evidence
  • Remediation with owners, deadlines and escalation
  • Portfolio analysed for shared platforms and fourth parties
  • Material change detected when it happens, not at renewal

Managing supply chain risk at scale

The constraint is almost always people, not method. Ask most teams why suppliers are reviewed annually and the honest answer is not that a year is the right interval — it is that a year is what the team can physically get through. That is why supply chain risk programmes tend to fail quietly rather than visibly: the process is followed, the documents exist, and the coverage silently narrows to whichever suppliers were loudest. Any serious answer has to reduce the human cost per supplier, not just describe the ideal cycle.

Supply chain risk, answered.

What is supply chain risk management?
The practice of identifying, assessing and reducing risk that reaches your organisation through the third parties it depends on — covering security, resilience, concentration and regulatory exposure, rather than only commercial or delivery risk.
What is a supply chain risk assessment?
A structured evaluation of the risk a supplier introduces, based on what they can access, how critical they are, and evidence of how they operate. Done properly it combines what the supplier tells you with what can be observed independently, and treats disagreement between the two as a finding.
How often should suppliers be reassessed?
Cadence should follow tier: critical suppliers more frequently than low-impact ones. More useful than any fixed interval is event-driven reassessment — a breach, an acquisition, a material change in external posture, or a new integration — because risk does not change on your review schedule.
What is the difference between supply chain risk and third-party risk?
They overlap heavily and are often used interchangeably. In practice “third-party risk” usually describes the direct relationships you contract with, while “supply chain risk” is used more broadly to include fourth parties, physical and logistics dependencies, and software dependencies you never contracted for at all.
Which regulations impose supply chain security duties?
NIS2 Article 21(2)(d) requires measures covering each direct supplier and service provider; DORA sets obligations for EU financial entities and their critical ICT providers; and the UK’s Cyber Security and Resilience Bill extends duties to critical suppliers. Sector rules such as APRA CPS 230 impose similar requirements elsewhere.

Map the chain you actually have.

Book a 30-minute call and we will produce a scored risk view of your real supplier estate — including the fourth parties and shared platforms nobody put on the register.