Cegeka_Logo Careers Language Solutions Back
Solutions
Hybrid Cloud

Hybrid Cloud

Explore the added value of cloud adoption for your business.

Data solution

Data & AI

Discover our different data solutions to help you become a data-driven company.

RegulatoryCompliance_Visuals_Navigation (1)

Regulatory Compliance

Ensure GDPR & GxP compliance with our comprehensive solutions.

Cyber Security & Networking Solution

Cyber Security & Networking

With cyber resilience, your organisation becomes a bit more secure with each day.

Digital Workplace Solution

Digital Employee Xperience

Your Digital Employee Xperience. Our Mission.

Testing_Visuals_IconNavigation (1)

Quality Engineering

Ensuring seamless software, one Test at a time.

Cegeka Application Services

Cegeka Application Services

Building the applications to embed growth, innovation and agility.

Business Applications

Business Applications

Transform your business with Microsoft Dynamics ERP and CRM, integrated with Microsoft’s Power Platform.

5G_Citymesh

5G & Mobile Private Networks

Expertise and development experience to bring all the advantages of 5G.

Products and platform solutions

Products & Platforms

Software solutions that optimize business processes and drive success.

Services Back
Services
Website_Navigation_IT_Team_Extension_3

IT Team Extension

The best IT professionals to support your projects.

Outsourcing Services

Outsourcing & Managed Services

Outsourcing your IT helps you to focus on your strategy.

Website_Navigation_Consultancy

Consultancy

The right skills and attitude to support the IT projects at your office

Website_Navigation_Projects

Projects

Integrating the right digital solutions for your IT project

Industries Back
Industries

Our industry-tailored services are designed to address specific challenges and opportunities across different industries.

All industries
government 1

Government and Public Sector

Digital transformation for smarter, citizen-focused public services.

energy_utilities 1

Energy & Utilities

The arrival of smart electricity grids will allow companies to take care of their own energy management

defense 1

Defense & Security

Mission-ready IT securing critical infrastructure and data sovereignty.

food 1

Food

Streamline operations, ensure traceability and maintain compliance.

finance 1

Finance & Insurance

Cloud-powered innovation for agile, secure financial services.

manufacturing 1

Manufacturing

Production chains are becoming intelligent networks with real-time track-and-trace systems.

Insights Back
Knowledge is our backbone

We believe in sharing our insights and expertise with you. Explore our resources and learn more about our products, services and industry trends.

Icons_Navigation_Case Studies

Case Studies

Step into the world of our delighted customers and see how we helped them achieve their goals.

Icons_Navigation_News Items

Corporate News

Stay in the loop with our company news, announcements, awards and events.

Icons_Navigation_Blogs

Blogs

Read our latest articles on topics ranging from technology, innovation, business and beyond.

Icons_Navigation_Webinars

Webinars

Be part of the action with our live or on-demand webinars, where our experts share invaluable knowledge.

Icons_Navigation_Ebooks

E-books & Whitepapers

Download our guides and reports on various aspects of technology and business.

Icons_Navigation_Events

Events

Find out where we are going to be next, and register for our upcoming events.

Cegeka Academy

Academy

Enhance your skills with our expert-led training courses, tutorials, and certifications at our Academy.

Join our Academy
About us Back
shaping digital together

We work shoulder to shoulder with our clients to ensure technology drives impact when and where it matters most.

Start the journey with us
Icons_Navigation_Why Cegeka

Why Cegeka

Discover why more than 2,500 clients around the world choose to work with us, and stay with us.

Icons_Navigation_Cegeka&Society

ESG at Cegeka

We turn ESG ambition into action via sustainable IT, carbon footprint reduction and an inclusive work environment.

Icons_Navigation_Our Story

The Cegeka Story

In just over 30 years, Cegeka has grown from 30 people to a global company with 9,000 employees across 3 continents.

Icons_Navigation_Annual Report

Annual Report

See how our work makes a difference, explore the full annual report to learn more.

More Cegeka

Our Management

Corporate News

Contact & Locations

Back
Select language

Austria

Belgium

Belgium

Denmark

Germany

Italy

Romania

Sweden

The Netherlands

United Kingdom

United States

Let’s get in touch
Cegeka_Logo Solutions
Solutions
Hybrid Cloud

Hybrid Cloud

Explore the added value of cloud adoption for your business.

Data solution

Data & AI

Discover our different data solutions to help you become a data-driven company.

RegulatoryCompliance_Visuals_Navigation (1)

Regulatory Compliance

Ensure GDPR & GxP compliance with our comprehensive solutions.

Cyber Security & Networking Solution

Cyber Security & Networking

With cyber resilience, your organisation becomes a bit more secure with each day.

Digital Workplace Solution

Digital Employee Xperience

Your Digital Employee Xperience. Our Mission.

Testing_Visuals_IconNavigation (1)

Quality Engineering

Ensuring seamless software, one Test at a time.

