Securing your data supply chain

Securing Your Data Supply Chain

For most organisations their security posture has typically focused on internal systems and operations. InfoSec teams are often constrained by resource pressure and the need to include an increasing array of external parties in their risk registers. And while an organisation may be confident in its own practices, can they be sure the same is true of their third party partners?

A good example occurred in May this year, when the Ministry of Defence suffered a major data breach through a third-party payroll system with names, bank details and addresses of regular, reserved and recently retired veterans being compromised.

To underline this point, the then Secretary of State for Defence told Parliament “that although this incident is entirely unrelated to our own MOD networks, we are also reviewing all personnel data networks to ensure that our people’s data is secure.” Put another way, “We believe our systems are secure, but our supply chain isn’t.”

In a world where outsourcing is pretty much the norm, interconnectedness and interoperability is sadly either rushed or relies upon legacy processes.

 

Where are the weakest links?

According to the Government’s Cyber security breaches survey 2024, it found that 50% of businesses and 32% of charities reported some form of cyber security breach over the past 12 months. Of these, 84% reported that breaches were due to phishing attacks. Yet, only 10% said they reviewed the risks posed by their immediate suppliers.

 

 

Creating a secure supply chain

As with many solutions, there are many steps that can be taken for little or no investment, and there are steps that may involve additional cost or time:

1. Identify your risks:
Review your supply chain to identify potential vulnerabilities and security risks.

2. Evaluate your suppliers:
Review the security practices and certifications of your suppliers to see if they meet or exceed your standards.

3. Add security clauses:
Include clear and enforceable security clauses in your supplier contracts.

4. Incident response plans:
Require suppliers to have incident response plans in place to quickly address any security breaches.

5. Collaborate:
Share security concerns and best practices with your suppliers.

6. Use secure data transfer tools:
Consider using secure methods for transferring data (in transit and at rest) between you and your suppliers.

7. Set access controls:
Limit who can access sensitive data within your supply chain.

8. Monitor & Alert:
Use monitoring tools to detect and respond to security threats in real-time.

9. Build internal awareness:
Educate your users and staff about supply chain security risks.

10. Check supplier training:
Check that your suppliers’ staff are trained on security best practices and understand their responsibilities.

11. Keep up to date:
Stay informed about emerging threats and vulnerabilities to adapt your security strategy.

12. Hold regular reviews:
Conduct regular reviews of your supply chain security practices and implement changes as and when needed.

Closing Thoughts

You may not be your brother’s keeper, but it is important (and prudent) that you have confidence in your suppliers’ ability to keep your communications, data and IP secure. After all, cyber criminals only have to get lucky once…

As a business that holds ISO 27001:2017, we were encouraged to see how this updated standard has introduced changes and enhancements to keep pace with changing threats and best practices. In particular, the inclusion of new controls specifically addressing cybersecurity threats, such as ransomware and supply chain attacks (ISO 27001:2022 Annex A 5.21). We’ll be covering this subject in depth in an upcoming article.

In fact, we have seen a significant increase in clients requesting information from us as part of their supply chain management assessment process. Curiously, this increase is almost exclusively within the private sector, which is somewhat strange as statistics show that Healthcare and Public Sector organisations are two of the most vulnerable sectors to cyber attacks.

Two common arguments we often hear as to why government run and public sector organisations are slow to tackle this problem are cost & complexity. In our experience, with many clients across both sectors, these views can be a little misleading. 

As can be seen from our Pricing Tool, cost-effective data security solutions are not that cost-prohibitive. Likewise, in terms of complexity, as a managed security service, we are there to remove the headaches and challenges of Secure File Sharing for our clients.

Facebook
Twitter
LinkedIn
Email

Want to know more?

Call Us

01904 500255

Message Us