
All businesses have suppliers, fact. But have you ever considered the associated risk of a cyber-attack to your suppliers? Commonly known as either a supply chain attack or third-party risk.
My first musing of Cyber Security Month: what can you do to minimise the risk of a supply-chain attack?
Firstly, what do I mean by a supply chain-attack? Well, these attacks aren't carried out directly on a business, but on its suppliers, such as the Kaseya ransomware attack in 2021. Kaseya offers software that allows companies to manage other companies' IT infrastructure. To use this software, there must be a trusted connection between the vendor and the environment. However, unfortunately there was a flaw in the software that was then exploited by criminals - they only needed to launch their attack on one company in order to gain access to many others to conduct their criminal activities.
How can you minimise this risk?
Keep a register of all your suppliers. Look at the suppliers who have direct (and indirect) access to your environment. Often, access is requested by default due to convenience, either by a direct (continuous) connection or software used to achieve remote access (indirect connection). It's important to know who manages that connection and what software is used to provide remote assistance, as well as creating an overview and monitoring this in your list of suppliers.
Understandably, sometimes it isn't always feasible check in detail if your suppliers have everything in order with regards to information security. So, to try and combat this, I would highly recommend verifying that the supplier has a valid ISO/IEC 27001 certificate and check their statement of applicability.
For your most critical processes and components, you must meticulously go through your agreements with your suppliers - not only those with access agreements - and consider:
Is there a service level agreement (SLA) in place?
What action/reaction can you count on in case of an incident?
Which other suppliers does your supplier use?
Are there any suppliers that may pose a potential risk? For example, can the supplier still guarantee its services to you if one of their suppliers fail?
Another important aspect of supply chain security is checking whether a processor agreement is needed or not - if you need a hand with this, turn to your local Data Protection Authority (DPA) for guidance. If you do need one, make sure that you carefully read the agreement and check, for example, which sub-processors are already known. Don't forget to regularly check and review your agreements, at least on an annual basis, as nothing changes as quickly as the cyber security landscape.
Finally, it strikes me that outsourcing services or tasks to third parties has become commonplace. Most likely due to having to organise and source everything that makes a business run, things such as equipment, software and knowledge in-house, which can be quite expensive. It is therefore absolutely imperative, if you are involving third parties, to be well aware of who is outsourcing what. Outsourcing services does not absolve you of responsibility.
So, to recap my Thursday Thoughts regarding supply-chain attacks:
Keep a register of all your suppliers
Check at least for valid ISO/IEC 27001 certificates
Carefully go through your established agreements with your suppliers
Review your agreements on annual basis
Need some help going through the agreements with your suppliers in the field of information security? Resillion is more than happy to assist you. Contact us for more information.
lang: en_GB
Our Accreditations and Certifications
Most recent headlines
09/11/2025
Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...
24/10/2025
NEP CEO Martin Stewart on $700M Investment, Restructuring, and the Challenges Fa...
24/10/2025
FOX Sports Debuts Next-Gen Graphics, Celebrates Career of Lead Producer Pete Mac...
24/10/2025
GROUP MEDIAPRO Chairman and CEO Tatxo Benet Steps DownBy Ken Kerschbaumer, Editorial Director
Friday, October 24, 2025 - 2:37 pm
Print This Story | Subscri...
24/10/2025
NBA Tip-Off: Amazon Prime Video Debuts Cutting-Edge Studio, Mobile Units, Global...
24/10/2025
(L-R) Director Justin Lin with his cast and producers at Eccles Theatre for the premiere of Last Days in Park City. (Photo by George Pimentel/Shutterstock for...
24/10/2025
As global connectivity demands continue to grow, non-terrestrial networks (NTNs) are emerging as a transformative force in telecommunications. By extending cove...
24/10/2025
Warsaw - Poland, October 20, 2025 - Nielsen, a global leader in audience measurement, data and analytics, has published its latest All Screens Video Landscape r...
24/10/2025
Springsteen: Deliver Me from Nowhere Filmed at Berklee NYCs Power Station The biopic, starring Jeremy Allen White as the Boss, focuses on the period when Spri...
24/10/2025
TORONTO Sometimes in sports, as in life, it's the little things that matter, and that aphorism will be on full display tonight when the Toronto Blue Jays ta...
24/10/2025
NEW YORK Charters Spectrum Reach has announced that its clients have used Waymark's AI-driven ad creation platform to create more than 15,000 ads since Spec...
24/10/2025
BURLINGTON, Mass. Avid has today announced the release of Pro Tools 2025.10, a feature-rich update that the company said offers notable advances in immersive mu...
24/10/2025
NEW YORK In a major change for the ad industry, Comcast Advertising will unveil technology that enables agencies and brands to buy targetable, biddable ads on l...
24/10/2025
WASHINGTON The ATSC broadcast standards group has outlined a growing list of international activities that the group said is expanding its influence and solidif...
24/10/2025
24 Oct 2025
VEON to Release 3Q25 Earnings Update on November 10, 2025 Dubai, October 24, 2025 - VEON Ltd. (NASDAQ: VEON), a global digital operator, today conf...
