Published 22/02/2021 – est. 4 minutes to read.
Supplier procurement process
Supplier assurance has long been a component of a company’s procurement process. You need to know that you can rely on a supplier and that they are dependable and financially sound. The procurement team will assess financial risk, insurance, standards, supply chain and continuity. They will determine the risk of working with a prospective supplier and whether a long-term working relationship can be established.
Cybersecurity was often considered irrelevant or overlooked; however, several high-profile data breaches reported in the press over the past few years have prompted many procurement teams to begin incorporating cybersecurity into their supplier assurance programs. Often, the IT department is tasked with conducting a one-off cybersecurity assessment of a supplier and feeding back to the procurement team with either a positive or negative result. This approach does not accurately reflect a supplier’s cybersecurity assurance.
Criteria to assess
A more comprehensive starting point is to consider the impact criteria to assess the inherent cybersecurity risk each supplier presents.
- Do they process any personal or confidential data?
- Do they have access to your networks or systems?
- Do they have access to any APIs on your cloud-based systems?
What level of harm will affect your business if a supplier suffers a breach and data loss? With these questions, a cyber impact level can be determined, which will then guide the path forward for cyber assurance.
Suppliers with the highest cyber impact should adhere to the highest standards set out in ISO27001 or IASME Governance and be assessed accordingly. Suppliers with lower impact should demonstrate at least matching the standards set by Cyber Essentials and be assessed according to this framework. Using standards-based assessments places the responsibility on the supplier to demonstrate the level of cybersecurity controls they have in place, avoiding the need for hours of audit work.
Are you monitoring suppliers
There also needs to be a system in place to monitor suppliers’ ongoing compliance with cybersecurity standards. Repeat assessments should be carried out at least annually to ensure that suppliers maintain standards, or more often if there are concerns about an individual supplier or if improvement needs to be demonstrated.
The impact of the COVID-19 pandemic and the rush to provide remote-working solutions for staff have only heightened the risk of cyberattacks against suppliers. Some companies may already have secure solutions in place for remote workers; however, many others had to act quickly to implement systems without fully considering the cybersecurity risks involved. Many will leave things as they are and not revisit their implemented solutions to ensure they comply with security standards. This only underscores the importance of including cybersecurity in your supplier assurance program.
Our Supplier Assurance Service can be delivered independently or as part of our Cyber Team as a Service (CTaaS).
For more information on how we can help to manage your Supplier Risk, conduct a Cloud Security audit, or discuss our services, connect directly with our technical team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
