Supply chain security: how safe are the suppliers who can reach your systems?

October 8, 2026

Supply chain security is the part of cyber security most businesses have yet to get round to. Your own logins, multi-factor authentication and backups may be well managed, but the picture gets hazy once you look at everyone else: the IT provider, the CRM platform, the payroll bureau, the company that maintains the air conditioning. Each of those suppliers has some route into your systems or your data, and very few firms have written them all down.

Here’s what supply chain security means for regulated businesses, and where to start.

1. What is supply chain security?

Supply chain security is the work of understanding and managing the risk that comes from suppliers who can reach your systems or hold your data.

That covers the obvious ones, like your IT provider and your cloud software, and the less obvious ones too. The NCSC’s report on the UK legal sector lists billing platforms, heating and air conditioning systems, and cleaning contractors among the routes attackers use to get into law firms. If a supplier has a login, a remote connection or a copy of your data, you should have a record of it.

2. How common are supply chain attacks?

Supply chain compromise has become one of the main ways attackers get into organisations.

ENISA’s latest threat landscape puts supply chain at 10.6% of cyber risk across the EU. The reason is simple economics. Breaking into one provider gives an attacker access to every customer that provider serves.

We’ve seen this play out in the legal sector. When legal IT provider CTS was breached in November 2023, conveyancing stalled across the country, and reports put the number of affected firms at between 80 and 200. None of those firms had been attacked directly but they were affected due to the third party.

3. If my supplier is breached, am I still responsible?

In most regulated sectors, the responsibility stays with you.

Under UK GDPR, you remain responsible for your clients’ personal data wherever it is stored. In gambling, licence condition 1.1.2 makes licensees responsible for the third parties they contract with. In financial services, new FCA rules from March 2027 require in-scope firms to notify the regulator about material third-party arrangements, and DORA already asks EU financial firms to keep a full register of their technology suppliers.

When a supplier has an incident, the breach notification, the client conversations and the regulator’s questions all come to you.

4. How many businesses actually check their suppliers?

Very few UK businesses formally review the security of their suppliers.

The government’s Cyber Security Breaches Survey 2025/2026 found that only 15% of businesses review the risks posed by their immediate suppliers, and just 6% look at the wider supply chain behind them. Even among large businesses, the figure is under half.

Most suppliers take security seriously, and we’re not suggesting otherwise. The difficulty is that without asking, you have no way of telling which ones do.

5. What should I ask a supplier about security?

Ask how they protect your data, how they would tell you about an incident, and who they rely on in turn.

Useful questions include whether they hold Cyber Essentials or ISO 27001, whether staff who can reach your systems use multi-factor authentication, and how quickly they would notify you of a breach. Ask about their own suppliers too, because a CRM platform is often built on someone else’s cloud service.

Gambling operators saw exactly this in October 2025. When iGaming CRM provider Fast Track was breached, players’ passports and driving licences were exposed, while the casinos’ own systems were never touched.

Things to do when reviewing your supply chain

  • List every supplier with access to your systems or data, so you know what you’re actually managing.
  • Rank them by what they can reach, so your effort goes to the suppliers holding client data or running critical services.
  • Check your contracts for breach notification timescales, audit rights and what happens to your data when the contract ends.
  • Remove access you no longer need, including old accounts, API keys and remote support tools left behind by former suppliers.
  • Ask key suppliers for evidence, such as a Cyber Essentials Plus or ISO 27001 certificate, rather than relying on a sales conversation.
  • Agree who makes the call if a supplier reports an incident, so nobody is working it out under pressure.

If one of your suppliers told you tomorrow that they’d been breached, how quickly could you say which of your data was affected?

If you’d like to talk through your supplier list, book a meeting with us or connect with Jason Chaplin on LinkedIn: https://www.linkedin.com/in/jasonchaplin/

IT Backbone

Key metrics

We’re proud of how we perform

15 mins

Avg. response time

< 2 hours

Avg. resolution time

100%

positive feedback

79%

First contact resolution