Many companies have their internal security measures well under control today. But what about suppliers, IT service providers and other external partners?
In increasingly interconnected supply chains in particular, risks often arise where third parties gain access to data, systems or critical business processes. A lack of transparency, differing security standards or unclear responsibilities can mean that a supplier’s weaknesses suddenly become your own corporate risk.
It is therefore no longer enough to consider information security only within your own organisation. Anyone who wants to strengthen their resilience also has to know, assess and continuously monitor the security posture of their most important suppliers.
Suppliers are part of your own security landscape
Cloud providers, software manufacturers, IT service providers, outsourcing partners and traditional suppliers are today deeply integrated into corporate processes. They process data, operate systems, provide software or take on services without which some central business processes would no longer function.
This also changes the risk picture. A security incident at a supplier can lead to consequences such as:
- business interruptions
- data loss or data protection breaches
- limited availability of important services
- reputational damage
- regulatory or contractual problems
The decisive question is therefore no longer only: how secure are our own systems? But increasingly also: how well do we know and manage the risks of our most important suppliers?
An ISO 27001 certificate alone does not answer this question
Certification to ISO/IEC 27001 can be an important indication that a supplier organises information security systematically. It does not, however, replace your own risk assessment.
The first thing to check is what exactly has been certified. The scope of a certification may cover only certain sites, legal entities, processes or services. For your own supplier relationship it is therefore decisive whether the service actually purchased falls within that scope.
The certification body itself should also be considered. Accreditation independently confirms that a certification body works according to recognised requirements and has the corresponding competence. A missing accreditation does not automatically mean that a certification is worthless. It does not, however, offer the same independent confirmation of the certification body’s competence.
For a well-founded supplier assessment it is therefore worth looking more closely:
- Is the certificate current?
- Which organisational units and services does it cover?
- Who issued the certificate?
- Is the certification body accredited?
- Does the scope match the service actually purchased?
- Which additional risks exist independently of the certification?
A certificate is therefore a valuable building block – but not the entire security assessment.
Supply chain risks carry more weight in established frameworks too
The NIST Cybersecurity Framework 2.0 also shows that supplier risks are an integral part of cybersecurity management.
Version 2.0 added the Govern function to the framework and once again clearly emphasised the importance of governance and cybersecurity risks in the supply chain.
Among other things, NIST provides for defining requirements for suppliers, checking risks before a business relationship begins, and assessing and monitoring supplier risks throughout the entire cooperation.
This makes it clear: supplier security is not an isolated procurement task. It belongs to company-wide risk management.
Supplier assessments: demanding, but indispensable
Structured supplier assessments are a central instrument for managing these risks.
In practice, however, such assessments are often demanding. Questionnaires are sent out by Excel or email, answers are documented inconsistently and assessments are made against varying criteria.
Typical challenges are:
- differing questions and assessment criteria
- a lack of comparability between suppliers
- considerable manual coordination effort
- follow-up queries and incomplete answers
- decentralised storage of documents and evidence
- no history of earlier assessments
- unclear responsibilities for identified risks
The problem is not the questionnaire itself. What matters is what happens with the results after the assessment.
Are identified risks documented? Who decides whether a risk can be accepted? Which measures does the supplier have to implement? Who tracks those measures? And when is the next assessment due?
Only once these questions are answered does a supplier questionnaire turn into effective supplier risk management.
A structured process creates comparability
A good supplier assessment should therefore follow a traceable process.
The first thing to clarify is how critical a supplier actually is for the company. A service provider with access to sensitive corporate data has to be judged differently than a supplier without access to relevant systems or information.
Depending on the risk class, different requirements and levels of scrutiny can then be defined.
A structured assessment process brings several advantages:
- Comparability: suppliers are assessed against traceable criteria.
- Risk orientation: critical suppliers can be examined more intensively than less relevant partners.
- Traceability: assessments and decisions remain documented.
- Early detection: security and compliance gaps become visible before they turn into an incident.
- Measure management: identified weaknesses can be converted directly into concrete tasks.
- Management overview: risks across the supplier landscape can be presented in consolidated form.
This turns supplier assessment from an administrative obligation into a genuine management instrument.
Supplier security is not a one-off check
One of the biggest weaknesses of classic supplier assessments: they always reflect only one particular point in time.
A supplier can be well positioned today – and have a completely different risk profile twelve months later.
New technologies are introduced. Subcontractors change. Responsibilities shift. Companies are acquired. Certifications expire. New vulnerabilities become known, or previously non-critical services suddenly become relevant for central business processes.
Supplier security should therefore be understood as a continuous process. This includes, for example:
Regular reassessments
Critical suppliers should be reassessed at defined intervals.
Event-driven assessments
An additional review can make sense in the case of material changes, new services or
security incidents.
Monitoring of certificates and evidence
Expiry dates and changes should be identified in good time.
Clear escalation processes
If answers fail to arrive or critical risks are identified, it has to be defined how to
proceed.
Tracking of measures
An identified weakness is only really addressed once the agreed measure has been
implemented and verified.
This is how a point-in-time assessment becomes continuous third-party risk management.
How fortControl supports supplier assessments
With several suppliers it quickly becomes clear why Excel files, email threads and individual documents reach their limits.
fortControl helps companies map supplier assessments in a structured and traceable way. Based on standardised or individually adapted question catalogues, relevant information on information security, certifications, services and further security criteria can be recorded centrally.
Suppliers can complete and return questionnaires digitally. This reduces the administrative effort and makes information available in structured form for further assessment.
The major advantage lies in transparency. Assessment results can be compared and presented clearly. Security areas can be visualised in a radar chart, for example. Identified risks can then be linked to concrete measures and responsibilities.
This makes visible:
- which suppliers present an elevated risk
- in which security areas action is required
- which measures have been agreed
- who is responsible for them
- how a supplier’s assessment has developed over time
Versioning, history and reporting preserve earlier assessments and keep developments traceable. This not only makes day-to-day work easier, but also creates a solid basis for internal controls, audits and management decisions.
From questionnaire to continuous supplier risk management
The goal of a supplier assessment should not be to ask as many questions as possible. What matters is drawing the right conclusions from the answers.
An effective process therefore combines four elements:
- 1 Assess
- 2 Understand
- 3 Act
- 4 Monitor
A supplier's security posture is reviewed regularly: the one-off check becomes a continuous process.
Risks are first recorded and assessed in a structured way. It is then decided which risks can be accepted and where measures are required. Their implementation is tracked and the supplier’s security posture is reviewed regularly.
That is precisely how transparency across the entire supplier landscape emerges.
Structure creates security – beyond company boundaries too
Information security does not end at your own company boundary.
The more digitally interconnected companies are, the more important the ability becomes to assess risks at suppliers and other external partners in a structured way.
Certifications can provide valuable indications here. But they replace neither a check of the specific scope nor a risk-based assessment of the respective business relationship.
Companies should therefore know their critical suppliers, define clear security requirements, document assessments traceably and follow up on identified risks consistently.
Because the decisive weak point does not have to be inside your own company. It can be one supplier away.
With fortControl, companies create a central basis for assessing supplier risks transparently, managing measures in a structured way and keeping changes traceable across the entire business relationship.