Managing supply chain cyber risk in practice

Tools and techniques for local authorities | Produced in partnership with Risk Ledger

Authors and contributors: Diana Rebaza, Risk Ledger

On 24 June 2026, Socitm held a 90-minute online workshop with a small group of technical cyber security leaders. The session focused on helping each other (and other councils) manage supply chain cyber risk, with a strong emphasis on how to assess and review suppliers effectively (including criticality and asking the right questions).

The goal was to:

  • Offer clear guidance on supply chain cyber risk management
  • Highlight the limitations of current approaches, particularly the excessive dependence on questionnaires and spreadsheets.
  • How to review an AI supplier and consider the implications of it.

Introduction

Supply chain cyber risk is now a major challenge for public sector organisations. As local authorities rely on complex networks of suppliers, technology providers, cloud services and software vendors, a cyber incident affecting one supplier can disrupt many organisations. Threat actors increasingly target supply chains because they offer a route to compromise multiple organisations through a single point of entry.

Supply chains are also becoming more interconnected and harder to oversee. Many organisations understand their direct suppliers but have limited visibility of wider fourth-party and fifth-party dependencies. This makes it harder to identify vulnerabilities, assess impacts and respond effectively to incidents.

For councils, supply chain cyber security is now a resilience issue, affecting service continuity, data protection and essential services. Organisations need to move beyond one-off supplier assessments and take a more collaborative, risk-based and continuous approach to managing supply chain risk.

Socitm partnered with Risk Ledger to run a virtual workshop on practical ways to manage supply chain cyber risk in local government. Speakers explored the growing threat of supply chain attacks, the limitations of traditional third-party risk management, and the need for a more collaborative, intelligence-led and risk-based approach. The discussion covered supplier criticality, proportionate assurance, continuous monitoring, Cyber Assessment Framework (CAF) 4.0 and artificial intelligence (AI) supplier assessment.

A key theme was the need to prioritise suppliers whose failure would have the greatest impact on essential services, rather than assessing all suppliers equally. Collaboration across councils and sectors was also highlighted as vital for improving visibility of shared and concentration risks.


Key discussion areas

Chat speech bubbles illustration

The evolving supply chain threat landscape

The session began by exploring how supply chain risk has become one of the most significant challenges facing organisations today. Rather than attacking organisations directly, cyber criminals are increasingly targeting suppliers and service providers as a way of gaining access to multiple victims through a single compromise.

This approach provides attackers a high return on investment because a successful attack against one supplier can affect dozens, hundreds or even thousands of customers simultaneously.

  • Attackers increasingly target suppliers because a single compromise can impact many organisations simultaneously.
  • Threat actors often exploit weaker links within supply chains to gain access to larger targets.
  • Modern organisations rely on multiple layers of suppliers, creating complex third-party, fourth-party and fifth-party dependencies.
  • Traditional spreadsheet-based supplier management approaches struggle to cope with the scale and dynamic nature of today’s interconnected supply chains.

The scale of the challenge

Some organisations still see supply chain risk only through their direct suppliers. In reality, modern services depend on complex networks that extend far beyond traditional third-party relationships.

  • Third-party suppliers
  • Fourth-party technology providers
  • Fifth-party service providers
  • Cloud platforms
  • Software developers
  • Managed service providers
  • Outsourced business functions

This means that local authorities are often dependent on organisations they may never contract with directly and may not even be aware of. A disruption affecting one of these hidden dependencies can still have serious consequences for council services.

A practical example was shared showing how 25 councils combined their supply chain data can create a map of:

  • More than 1,200 supplier connections.
  • Approximately 800 unique suppliers.
  • Around 65 concentration risks shared across the participating organisations

This example demonstrated that a single local authority often sees only part of the picture. However, when information is shared across a wider community, patterns and dependencies become much easier to identify. This collaborative view enables organisations to better understand common suppliers, shared vulnerabilities and areas where disruption could affect multiple councils simultaneously.

๐Ÿ“Œ Key message: Supply chain risk management must move beyond static supplier registers towards continuous visibility and collaborative intelligence sharing.

