Share this article
You could be a service provider, supplier, vendor, distributor or retailer but regardless of your role, you are almost certainly in a mutually beneficial relationship with other businesses. This means that to be secure it is not enough to look at your own organisation’s people, systems and infrastructure. You need to look at your partners because your cyber health is only as safe as the weakest link in your supply chain.
If the last twelve months of the global pandemic has taught us anything, it is that our behaviours and our state of health are closely connected to others. While we may safeguard ourselves by taking the recommended precautions, we are also reliant on others taking a stringent approach to risk in order to minimise the risk of infection.
It can certainly be useful to think of our information security in the same terms as the spread of Covid-19. We all need to do our bit to reduce the transmission of a disease, just as we all have a responsibility to preserve the integrity of our data and sensitive information that may impact on others. Similarly, if just one of your supply chain partners is not taking data security seriously, your own position is compromised and you may even be held accountable if a breach occurs.
Supply chains have always been a target, for the simple reason that maintaining robust information security processes and procedures between organisations is a much harder task than controlling internal ones. However, it’s become apparent that supply chain vulnerabilities are getting worse. As the data transfer and business interactions between organisations grows and the volume of data moving between parties increases at pace, there are inevitable challenges to a business’s risk posture.
Not only that but recent attacks like the SolarWinds breach have demonstrated how even proactive organisations following best practice in relation to patching and installing updates can fall foul of breaches that hit their software providers.
Research confirms that supply chains are the single greatest risk to cyber security. In 2017 it was found that 80 per cent of all cyber breaches began within the supply chain. Of course, since the onset of the Covid-19 pandemic the cyber security landscape has changed dramatically. But, so have the risks.
The surge in demand for online transactions has been exacerbated by “the Amazon effect”, the pressure to process orders and deliver them incredibly quickly. Meanwhile, remote working has meant that data and payments are often being managed by staff who are removed from the office environment and away from the close supervision of a CISO or IT department.
Combine these factors together and you have a perfect storm for hackers who have, inevitably, stepped up their game. And, ever pragmatic, hackers are continuing to focus on SMEs and supply chain partners where they consider there are vulnerabilities that can be more easily exploited.
So, what steps can you take to safeguard your data and build resilience into your own supply chain?
The smartest and simplest thing to do is to use one of the cyber security standards which provide a framework for cyber security best practice. If you are part of the supply chain and working in conjunction with a larger organisation then Cyber Essentials certification may be sufficient. Depending on the size of business, however, ISO 27001 compliance can provide a greater level of security – due to the fact that it is a more rigorous and robust standard. Both will require an investment in time and resource, but with professional guidance from ISO 27001 consultants the process for each can be conducted in a timely and cost-effective manner. In the context of a breach, this represents a wise investment.
Sometimes it is not enough to do the right thing; you also need to be seen to be doing it. Through Cyber Essentials or the ISO 27001 standard you can demonstrate to your customers and your supply chain partners that you prioritise data security and have followed best practice standards. This will provide them with reassurance and confidence. In fact, many organisations now insist upon one or both of these before taking on a new supply chain partner.
Just as you can demonstrate your commitment to cyber security through cyber security standards, you should be looking for the same standards from your suppliers and business partners. That way you know they too have taken practical steps to follow best practice. In turn, being able to evidence this stance to the rest of your supply chain will provide them with tangible proof of a proactive strategy on your part.