By Russell Lawson, ISO consultant, lead auditor and founder of The Compliance Companion — the practical platform that helps businesses build ISO 9001, ISO 14001, ISO 45001 and ISO 27001 systems using real-world templates, AI-powered tools and guided support. Through years of consultancy and audit work, Russell has seen that some of the most serious weaknesses in a management system are not always inside the business itself, but in the suppliers it relies on every day.

For a long time, many organisations treated cyber security as a technical issue. Something for IT to handle quietly in the background. Something to revisit when a client questionnaire landed in the inbox or when renewal time came around for Cyber Essentials, cyber insurance or ISO 27001.

For a long time, supplier risk was often treated as a procurement issue.

Did the supplier deliver on time?
Were they reasonably priced?
Did they meet the specification?

Those questions still matter, of course. But they are no longer enough. Today, one of the biggest risks many businesses face sits in the systems, services and suppliers they depend on to keep operating. That is why supplier cyber assurance is becoming such an important issue.

In simple terms, supplier cyber assurance is about knowing which suppliers create genuine information security exposure, understanding what the risks are, and applying a level of review and control that matches the importance of that relationship.

That sounds obvious. But in practice, many businesses are still not doing it well.

I see this regularly in both audit and consultancy work. A business may have strong internal controls, decent password practices, sensible backups and a well-written information security policy. But when you ask about supplier assurance, things often become much less clear. There may be no proper record of which suppliers have access to what, no structured review of cyber-related risks, and no clear ownership of ongoing checks once the contract is signed.

That matters because supplier-related weaknesses can create a much bigger problem than many organisations realise.

If a supplier has access to your systems, your information, your clients’ information or your operational infrastructure, then their weakness can become your weakness very quickly. And if a business is heavily dependent on one provider, the impact can go far beyond security alone. It can affect continuity, service delivery, customer confidence and compliance.

This is one reason supplier cyber risk has moved up the agenda so sharply. Businesses are becoming more connected, more cloud-dependent and more reliant on outsourced support. In other words, the modern business model often spreads risk across a wider digital supply chain. That can bring efficiency, but it also means one weak point can have much wider consequences.

That is exactly where ISO 27001 becomes so useful.

One of the strengths of ISO 27001 is that it forces organisations to think in a more structured way about risk and control. It does not assume all suppliers are equal, and it does not encourage a box-ticking approach. What it should do is help you identify where supplier relationships actually matter, what the exposure is, and what proportionate controls make sense.

That is a far more useful approach than treating supplier assurance as a one-off questionnaire exercise.

I often find that businesses fall into one of two traps.

The first is under-controlling. They assume a supplier is reputable, widely used, or recommended by someone they trust, so they do very little review. The relationship starts quickly, the service becomes business-critical, and no one really goes back to test whether the risks were properly understood in the first place.

The second is over-controlling in a very shallow way. They send every supplier the same long checklist, collect a few answers, file them away, and feel reassured. But they do not distinguish between a low-risk supplier and one with deep access to systems, data or operational processes. The paperwork looks busy, but the real risk thinking is still missing.

The strongest organisations do something much simpler and much smarter.

They start by identifying which suppliers really matter. Not every supplier creates the same level of cyber exposure. A company providing office stationery is different from a provider managing your email environment, security monitoring, payroll platform or document hosting. A supplier handling sensitive customer data is not the same as a supplier with no system access at all. The first step is to recognise that not all supplier relationships deserve the same level of attention.

Once that is clear, the questions become much more useful.

What systems does this supplier touch?
What data can they access?
Could their outage stop us operating?
Would a compromise on their side affect our customers or our compliance position?
How easily could we switch away from them if something went wrong?

These are not just technical questions. They are management questions. And they are often the ones that reveal whether supplier assurance is genuinely embedded in the organisation or still being treated as an afterthought.

This is also where I see businesses become much more realistic about the importance of documentation.

Good supplier assurance is not about producing a huge folder of paperwork. It is about having clear, usable records that show you have thought about risk properly. That might include supplier categorisation, due diligence records, contract clauses, review points, incident expectations, and evidence that important suppliers are revisited over time rather than assessed once and forgotten.

If you are looking for a practical next step on that side of things, this is where a natural internal link fits well: If you are strengthening your ISO 27001 system, it is also worth looking at our guide to the ISO 27001 documentation kit and what you actually need: https://the-compliance-companion.co.uk/iso-27001-documentation-kit-what-you-actually-need-with-real-examples/

That matters because one of the biggest weaknesses I see is not that businesses lack supplier controls entirely. It is that the controls are not documented clearly enough, reviewed often enough, or connected properly to the wider management system.

This becomes especially important with managed service providers.

Many businesses now rely on external providers for IT support, security monitoring, cloud administration, backup management, user administration, and infrastructure support. That can be entirely sensible. In many cases, it is the right model. But it also means those providers can end up with very broad access to systems and information. In effect, they become trusted extensions of the business.

That level of access should always trigger more serious review.

I would go further than that. In many businesses, the managed service provider represents one of the single biggest concentrations of operational and cyber risk. Not necessarily because they are doing anything wrong, but because so much depends on them. If they fail, are compromised, or simply underperform, the impact can spread quickly across multiple parts of the organisation.

This is why supplier cyber assurance needs to move beyond generic compliance language and become part of real operational thinking.

Who owns the supplier relationship internally?
Who checks whether access is still appropriate?
Who reviews incidents, changes or concerns?
Who decides whether the controls remain proportionate as the relationship evolves?

Without those answers, a supplier can quietly become critical long before the business fully realises it.

Another area where smart businesses stand out is review frequency.

A supplier review carried out at onboarding is not enough for a relationship that becomes business-critical over time. Systems change. Services expand. Access increases. Risks shift. If supplier assurance is only ever done at the start, it will gradually become less meaningful.

That is why I often recommend linking supplier assurance back into internal audit and management review. It keeps the subject alive, encourages challenge, and gives the business a structured way to revisit assumptions. In my experience, this is where mature systems really separate themselves from superficial ones. They do not just approve suppliers. They keep watching them.

There is also a broader point here for smaller businesses.

A lot of smaller organisations assume supplier cyber assurance is mainly a concern for large enterprises or regulated sectors. I do not think that is true anymore. Smaller businesses are often more dependent on third-party technology providers, not less. They may not have a large internal IT team. They may rely heavily on a single support company, a single cloud platform, or a small number of outsourced digital services. In that context, supplier cyber risk can actually be more concentrated, not less.

This is one reason ISO 27001 remains so valuable. Done properly, it helps businesses build proportionate control without becoming bureaucratic. It encourages sensible questions, clearer ownership and better records. Most importantly, it helps organisations move away from assumptions and toward evidence.

And that is really what supplier cyber assurance is all about.

Not panic.
Not endless questionnaires.
Not trying to eliminate all risk.

It is about understanding which supplier relationships matter most, where the real exposure sits, and what a reasonable, structured response looks like.

Right now, that is becoming a much more important business skill.

Because the more connected businesses become, the less useful it is to think about cyber security as something that stops at the organisation’s own front door. For many businesses, some of the most important risks now sit just beyond it — in the suppliers they trust every day.

If your management system is not helping you see that clearly, it may be time to tighten it up.