Why traditional approaches are struggling

The session challenged point-in-time, spreadsheet-based approaches to third-party risk management. Historically, organisations have relied on:

  • Supplier registers
  • Manual questionnaires
  • Annual assessments
  • Risk scoring spreadsheets
  • Contract renewal reviews

While these approaches may have been effective when supply chains were smaller and less interconnected, there is a struggle to keep pace with modern risks. Supply chains change constantly as organisations adopt new services, suppliers change subcontractors, and technology dependencies evolve. A supplier assessment completed six or twelve months ago may no longer accurately represent current risk exposure.


Reviewing suppliers effectively

View of a cityscape from a skyscraper viewing room with large windows. Photo by Charles Forerunner via Unsplash
Photo by Charles Forerunner via Unsplash

1. Start with the criticality, not questionnaires

Understand the importance of a supplier to their organisation before sending security questionnaires.

Before assessing security controls, organisations should first determine how critical a supplier is to service delivery and the potential impact of any disruption. This requires looking beyond contract value to consider operational reliance, business continuity and service resilience.

Questions should focus on:

  • What service does the supplier provides?
  • The impact if the supplier fails
  • How difficult they would be to replace?
  • Their role in delivering critical services
  • Any reputational implications of supplier failure

Many local authorities are already gathering some of this information through procurement and contract management processes. Integrating this information into a formal third-party risk management approach can help create a more consistent and risk-based supplier assurance framework.

2. Develop a supplier tiering model

Once suppliers have been assessed for criticality, organisations can group them into tiers and apply appropriate levels of assurance.

In this section, participants discussed difficulties obtaining information from suppliers, particularly around fourth-party relationships and wider supply chains. Key points included:

  • Suppliers are often reluctant to disclose supply chain details.
  • Open-source intelligence can supplement supplier responses.
  • Information such as exposed attack surfaces, leaked credentials and external vulnerabilities can often be identified independently.
  • Building relationships with suppliers is generally more effective than using a purely contractual or compliance-driven approach.

3. Focus on evidence, not just answers

The speakers stressed that supplier questionnaires should not simply be scored and filed away. For critical suppliers, organisations should seek supporting evidence and understand how security controls operate in practice. This could include:

  • Reviewing key security policies and procedures.
  • Examining incident response arrangements.
  • Understanding business continuity and disaster recovery capabilities.
  • Exploring how the supplier manages vulnerabilities and security updates.
  • Assessing how seriously security is embedded within the supplier’s culture and governance.

The discussion noted that organisations can often tell a great deal about a supplier’s maturity through the quality of responses, responsiveness, and willingness to engage constructively in the assurance process.

4. Consider supplier resilience, not just security

An important distinction raised during the session was the need to assess resilience alongside cyber security. While security controls remain important, local authorities should also consider whether a supplier could continue operating following a significant incident.

For critical suppliers, key questions include:

  • Would the supplier survive a major cyber incident?
  • Do they have appropriate recovery arrangements?
  • Can they continue delivering services during periods of disruption?
  • How dependent are they on other suppliers or sub-processors?
  • How would they communicate incidents affecting council services?

This broader resilience perspective aligns closely with the outcomes-focused approach being promoted through CAF 4.0.

5. Move beyond third parties

A recurring theme was that risk does not stop with direct suppliers. Suppliers themselves rely on software providers, cloud platforms, managed service providers, and other partners. These fourth-party relationships can introduce significant risks that may not be visible through traditional supplier assurance approaches.

Organisations were encouraged to seek greater transparency regarding:

  • Critical sub-processors.
  • Key technology providers.
  • Supply chain dependencies.
  • Arrangements for managing fourth-party risk.
  • Processes for notifying customers about vulnerabilities and incidents arising elsewhere in the supply chain.

6. Turn assurance into action

The speakers emphasised that the purpose of supplier assurance is not simply to generate risk scores or compliance reports. Every assessment should lead to decisions and actions that reduce organisational risk.

Examples include:

  • Working collaboratively with suppliers to strengthen controls.
  • Introducing contract clauses to address identified weaknesses.
  • Increasing monitoring of higher-risk suppliers.
  • Implementing compensating controls within the council.
  • Developing contingency plans for supplier failure or disruption.

7. A relationship-based approach

Finally, the session emphasised the value of moving beyond purely compliance-led supplier engagement. Participants noted that collaborative conversations often lead to better outcomes than relying only on contract terms or lengthy questionnaires.