24/10/2025
One-off special from the team behind BAFTA award-winning Libby, Are You Home Yet...
24/10/2025
The review examined how the model is developed, managed, and delivered against the requirements set out in the Origin framework.
Simon Redlich, Chief Executive...
24/10/2025
Countdown to GTC DC: What to Watch Next Week Next week, Washington, D.C., becomes the center of gravity for artificial intelligence. NVIDIA GTC Washington, D...
24/10/2025
RT will provide extensive coverage of the results of the Presidential Election across television, radio and online on Saturday, 25 October 2025.
Throughout th...
24/10/2025
New Coaches, New Families and New Challenges Set for Ireland's Fittest Famil...
24/10/2025
Westlife, Imelda May and Ben Elton among the guests on this week's Late Late...
23/10/2025
Unlocking character: Sportcast on executing the Bundesliga and Bundesliga 2 new ...
23/10/2025
Clear coordination: Juggling the new Bundesliga rights cycle requirements and pu...
23/10/2025
Analysis: Is piracy just the cost of doing business? By Callum McCarthy, Editor-at-Large
Tuesday, October 21, 2025 - 09:58
Print This Story
It's high ...
23/10/2025
ESPN's Adam Whitlock on Driving Real-World Innovation Across the Video-Trans...
23/10/2025
SVG TranSPORT 2025 Unites 300+ Industry Leaders in New York for Deep Dive Into L...
23/10/2025
NBA Tip-Off: League Starts Season With Two New Broadcast Partners, In-House NBA ...
23/10/2025
NFL Deepens Business Partnership with EA Sports; More Madden Casts to Come?EA Sports will remain the exclusive producer and distributor of Madden NFL video game...
23/10/2025
NFL Moves Pro Bowl Games Indoors and to Super Bowl Week; Leans Into a Made-for-T...
23/10/2025
By Alan Dominguez
Recently I have been thinking about the intersection of two e...
23/10/2025
(L-R) Amber Fares and Noam Shuster Eliassi attend the 2025 Sundance Film Festival premiere of Coexistence, My Ass! at the Egyptian Theatre on January 26, 2025...
23/10/2025
The new solution is industry's first multi-channel receiver available for L3Harris's resilient tactical high-frequency data waveforms....
23/10/2025
NEW YORK During a high-profile session at NAB Show New York, new survey data was shared that revealed significant public concern over artificial intelligence (A...
23/10/2025
BELLEVUE, Wash. and NEW YORK Fox Weather has tapped T-Mobile as its preferred communications provider and said all of its reporters will be equipped with SuperM...
23/10/2025
RASTATT, Germany Broadcast and media workflow technology vendor Lawo has tapped Mike Wright as VP of sales, North America....
23/10/2025
MONTREAL European cultural broadcaster ARTE has selected Grass Valley LDX 135 cameras and Creative Grading solution as part of its move from SDI/1080i to a nati...
23/10/2025
CINCINNATI The E.W. Scripps Company has named Daniel Parsons as its new chief information security officer, effective Oct. 20....
23/10/2025
ALAMEDA, Calif. Northern Michigan broadcaster WWTV recently completed a major IP-based upgrade that connects its new Traverse City studio with its control room ...
23/10/2025
A deadline is looming for a new carriage deal between Verizon's Fios TV and Nexstar, with both Verizon and the pay TV-backed American Television Alliance bl...
23/10/2025
NEW YORK During a high-profile session at NAB Show New York, new survey data was shared that revealed significant public concern over artificial intelligence (A...
23/10/2025
BELLEVUE, Wash. and NEW YORK Fox Weather has tapped T-Mobile has as its preferred communications provider and announced that all Fox Weather reporters are being...
23/10/2025
PBS will use generative AI from Amazon Web Services to provide enhanced search results to viewers on the PBS App and PBS LearningMedia platforms, the network an...
23/10/2025
News Corp to Report Fiscal 2026 First Quarter Earnings
New York, NY (October 23, 2025) - News Corp will release its first quarter Fiscal 2026 results on Thursd...
23/10/2025
The 90-minute film is produced by Rogan Scotland, part of BAFTA-winning Rogan Pr...
23/10/2025
Back to All News
The Resurrected' Marks First Chinese-Language Series to L...
23/10/2025
RT is today publishing a statistical summary from the Register of External Activities for the second quarter of 2025.
The RT Register of External Activities ...
23/10/2025
Series three of the award winning, hit comedy entertainment series The 2 Johnnies Late Night Lock In is back on your screens, celebrating the very best of all t...
23/10/2025
Performances by Michael Flatley, Andy Irvine, Cuckoo's Nest, Foster and Allen and more
Friday 24 October, 8pm on RT One and RT Player
Fleadh Cheoil re...
23/10/2025
The nights grow longer and the shadows get bolder with Vampire The Masquerade: B...
22/10/2025
MONTR AL - October 2, 2025 - The Institute of Technical Education (ITE) last mon...