Cegeka Application Services

Cegeka Application Services

Building the applications to embed growth, innovation and agility.

Business Applications

Business Applications

Transform your business with Microsoft Dynamics ERP and CRM, integrated with Microsoft’s Power Platform.

5G_Citymesh

5G & Mobile Private Networks

Expertise and development experience to bring all the advantages of 5G.

Products and platform solutions

Products & Platforms

Software solutions that optimize business processes and drive success.

Services
Services
Website_Navigation_IT_Team_Extension_3

IT Team Extension

The best IT professionals to support your projects.

Outsourcing Services

Outsourcing & Managed Services

Outsourcing your IT helps you to focus on your strategy.

Website_Navigation_Consultancy

Consultancy

The right skills and attitude to support the IT projects at your office

Website_Navigation_Projects

Projects

Integrating the right digital solutions for your IT project

Industries
Industries

Our industry-tailored services are designed to address specific challenges and opportunities across different industries.

All industries
government 1

Government and Public Sector

Digital transformation for smarter, citizen-focused public services.

energy_utilities 1

Energy & Utilities

The arrival of smart electricity grids will allow companies to take care of their own energy management

defense 1

Defense & Security

Mission-ready IT securing critical infrastructure and data sovereignty.

food 1

Food

Streamline operations, ensure traceability and maintain compliance.

finance 1

Finance & Insurance

Cloud-powered innovation for agile, secure financial services.

manufacturing 1

Manufacturing

Production chains are becoming intelligent networks with real-time track-and-trace systems.

Insights
Knowledge is our backbone

We believe in sharing our insights and expertise with you. Explore our resources and learn more about our products, services and industry trends.

Icons_Navigation_Case Studies

Case Studies

Step into the world of our delighted customers and see how we helped them achieve their goals.

Icons_Navigation_News Items

Corporate News

Stay in the loop with our company news, announcements, awards and events.

Icons_Navigation_Blogs

Blogs

Read our latest articles on topics ranging from technology, innovation, business and beyond.

Icons_Navigation_Webinars

Webinars

Be part of the action with our live or on-demand webinars, where our experts share invaluable knowledge.

Icons_Navigation_Ebooks

E-books & Whitepapers

Download our guides and reports on various aspects of technology and business.

Icons_Navigation_Events

Events

Find out where we are going to be next, and register for our upcoming events.

Cegeka Academy

Academy

Enhance your skills with our expert-led training courses, tutorials, and certifications at our Academy.

Join our Academy
About us
shaping digital together

We work shoulder to shoulder with our clients to ensure technology drives impact when and where it matters most.

Start the journey with us
Icons_Navigation_Why Cegeka

Why Cegeka

Discover why more than 2,500 clients around the world choose to work with us, and stay with us.

Icons_Navigation_Cegeka&Society

ESG at Cegeka

We turn ESG ambition into action via sustainable IT, carbon footprint reduction and an inclusive work environment.

Icons_Navigation_Our Story

The Cegeka Story

In just over 30 years, Cegeka has grown from 30 people to a global company with 9,000 employees across 3 continents.

Icons_Navigation_Annual Report

Annual Report

See how our work makes a difference, explore the full annual report to learn more.

More Cegeka

Our Management

Corporate News

Contact & Locations

Austria   Austria DE Belgium   Belgium NL Belgium   Belgium FR Denmark   Denmark EN Germany   Germany DE Italy   Italy IT Romania   Romania EN Sweden   Sweden EN The Netherlands   The Netherlands NL United Kingdom   United Kingdom EN United States   United States EN Careers Let’s get in touch
Home Discover our latest blogs Discover our latest blogs The unmonitored supplier is already within your risk perimeter
Cegeka Application Services
NIS2
4 minutes reading

The unmonitored supplier is already within your risk perimeter

This is no longer just an IT department issue: if one of your critical suppliers were to suffer a cyber incident tomorrow, would your CISO, your CIO or your board of directors find out about it first from a news story online or from one of your internal reports?

Ludovica Gaspari

Ludovica Gaspari

August 04, 2026

Imagine a manufacturing company that comes to a standstill for three days. Not because of a direct attack: the problem lies in the management software supplied by a third-party software house, which was itself compromised via its cloud infrastructure provider. No one in that company had ever classified that supplier as critical. It was ‘just’ the ERP system – the one that’s been running in the background for years without anyone giving it a second thought. Three days of production downtime, contracts at risk due to delivery delays, and a question the CEO asks himself far too late: how many other suppliers like this do we have?

A supplier ecosystem is also an ecosystem of risks

This is precisely the scenario that NIS2 has placed at the center of the corporate agenda. Not regulatory compliance in itself, but an awareness that until recently remained confined to IT departments: your company’s security today also depends on the security of its supplier ecosystem.

