Supply chain risk, assessed and mitigated.
Supply chain risk is the exposure an organisation carries through the third parties it depends on — the chance that a supplier’s failure, compromise or disappearance becomes your outage, your breach or your regulatory problem. This page covers what supply chain risk management is, how to run a supply chain risk assessment, what belongs in a supply chain risk management plan, and the mitigation that works once you accept the uncomfortable premise: you are accountable for risk you do not control.
What is supply chain risk management?
Supply chain risk management is the discipline of identifying, assessing and reducing the risk that reaches you through your suppliers rather than through your own estate. It spans the traditional concerns — a single-source component, a supplier’s insolvency, a geographic concentration — and the security concerns that now dominate: a supplier compromised, a shared platform breached, a software dependency poisoned upstream.
The structural problem is straightforward and does not go away. Your own security is something you can change. Your suppliers’ security is something you can only influence, usually through a contract signed before you knew what you would find. Everything below is about narrowing that gap.
Four properties make this risk class behave differently from internal risk:
- It is transitive. Your supplier’s suppliers are also your exposure, and you have no contractual relationship with them at all.
- It is concentrated in ways that are hard to see. Forty vendors can turn out to be four hosting providers and one identity provider.
- It changes without telling you. A supplier is acquired, moves region, ships a new internet-facing service or loses its security lead — none of which generates a notification to you.
- It is increasingly regulated. NIS2, DORA and the UK’s Cyber Security and Resilience Bill all place supplier duties on the buyer.
How to run a supply chain risk assessment
A risk assessment for a supply chain differs from an internal one in a specific way: most of the evidence belongs to someone else. The sequence below is built around that.
- Establish what the supply chain actually isNot the vendor list from procurement — the list of parties who hold your data, connect to your network, or whose failure stops you delivering. These are usually three different lists, and the union of them is larger than anyone expects. Start from accounts payable and integration logs rather than the contracts register.
- Tier by impact, not by spendSpend is a poor proxy for exposure. A £4,000-a-year tool with an API token into your CRM outranks a £2 million facilities contract. Tier on what the supplier can reach and what breaks without it.
- Establish inherent risk before asking anyone anythingData classification, access level, criticality to your service, jurisdiction, and whether they are a fourth-party route into you. This determines the depth of assessment each supplier warrants and stops you sending a 200-question document to a stationery supplier.
- Gather evidence from both directionsInside-out: questionnaires, certifications, policies, audit reports. Outside-in: what their external attack surface actually looks like, breach history, and public record. Each catches what the other misses — a questionnaire records intent, a scan records reality.
- Reconcile the two, and treat the gaps as findingsThe interesting output of a supply chain risk assessment is rarely a low score. It is the supplier who answered “yes, MFA everywhere” while an external view shows an exposed legacy portal. That contradiction is worth more than either source alone.
- Map the concentrationsAggregate the estate by hosting provider, identity provider, region and fourth-party dependency. Concentration risk is invisible supplier by supplier and obvious in aggregate.
What belongs in a supply chain risk management plan
A plan that survives contact with an auditor states decisions, owners and thresholds rather than intentions.
- Scope and definitionsWhat counts as a supplier, what counts as critical, and where the boundary sits between this plan and business continuity.
- Tiering model with explicit criteriaThe rules that place a supplier in each tier, written so two people applying them reach the same answer.
- Assessment cadence per tierHow often each tier is reassessed, what triggers an off-cycle reassessment, and what continuous monitoring covers in between.
- Risk acceptance thresholds and who may signThe single most-skipped section. If nobody has defined what is acceptable, every finding escalates and nothing gets closed.
- Contractual security requirementsRight to audit, incident notification windows that let you meet your own regulatory deadlines, subcontractor disclosure, and data destruction at exit.
- Remediation workflow with SLAsWho chases, on what timetable, and what happens when a supplier does not respond.
- OffboardingAccess revocation, data destruction and evidence of it. Most registers quietly accumulate suppliers who left years ago and still hold credentials.
Supply chain cyber security: where the failures come from
Supply chain security incidents cluster into a small number of shapes. Knowing them shortens the assessment.
Compromise of a trusted supplier with access
A supplier with legitimate remote access or an API integration is compromised, and the attacker inherits that access. Managed service providers, remote-support tools and monitoring agents are the recurring examples, because the access is broad by design and rarely time-bound.
Compromise of software you install
A build pipeline or update mechanism is subverted and the malicious artefact arrives signed and trusted. This is the failure mode that produced software bill of materials requirements: you cannot reason about a dependency you cannot enumerate.
Shared-platform concentration
Many suppliers, one underlying platform. The individual assessments look fine and the aggregate exposure is a single point of failure that no per-supplier review surfaces.
Operational technology and physical supply
Where the supply chain reaches into plant and industrial control systems, third-party remote access is the leading breach vector and the consequences are physical. OT security deserves treatment on its own terms rather than as an IT problem with different acronyms.
Fourth parties
Your supplier’s supplier, with whom you have no contract, no questionnaire and no leverage. The mitigations here are disclosure obligations in the contract and discovery from the outside.
Supply chain risk mitigation that works
The difference between a programme that reduces risk and one that produces documents is mostly about what happens between assessments.
- Annual questionnaire to every supplier at the same depth
- Certificates collected and filed, scope unread
- Findings tracked in a spreadsheet with no SLA
- Concentration never analysed in aggregate
- Nothing observed between assessment cycles
- Assessment depth set by inherent risk and access
- Questionnaire answers reconciled against outside-in evidence
- Remediation with owners, deadlines and escalation
- Portfolio analysed for shared platforms and fourth parties
- Material change detected when it happens, not at renewal
Managing supply chain risk at scale
Supply chain risk, answered.
What is supply chain risk management?
What is a supply chain risk assessment?
How often should suppliers be reassessed?
What is the difference between supply chain risk and third-party risk?
Which regulations impose supply chain security duties?
Go deeper.
Map the chain you actually have.
Book a 30-minute call and we will produce a scored risk view of your real supplier estate — including the fourth parties and shared platforms nobody put on the register.