Third-Party Risk: Your Suppliers Can Become Your Biggest Cyber Vulnerability Your organisation may have strong cybersecurity controls.
Your suppliers may not. And increasingly, that matters. Modern organisations rarely operate independently. We depend on cloud providers, software vendors, accountants, payroll providers, marketing agencies, IT companies, contractors, logistics partners, consultants and countless other third parties. Each relationship creates efficiency and expertise. But each can also create another pathway into your organisation. A supplier may have access to your systems. They may hold your customer information. They may process confidential data. They may connect remotely to your network. And increasingly, they may be using Artificial Intelligence to process information on your behalf. This creates a fundamental governance challenge for Boards: You can outsource a service. You can outsource technology. But you cannot outsource accountability for the risk. Your Security Perimeter Has Changed There was a time when organisations could think about cybersecurity largely in terms of protecting their own network. That world has disappeared. Today's organisation is an interconnected ecosystem. Data moves between cloud platforms. Applications communicate through APIs. Employees collaborate with external partners. Suppliers access organisational systems remotely. Information is shared across multiple platforms and jurisdictions. And AI services are increasingly being incorporated into business processes. Your cyber environment therefore extends far beyond your own organisation. Your suppliers have effectively become part of your security perimeter. The problem is that you don't necessarily control how well they protect it. Attackers Understand the Supply Chain Why attack a large organisation directly if one of its smaller suppliers provides an easier route? Cybercriminals understand this very well. A major organisation may have sophisticated security controls, dedicated cybersecurity teams and substantial budgets. One of its suppliers may have:
Your cybersecurity may only be as strong as the weakest trusted connection into your organisation. Third-Party Risk Is More Than Cybersecurity Boards should resist viewing supplier risk as simply another technical cybersecurity issue. Consider what happens when a critical supplier experiences a major incident. Can you continue operating? Can you access your data? Can you serve customers? Can you pay employees? Can you communicate with stakeholders? Can you move quickly to another supplier? Who must notify customers or regulators? How much reputational damage could flow back to your organisation? These are questions about business resilience, not simply cybersecurity. A cyber incident affecting a supplier can quickly become your business interruption. Not Every Supplier Presents the Same Risk One of the mistakes organisations make is treating every supplier equally. The company supplying office furniture clearly does not create the same cyber exposure as the company hosting your customer database. Boards should expect management to understand which suppliers are critical. That means asking questions such as:
It is to identify where dependency creates material organisational risk. The AI Supply Chain Is Creating a New Risk Artificial Intelligence adds another dimension to third-party governance. A supplier may be using AI even when your organisation isn't. Imagine engaging an external marketing agency, legal adviser, recruitment company, software developer or consultant. Are their employees using public AI tools? Could your confidential information be entered into those systems? Are AI-generated outputs being checked? Does the supplier use AI models or services provided by another organisation? Where does your information go? Who retains it? Could it be used for training? This creates what we might call an AI supply chain. Your organisation may therefore have excellent internal AI governance while still being exposed through suppliers with very different practices. Boards increasingly need visibility not only into their own AI usage, but into how critical third parties are using AI when handling organisational information. Due Diligence Must Happen Before the Contract Is Signed Third-party cyber risk is much easier to manage before a supplier becomes embedded within the organisation. Procurement therefore plays an important role in cyber and AI governance. Before appointing a critical supplier, organisations should understand:
A small supplier should not necessarily face an enormous security questionnaire simply because it is company policy. Equally, a critical technology provider should not be approved solely because they offered the best price. Good governance should be proportionate to risk. Contracts Matter—But Contracts Don't Create Resilience Contracts should clearly define expectations around areas such as:
A contract may tell you that a supplier must notify you of an incident. It doesn't tell you whether they are capable of detecting one. A contract may require appropriate security controls. It doesn't prove those controls are operating effectively. This is why governance must continue throughout the relationship. Supplier Risk Doesn't End After Onboarding Too many organisations assess suppliers once. The questionnaire is completed. The contract is signed. The supplier is approved. And then everyone moves on. But organisations change. Suppliers change. Technology changes. Ownership changes. Subcontractors change. AI usage changes. Cyber threats change. A supplier considered low risk three years ago may now be providing a critical service or processing substantially more information. Third-party risk therefore requires ongoing review. The greater the dependency, the greater the need for continuing assurance. Don't Forget Fourth-Party Risk There is another question Boards should increasingly ask: Who do our suppliers depend on? Your organisation may contract with Supplier A. Supplier A may rely on a cloud provider, data processor, software platform or AI service. That organisation may rely on another provider. Your organisation can therefore become exposed to companies with which you have no direct contractual relationship. This is sometimes called fourth-party risk. Boards do not need a detailed map of every company in every supplier's ecosystem. But for critical services, management should understand significant dependencies and concentrations of risk. Concentration Risk Deserves Board Attention Suppose ten of your critical suppliers all rely on the same cloud provider. Individually, each supplier may appear resilient. Collectively, the organisation may have a significant concentration risk. The same issue can arise with:
Boards need to understand not only who their critical suppliers are, but also where dependencies overlap. Incident Response Must Include Suppliers Imagine one of your critical suppliers calls tomorrow morning and says: "We've had a cyber incident." What happens next? Who receives that call? Who determines what information may have been compromised? Who decides whether systems should be disconnected? Who communicates with customers? Who considers regulatory notification? Who communicates with the Board? And perhaps most importantly: Have you ever tested this scenario? Third-party incidents should be included in tabletop exercises and incident response planning. A plan that assumes every incident originates inside your own organisation is no longer realistic. Your Suppliers Can Also Strengthen Your Resilience Third-party risk should not become an exercise in distrust. Strong supplier relationships can actually improve organisational resilience. Good suppliers bring expertise. They identify emerging threats. They share lessons. They help organisations recover. They provide capabilities that would be difficult or expensive to maintain internally. The objective is therefore not to eliminate third-party relationships. It is to create trusted, well-governed relationships. Good governance should strengthen partnerships rather than simply add compliance requirements. The Human Element Still Matters Third-party risk ultimately comes back to people. Someone selects the supplier. Someone approves access. Someone shares information. Someone reviews the contract. Someone notices unusual behaviour. Someone receives the incident notification. Someone makes the decision to continue or suspend the relationship. Technology can help monitor third-party risk. But judgement, communication and trust remain essential. This is why third-party risk fits naturally into a human-centric approach to cybersecurity. Questions Every Board Should Ask Boards don't need to review hundreds of supplier security questionnaires. They do need confidence that management understands the organisation's material third-party dependencies. Some useful questions include: Who are our most critical suppliers? Which suppliers have access to our most sensitive information or systems? What would happen if one of them became unavailable tomorrow? How do we assess their cyber and AI governance practices? How frequently are critical suppliers reassessed? Do we understand their important subcontractor dependencies? Are there concentrations of risk across our supplier ecosystem? Are third-party incidents included in our response exercises? Could we replace a critical supplier if necessary? And perhaps most importantly: Would we know quickly if one of our suppliers had been compromised? From Supplier Management to Ecosystem Resilience The language we use matters. If third-party risk is treated purely as supplier compliance, the objective becomes collecting questionnaires and contracts. If it is treated as ecosystem resilience, the conversation changes. Now we ask: Where are we dependent? Where could disruption spread? Where is information flowing? Where do we have concentration risk? Which relationships are essential to our ability to operate? How do we strengthen resilience together? Those are Board-level questions. Trust, But Verify Organisations depend on trust. We trust employees. We trust technology. We trust business partners. And we trust suppliers. But good governance does not rely on trust alone. It creates appropriate assurance. Not because every supplier should be viewed with suspicion. But because strong relationships are built on clear expectations, transparency and shared responsibility. Boards should therefore expect management to know which third parties matter most, understand the risks they create, test critical dependencies and maintain appropriate oversight. Because your organisation can have excellent cybersecurity controls and still experience a significant cyber incident through someone else's systems. Your suppliers are part of your resilience. Treat them that way. And remember: You can outsource the service. You cannot outsource accountability for the risk. Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.
0 Comments
How Boards Should Measure Cyber Culture (Not Just Compliance) A 100% cybersecurity training completion rate does not mean you have a cyber-aware organisation.
It means everyone completed the training. Those are two very different things. For years, Boards have been presented with cybersecurity dashboards containing reassuring numbers. Training completion: 98%. Policies acknowledged: 100%. Phishing simulation failure rate: 4%. Critical patches completed: 97%. These metrics have value. They provide evidence that important activities are taking place. But they don't necessarily tell a Board whether people will make good decisions when confronted with a real cyber threat. They don't tell you whether an employee will challenge an unusual payment request. Whether someone will question an AI-generated answer before acting on it. Whether a manager will report a potential data breach immediately. Or whether an employee who accidentally clicks a malicious link will feel safe enough to tell someone within five minutes. Those behaviours are influenced by something much harder to measure. Culture. And if Boards want to understand how cyber resilient their organisations really are, they need to start measuring it. Compliance Matters—But It Isn't the Destination Let's be clear. Compliance is important. Policies matter. Training matters. Technical controls matter. Regulatory requirements matter. The problem occurs when organisations mistake evidence of compliance for evidence of resilience. Consider two organisations. Both have 100% cybersecurity training completion. In the first organisation, employees rarely discuss cybersecurity, hesitate to report mistakes, don't understand the organisation's AI policy, and assume security belongs to IT. In the second, employees regularly report suspicious activity, managers discuss cyber risks with their teams, Cyber Champions encourage questions, and staff feel confident challenging unusual requests. On a compliance dashboard, these organisations may look almost identical. Culturally, they are worlds apart. Which organisation would you rather lead during a cyber incident? What Is Cyber Culture? Cyber culture is the collective set of behaviours, attitudes, beliefs