Supply Chain Cybersecurity: How Can Companies Manage Third-Party Risks?

This is some text inside of a div block.
5
September 2, 2026

Table of contents

Introduction

For a long time, cybersecurity was viewed as an essentially internal matter: securing the network, protecting workstations, controlling access and monitoring the company's information systems. This approach is now showing its limitations.

Companies are increasingly at the heart of complex digital ecosystems made up of software providers, cloud service providers, managed service providers, SaaS vendors, consulting firms, subcontractors, partners and numerous open-source dependencies. A compromise at one of these organizations can allow an attacker to reach several organizations in a cascading attack.

The situation is now clearly recognized at European level. In its Threat Landscape 2025, ENISA highlights the increasing targeting of digital dependencies and supply chains: attackers are increasingly seeking to compromise providers or intermediary components in order to amplify the impact of their operations.

In this context, one question becomes essential: how can an organization manage a risk when a significant part of it lies with organizations it does not directly control?

The Supply Chain: A Key Component of Cybersecurity

The widespread use of digital services has profoundly transformed information systems. A company may now depend on dozens, or even hundreds, of suppliers to run its daily operations: cloud hosting, business software, collaboration tools, payment services, IT maintenance, cybersecurity, telecommunications and open-source software components.

This interconnection creates a paradox: the more functions a company outsources, the more capable it must be of managing the associated risks.

The risk may take the form of a compromise of a supplier's information system, the theft of credentials from a service provider with privileged access, a vulnerability in software or an open-source dependency, or the prolonged unavailability of a critical service.

The issue is therefore no longer simply whether the company's own information system is secure. Organizations must also ask whether the partners and suppliers they depend on are sufficiently resilient to avoid becoming their weakest point.

An Attack on a Supplier Can Become a Crisis for the Company

Supply chain attacks have a particular characteristic: they allow cyber attackers to multiply the leverage of an initial compromise.

Rather than directly attacking a highly protected large company, an attacker may seek to compromise a service provider with legitimate access to several customers. The supplier can therefore become a single point of compromise potentially affecting several organizations, environments and sectors.

ENISA specifically observes this trend in its Threat Landscape 2025: exploiting digital dependencies allows attackers to amplify the impact of their operations by leveraging the interconnected nature of digital ecosystems.

This reality is particularly important for suppliers with elevated privileges: managed service providers, cloud services, MSSPs, software vendors, monitoring tools and identity management solutions.

A question should therefore systematically be asked when assessing a third party: “What could an attacker do with the access this supplier has?”

The answer should determine not only the expected level of security, but also the continuity and reversibility measures that need to be put in place.

The Most Difficult Risk to Manage Is the One You Cannot See

One of the main challenges today is visibility. Large companies generally know their direct suppliers. However, they often have much more limited visibility into indirect dependencies.

A supplier may itself depend on a cloud hosting provider, software vendor, open-source library, subcontractor, cybersecurity provider or supplier located in another country. The chain can therefore quickly become extremely complex.

This is precisely why ENISA considers dependencies on ICT service providers to be one of the major emerging long-term risks.

The real challenge for companies is therefore no longer simply to map their suppliers, but rather to understand the critical dependencies hidden behind them.

NIS2: Supply Chain Security Becomes a Structural Requirement

This evolution is now reflected in European regulations.

The NIS2 Directive explicitly incorporates supply chain security into cybersecurity risk management measures. Article 21 requires essential and important entities to implement appropriate and proportionate technical, operational and organizational measures to manage risks affecting their network and information systems.

Simply requesting a security certificate or statement from suppliers is no longer sufficient.

In practice, organizations must be able to identify their critical suppliers, assess the risks associated with these dependencies and incorporate security requirements into their contractual relationships. They must also be able to monitor how these risks evolve over time and integrate supplier incidents into their crisis management frameworks.

ENISA also recommends a structured approach to supply chain cybersecurity covering areas such as risk management, supplier relationships, vulnerability management and the quality of products and services.

The logic is therefore clear: a supplier's security should no longer be checked only when the supplier is selected. It must be managed throughout the entire relationship.

DORA: A Particularly Demanding Approach to Third-Party Risk

In the financial sector, this approach is even more structured under DORA.

The European regulation on digital operational resilience requires financial entities to manage ICT third-party risk as an integral part of their IT risk management framework.

DORA notably emphasizes that outsourcing a function to an external provider does not transfer the financial entity's responsibility: the entity remains responsible for complying with its regulatory obligations. The company remains responsible for managing its risks and must have sufficient visibility over the services on which it depends, particularly when they are critical.

This approach provides a lesson that extends far beyond the financial sector: outsourcing a function does not mean outsourcing the risk.

For financial organizations as well as technology providers, third-party risk management therefore becomes a strategic process incorporating the identification of critical dependencies, supplier assessments, contractual requirements, ongoing risk monitoring and the ability to respond to a failure.

ISO 27001: Structuring Supplier Risk Management for the Long Term

Faced with this complexity, organizations need a framework that goes beyond occasional supplier questionnaires and siloed assessments. ISO/IEC 27001 provides a particularly relevant methodological foundation.

By relying on an Information Security Management System (ISMS), the standard makes it possible to incorporate supplier risk management into a structured and continuous improvement approach. It helps organizations identify critical dependencies, assess the associated risks, define proportionate security requirements and formalize responsibilities between the company and its partners.

This approach also makes it possible to integrate cybersecurity into procurement and contractual processes, monitor risks over time and retain the evidence required for audits.

Practical Checklist: How to Strengthen Supply Chain Cybersecurity

☑ Map all digital suppliers and service providers

☑ Identify critical suppliers and high-impact dependencies

☑ Assess risks according to the actual criticality of services and data

☑ Integrate cybersecurity requirements into procurement processes

☑ Strengthen contractual clauses relating to security and incidents

☑ Review privileged access granted to service providers

☑ Identify subcontractors and indirect dependencies where relevant

☑ Establish continuous monitoring of supplier risks

☑ Test scenarios involving the compromise or unavailability of a critical supplier

☑ Establish business continuity and reversibility mechanisms

☑ Include critical suppliers in crisis management exercises

☑ Document controls and retain the evidence required for audits

Towards Cybersecurity Across Your Entire Supply Chain

In 2026, cybersecurity no longer stops at the boundaries of your organization.

Information systems are increasingly interconnected, services are outsourced and dependency chains are multiplying. In this context, an organization's security also depends on its partners' ability to resist, detect and respond to cyberattacks.

European regulatory developments are moving in the same direction. NIS2 explicitly incorporates supply chain security into risk management, while DORA requires the financial sector to adopt a structured approach to ICT third-party risk.

Compliance should not, however, be the only motivation, because managing supplier risks is above all about protecting business continuity.

The goal is not to control every supplier with the same level of intensity, nor to multiply questionnaires and audits. It is to develop an overall view of dependencies, focus efforts on critical suppliers and build organizational resilience.

From this perspective, cybersecurity becomes a collective challenge: a truly resilient company is one that knows its dependencies, understands its risks and knows what to do when one of its partners becomes the entry point for a crisis.

Strengthen Your Supply Chain Cybersecurity

Would you like to assess your supplier risks, structure your cybersecurity framework or prepare for NIS2 and DORA requirements?


Discover DPO Consulting's Cybersecurity services: https://www.dpo-consulting.com/cybersecurity-compliance

or contact our experts to define an approach tailored to your organization: https://www.dpo-consulting.com/contact-us

Read this next

See all