By helping suppliers understand how weaknesses could affect public services, councils can build stronger partnerships, improve transparency and encourage security improvements that benefit the wider sector.

๐Ÿ“Œ Key message: Effective supplier assurance is not about assessing every supplier in the same way. It is about understanding criticality, applying proportionate scrutiny, validating evidence, and using the findings to reduce risk and strengthen resilience across the supply chain.


Reviewing AI suppliers

Photo by Fakurian via Unsplash
Photo by Fakurian via Unsplash

As artificial intelligence (AI) becomes increasingly embedded in software, platforms and public services, councils need to ensure their supplier assurance processes are equipped to assess the associated risks.

While AI suppliers should be subject to the same governance and due diligence processes as other suppliers, additional consideration should be given to issues such as transparency, data handling, human oversight, accuracy, and accountability.

Taking a structured and proportionate approach to reviewing AI suppliers can help councils realise the benefits of AI while maintaining trust, protecting sensitive information, and ensuring services remain safe and resilient

Six key review areas

  1. Governance: AI policies, risk assessments, and oversight arrangements.
  2. Provenance: Which models are being used, and ownership and sourcing of AI technology.
  3. Data handling: Whether customer data is used for model training, retention periods, and sensitive data protection.
  4. Human oversight: Human review of outputs and controls over automated decisions.
  5. Quality and accuracy: Validation methods and monitoring for incorrect outputs.
  6. Change management: Notification of model or service changes and impact assessment processes.

AI supplier red flags

  • Inability to explain how AI models work
  • Customer data being used to train foundation models
  • No human involvement in decision-making
  • Vague claims regarding AI accuracy
  • Lack of commitment to notify customers about major model changes

๐Ÿ“Œ Key message: AI suppliers should be subject to existing third-party risk management processes, with additional scrutiny applied based on the risk and criticality of the service.


CAF 4.0 and supply chain security

The session reviewed recent changes to Cyber Assessment Framework (CAF) 4.0, particularly ‘A4.a: Supply chain security’ and ‘A4.b: Secure software development and support’.

Discussion focused on:

  • Identifying critical suppliers and dependencies
  • Demonstrating due diligence in supply chain mapping
  • Understanding software development practices
  • Assessing vulnerability management processes
  • Gaining assurance over software supply chains
  • Adopting continuous monitoring rather than point-in-time assessments

๐Ÿ“Œ Key message: CAF is focused on resilience outcomes, not simply demonstrating that security controls exist. Councils should be able to evidence proportionate risk management and informed decision-making.


Key takeaways for councils

  1. Prioritise suppliers based on criticality: Assess suppliers according to their impact on essential services rather than contract value alone.
  2. Use a tiered assurance model: Apply the highest levels of scrutiny to suppliers that present the greatest operational risk.
  3. Move beyond compliance: Supplier assessments should drive practical risk reduction and informed action.
  4. Improve visibility of supply chains: Seek greater understanding of fourth-party and wider supplier dependencies where possible.
  5. Embrace continuous monitoring: Point-in-time assessments are no longer sufficient for rapidly changing supply chains.
  6. Collaborate across the sector: Sharing intelligence and supplier insights can help councils identify concentration risks and improve resilience collectively.
  7. Strengthen AI supplier due diligence: Review governance, data protection, transparency and human oversight before adopting AI-enabled services.
  8. Align approaches with CAF 4.0: Focus on demonstrating resilience, supplier understanding and proportionate risk management rather than checkbox compliance.

Conclusion

The session reinforced that supply chain cyber risk is no longer solely a technical issue. It is a resilience challenge that requires collaboration, risk-based prioritisation and ongoing monitoring.

Councils should focus their limited resources on the suppliers that matter most, build stronger relationships with suppliers, and leverage collective intelligence to gain a better understanding of shared risks across the local government ecosystem.

The emergence of AI-powered services and CAF 4.0 requirements further underline the need for a structured, proportionate and continuous approach to supplier assurance


About Risk Ledger

Risk Ledger logo

Risk Ledger helps organisations strengthen cyber resilience by providing greater visibility of supplier and supply chain risks.

Its platform helps organisations understand where risks may exist across their wider network of suppliers, making it easier to take action and stay ahead of new threats.