Supply Chain

The Factory team attended The National GovTech Show and Exhibition 2026 conference in Hatfields, London this week, a great event and varied conversations with both attendees and other exhibitors, a common discussion theme inspired this blog post.

So, you’re doing all the right things but what about your supply chain and how can you mitigate risk around suppliers?

Following the Marks and Spencer’s breach, I know, we all shudder and profusely wince, the impact and loss of revenue was beyond vast, the M&S teams, families, sleepless nights, the reputational hit. It wasn’t just Marks and Spenders either at that time, there was a succession of attacks on the Retail sector and beyond.

So, there’s good reason that a common question we get asked is; How do we make sure our supply chain is doing all the right things and how and what can we do to mitigate that risk?

Your teams are implementing all the right services, products, protocols, policies and building on that with a solid Cyber security roadmap, but what about your data that’s with external suppliers and what if an organisation in your supply chain is breached?

Based on what we see/do and coupled with current NCSC guidance here are some key considerations;

1.      A Cyber security partner, having a trusted and valued partner can be of immense value, we do say to even have two, as we don’t want to be “marking our own homework” as such. That partner though can offer guidance, support and security testing on new apps, systems and assist on documentation and policy for your supply chain.

2.      Know your suppliers – An approach like your own Cyber security posture is advisable, so such as you would with your systems/architecture, map your suppliers and what data they hold and process associated to your org.

3.      Criticality/risk score – Which suppliers can affect operations, data, systems, or customers? Do they have Cyber essentials, or Cyber essentials plus? Shared security protocols are ever more important in mitigation of risk, if they are doing all the right things and align to you, thats a big positive tick.

Many organisations now, specifically government are making Cyber essentials mandatory Cyber Essentials are significantly less likely to suffer from common cyber-attacks, including ransomware.

4.      Access – What level of access do they have to your systems/data? How do they access and control your data?

5.      Assurance – Request evidence of certifications from suppliers, pen test summaries of systems, applications, how they manage users with privileged or sensitive systems access.

6.      Resilience – If a key supplier, and again the Marks and Spencer’s attacks impacted many supplier, small to large, key suppliers suffered too from loss just as they did. Shared playbooks and Incident response plans make sense. Tabletop exercises are an excellent way to test these plans and identify gaps or risks that may otherwise be overlooked. They bring scenarios to life and often produce clear, actionable outcomes.

Here’s a link here to more info from the NCSC or do get in touch if a conversation/deeper dive that would be of value, we’d happily have that.

Guidance | National Cyber Security Centre

Share This Post

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore

CE Linking Info

Key (which links the agent back to our Installation); 6e3a49018092e010f277df557677e7e1c403ae7e7e9bb8f17727b3b571381105 Server;sensor.cloud.tenable.com:443 Groups;Leave empty – this particular key pops your agents in the correct group for

Do You Want To Boost Your Business?

drop us a line and keep in touch