Part III · Chapter 18

Supply chain security

The Cybersecurity Act sets requirements on the security of those you depend on, not only on your own. That makes supplier security one of the most demanding areas, because the control sits outside your own organisation. This chapter works through a five step model for supplier governance, treats cloud providers as a special case, and makes visible the dependency on software nobody ordered.

  • CISOs and security leads

Last reviewed

One of the clearest patterns in recent years of attacks on Swedish organisations is that the victim was rarely the target. The way in ran through a supplier, often a small one, often one nobody had thought of as critical. The shared supplier is a single point that can bring down many operations at once, and it appears in none of the victims' own risk registers.

The chapter opens with why the supply chain is so vulnerable, the structural asymmetry between responsibility and control. Responsibility follows the operation, but control ends at your own contract. Then follows the five step model, the backbone of the chapter, taking the work from mapping and classification through requirement setting and review to continuous follow up. Classification is the step that decides whether the work is doable at all, since an organisation reviewing every supplier equally hard is in practice reviewing none of them properly. Cloud providers get their own section because they break the assumptions of the model. They rarely negotiate terms, which moves the centre of gravity from contracts to exit planning. The software chain is dealt with next, the dependency on components that come along into the systems without anyone having ordered them or even knowing they are there. The sovereignty dimension links back to chapter 7 on digital sovereignty. Then comes what happens when the supplier actually is hit, procurement as the first and cheapest control, the specific third party requirements of DORA, a realistic timeline and the modern routes of attack into the chain.

The question has sharpened because the requirements are now passed backwards. Entities covered by the Cybersecurity Act have to set requirements on their suppliers, which means organisations not covered themselves meet the requirements through contracts. What used to be a recommendation has become a condition for being allowed to supply. Whoever can answer the requirements with work already in place wins business on it, while whoever cannot has to explain themselves in every procurement.

This page shows what the chapter covers and why the chain determines your own security. The five step model, the requirement wording and the timeline are in chapter 18 of the book.

The weakest link in your supply chain is your own weakest link. The only difference is that you cannot see it.

Key insights

  • The requirement covers the whole chain, but control exists only in your own contract. Procurement is therefore the first control.
  • Suppliers should be classified by criticality. Reviewing all of them equally hard means in practice that none is reviewed properly.
  • The software chain is the least visible dependency, because the components arrive without a decision.
  • Cloud providers rarely negotiate terms, which moves the work from contracts to exit planning.
  • When the supplier is hit it is your operation that stops, wherever the fault arose.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.