In other words, cyber risk no longer stops at the company’s perimeter. It enters via management applications, cloud services, technology partners, outsourcers, consultants, vertical providers and subcontractors. And when a critical supplier is not properly assessed, monitored and governed, the risk they pose becomes an operational, financial and reputational risk for the company using them. The paradigm shift is simpler than it seems. Until recently, a supplier was assessed on price, quality of service, contractual soundness, reliability of deliveries, and responsibility for this assessment almost always lay with the Procurement Manager. Today, a fourth dimension must be added – one that is entirely new for many companies and which directly involves the CIO, CISO, and Risk and Compliance Managers: how much cyber risk does that supplier introduce into your supply chain, and what happens to your business if that supplier is compromised? This is not a theoretical exercise. It is the difference between identifying a critical issue whilst it is still manageable, or realizing it only when production has already ground to a halt or an essential service is unavailable.

"Cyber risk no longer stops at your company's perimeter."

What NIS2 really requires regarding the classification of suppliers

At an operational level, the implementation of NIS2 across Europe has highlighted the central role of the supply chain in cyber risk management. As a result, organisations subject to NIS2 are required to look beyond their own internal perimeter and identify those entities in the supply chain that may affect the continuity and security of their services.

"A supplier may be low cost, reliable and compliant, yet still represent a critical cyber risk."

The real work begins when those suppliers need to be categorised, assessed and monitored based on the actual risk they may pose to the business: which suppliers warrant an in-depth audit, which can be managed via a self-assessment questionnaire, and which require immediate remedial action. This is a decision that can rarely be left solely to the CISO, the Procurement Manager or the Compliance Manager: it requires the two roles to agree on criteria and priorities; otherwise, suppliers end up being classified based on who responded first, rather than on actual risk.

What does the company gain, beyond compliance?

It is a task worth doing properly, regardless of regulatory deadlines. Firstly, because having genuine visibility into the risk within your supply chain is a negotiating lever, not merely a compliance requirement: a company that knows exactly where its third-party vulnerabilities lie can demand stronger contractual guarantees, or choose alternatives before a supplier chooses for it – in the worst possible way. Secondly, because it is increasingly likely that your own B2B customers will hold you to account for your security posture as a supplier: the due diligence you carry out on your suppliers today will be carried out on you tomorrow.

The limitations of Excel spreadsheets and the value of a structured process

The problem, for those who have tried to tackle this issue using shared Excel spreadsheets and questionnaires sent by email, is that third-party risk management quickly becomes unsustainable as soon as the number of suppliers exceeds the handful you know by heart: out-of-date classifications, questionnaires that get lost in the inboxes of people who have since changed roles, contracts that nobody reviews after signing, and untracked remedial actions. And above all: assessments based almost exclusively on what the supplier declares. A supplier may claim to have formalized processes, yet have exposed digital assets, unmanaged vulnerabilities, poorly configured domains or email addresses involved in data breaches.

This is where a structured Third-Party Risk Management solution makes a real difference, and not just for the CISO who must demonstrate its effectiveness: it does not add bureaucracy, it eliminates it, because it centralizes classification, monitoring and documentation into a single process that remains up to date even when the people managing it change. It does not merely collect data, but transforms it into decision-making evidence, useful both to the Procurement Manager, who must decide with whom to renew a contract, and to the CIO, who must report to the board. It allows a technical component, dedicated to the supplier’s cyber security posture, to be combined with documentary, declarative and process-based assessments. This means that the assessment no longer depends solely on what the supplier enters in a questionnaire, but is enriched by objective evidence gathered through analysis of digital assets, IP addresses, domains, email addresses and publicly available information.

In a NIS2 context, this aspect is particularly relevant: it is not enough to demonstrate that you have requested information from suppliers. It is increasingly important to demonstrate that you have established a process of assessment, classification, decision-making and remediation that is proportionate to the actual risk.

"The real challenge is not collecting supplier data. It is turning it into evidence-based decisions."

No longer a list, but a governance tool

With Cegeka’s TPRM solution, this means moving from a static list of suppliers to a dynamic risk map, accessible at any time and ready to be presented, with data to hand, to anyone who asks: an auditor, a client, or your own board.

The question you should be asking is not whether you are ready for a NIS2 audit, assessment or regulatory review. It is whether you know, right now, which of your suppliers could bring your operations to a standstill for three days. If the answer isn’t obvious, it’s probably time to find out before an incident does it for you.

Do you want to understand how exposed your supply chain is today? Let’s talk: an initial assessment can show you, in just a few weeks, where the risk really lies, before an incident does it for you.

Ludovica Gaspari

Ludovica Gaspari

More of Ludovica Gaspari articles

Cegeka Third Party Risk Management App

Streamline your supplier qualification process with Cegeka's TPRM App, leveraging AI for efficient risk assessments and compliance management on a unified platform.
Explore more

Get in touch

Ready to simplify Third-Party Risk Management?

Let us show you how Cegeka’s TPRM Service App can streamline supplier assessments, ensure compliance with DORA, NIS2 and GDPR and reduce your third-party risk exposure.