Blogs

The unmonitored supplier is already within your risk perimeter

Written by Ludovica Gaspari | Aug 4, 2026, 8:15:03 AM

Imagine a manufacturing company that comes to a standstill for three days. Not because of a direct attack: the problem lies in the management software supplied by a third-party software house, which was itself compromised via its cloud infrastructure provider. No one in that company had ever classified that supplier as critical. It was ‘just’ the ERP system – the one that’s been running in the background for years without anyone giving it a second thought. Three days of production downtime, contracts at risk due to delivery delays, and a question the CEO asks himself far too late: how many other suppliers like this do we have?

A supplier ecosystem is also an ecosystem of risks

This is precisely the scenario that NIS2 has placed at the center of the corporate agenda. Not regulatory compliance in itself, but an awareness that until recently remained confined to IT departments: your company’s security today also depends on the security of its supplier ecosystem.

In other words, cyber risk no longer stops at the company’s perimeter. It enters via management applications, cloud services, technology partners, outsourcers, consultants, vertical providers and subcontractors. And when a critical supplier is not properly assessed, monitored and governed, the risk they pose becomes an operational, financial and reputational risk for the company using them. The paradigm shift is simpler than it seems. Until recently, a supplier was assessed on price, quality of service, contractual soundness, reliability of deliveries, and responsibility for this assessment almost always lay with the Procurement Manager. Today, a fourth dimension must be added – one that is entirely new for many companies and which directly involves the CIO, CISO, and Risk and Compliance Managers: how much cyber risk does that supplier introduce into your supply chain, and what happens to your business if that supplier is compromised? This is not a theoretical exercise. It is the difference between identifying a critical issue whilst it is still manageable, or realizing it only when production has already ground to a halt or an essential service is unavailable.

"Cyber risk no longer stops at your company's perimeter."

What NIS2 really requires regarding the classification of suppliers

At an operational level, the implementation of NIS2 across Europe has highlighted the central role of the supply chain in cyber risk management. As a result, organisations subject to NIS2 are required to look beyond their own internal perimeter and identify those entities in the supply chain that may affect the continuity and security of their services.

"A supplier may be low cost, reliable and compliant, yet still represent a critical cyber risk."

The real work begins when those suppliers need to be categorised, assessed and monitored based on the actual risk they may pose to the business: which suppliers warrant an in-depth audit, which can be managed via a self-assessment questionnaire, and which require immediate remedial action. This is a decision that can rarely be left solely to the CISO, the Procurement Manager or the Compliance Manager: it requires the two roles to agree on criteria and priorities; otherwise, suppliers end up being classified based on who responded first, rather than on actual risk.

What does the company gain, beyond compliance?

It is a task worth doing properly, regardless of regulatory deadlines. Firstly, because having genuine visibility into the risk within your supply chain is a negotiating lever, not merely a compliance requirement: a company that knows exactly where its third-party vulnerabilities lie can demand stronger contractual guarantees, or choose alternatives before a supplier chooses for it – in the worst possible way. Secondly, because it is increasingly likely that your own B2B customers will hold you to account for your security posture as a supplier: the due diligence you carry out on your suppliers today will be carried out on you tomorrow.

The limitations of Excel spreadsheets and the value of a structured process

The problem, for those who have tried to tackle this issue using shared Excel spreadsheets and questionnaires sent by email, is that third-party risk management quickly becomes unsustainable as soon as the number of suppliers exceeds the handful you know by heart: out-of-date classifications, questionnaires that get lost in the inboxes of people who have since changed roles, contracts that nobody reviews after signing, and untracked remedial actions. And above all: assessments based almost exclusively on what the supplier declares. A supplier may claim to have formalized processes, yet have exposed digital assets, unmanaged vulnerabilities, poorly configured domains or email addresses involved in data breaches.

This is where a structured Third-Party Risk Management solution makes a real difference, and not just for the CISO who must demonstrate its effectiveness: it does not add bureaucracy, it eliminates it, because it centralizes classification, monitoring and documentation into a single process that remains up to date even when the people managing it change. It does not merely collect data, but transforms it into decision-making evidence, useful both to the Procurement Manager, who must decide with whom to renew a contract, and to the CIO, who must report to the board. It allows a technical component, dedicated to the supplier’s cyber security posture, to be combined with documentary, declarative and process-based assessments. This means that the assessment no longer depends solely on what the supplier enters in a questionnaire, but is enriched by objective evidence gathered through analysis of digital assets, IP addresses, domains, email addresses and publicly available information.

In a NIS2 context, this aspect is particularly relevant: it is not enough to demonstrate that you have requested information from suppliers. It is increasingly important to demonstrate that you have established a process of assessment, classification, decision-making and remediation that is proportionate to the actual risk.

"The real challenge is not collecting supplier data. It is turning it into evidence-based decisions."

No longer a list, but a governance tool

With Cegeka’s TPRM solution, this means moving from a static list of suppliers to a dynamic risk map, accessible at any time and ready to be presented, with data to hand, to anyone who asks: an auditor, a client, or your own board.

The question you should be asking is not whether you are ready for a NIS2 audit, assessment or regulatory review. It is whether you know, right now, which of your suppliers could bring your operations to a standstill for three days. If the answer isn’t obvious, it’s probably time to find out before an incident does it for you.

Do you want to understand how exposed your supply chain is today? Let’s talk: an initial assessment can show you, in just a few weeks, where the risk really lies, before an incident does it for you.