and expectations that influence how people respond to cyber and AI risks. It answers questions such as: Do people think before they click? Do they challenge unusual requests? Do they understand why security matters? Do they know how to use AI responsibly? Do they feel safe reporting mistakes? Do managers reinforce good cyber behaviours? Does leadership demonstrate that cybersecurity matters? Culture is what happens when nobody is checking whether the policy is being followed. Boards Need to Measure Behaviour, Not Just Activity Traditional cyber metrics often measure activity. How many people completed training? How many phishing simulations were sent? How many policies were acknowledged? Culture metrics should go further. They should help Boards understand how people actually behave. For example: 1. Reporting Rates How many suspicious emails, unusual requests, mistakes and potential incidents are employees reporting? Interestingly, an increase in reporting can be a positive sign. A Board looking purely at incident numbers might see more reports and conclude that risk is increasing. A mature Board might ask whether employees have simply become better at recognising and reporting concerns. Context matters. 2. Time to Report This may be one of the most valuable human-centric cyber metrics an organisation can measure. How long does it take between someone noticing something unusual and reporting it? At Cyberplanz, we believe: The most important five minutes in any cyber incident are the five minutes after someone realises something might be wrong. If employees report concerns quickly, incident response teams have more opportunities to contain potential damage. If employees wait because they fear blame, embarrassment or disciplinary consequences, small incidents can become much larger ones. Boards should therefore consider time to report alongside traditional technical metrics. 3. Employee Confidence Ask employees simple questions. Do you know how to report a cyber concern? Would you feel comfortable reporting a mistake? Do you know which AI tools you are permitted to use? Would you challenge an unusual request from a senior executive? Do you understand your role during a cyber incident? These questions reveal far more about organisational resilience than training completion alone. 4. Leadership Participation Cyber culture is heavily influenced by what leaders do. Boards should ask: Are executives completing the same awareness activities expected of employees? Do managers regularly discuss cyber and AI risks? Are leaders following security policies themselves? Are cyber incidents and near misses discussed openly? When leaders bypass controls because they are inconvenient, employees notice. Culture follows behaviour. 5. Near-Miss Reporting Near misses are one of the richest sources of information available to an organisation. A finance employee questions an unusual invoice before payment. An employee nearly uploads confidential information into an unapproved AI platform but checks first. Someone receives a convincing deepfake call supposedly from an executive and verifies it independently. Nothing bad happened. But something valuable happened. The organisation learned. Boards should encourage near-miss reporting because it provides insight into emerging threats before they become incidents. Measure the Questions People Ask There is another cultural indicator that rarely appears on cybersecurity dashboards. Questions. Are employees asking: "Is this AI tool approved?" "Can I share this information?" "Does this email look right?" "Should we verify this payment request?" "Who should I report this to?" Questions demonstrate engagement. Silence doesn't necessarily demonstrate security. Sometimes it demonstrates uncertainty. A healthy cyber culture encourages curiosity. Don't Turn Phishing Simulations Into Punishment Phishing simulations can provide useful insight. But they can also damage culture when handled badly. If employees who click simulated phishing links are publicly embarrassed, punished or repeatedly labelled as security risks, the organisation may unintentionally teach people something dangerous: Don't admit mistakes. The objective of simulations should be learning. Boards should therefore look beyond click rates and ask: Did reporting increase? Did people recognise the warning signs? Did teams discuss what happened? Did behaviours improve over time? A phishing simulation should create learning, not fear. AI Governance Needs Cultural Metrics Too As Artificial Intelligence becomes embedded across organisations, Boards need visibility into AI culture as well as cyber culture. Traditional compliance measures might tell you whether an AI policy exists. Cultural measures tell you whether anyone understands it. Boards should ask:
Cyber Champions Provide Valuable Cultural Intelligence Cyber Champions can provide Boards and leadership teams with insights that dashboards often miss. Because Champions operate within departments, they hear the questions people ask. They see where policies create friction. They identify emerging AI usage. They recognise where employees lack confidence. And they can highlight positive behaviours worth reinforcing. This creates a valuable feedback loop: Board → Leadership → Cyber Champions → Employees → Cyber Champions → Leadership → Board Good governance should not simply flow downward. Insight must flow upward. Build a Board Cyber Culture Dashboard Rather than presenting Boards with dozens of technical metrics, organisations could develop a simple Cyber Culture Dashboard. For example: Employee confidence in reporting cyber concerns Average time to report potential incidents Suspicious activity reporting trends Near-miss reporting Cyber Champion engagement Leadership participation AI governance awareness Employee confidence challenging unusual requests Lessons implemented following incidents The objective is not to create another complicated reporting exercise. It is to give Directors a clearer picture of whether secure behaviours are becoming embedded across the organisation. Look for Trends, Not Perfect Scores Culture cannot be reduced to a single percentage. Nor should organisations aim for artificial perfection. A healthy cyber culture may actually produce more reported incidents, more questions and more near misses because employees are increasingly engaged. Boards should therefore look for trends. Is reporting becoming faster? Is employee confidence increasing? Are people asking more questions? Are lessons being implemented? Are departments discussing cyber and AI risks more frequently? Is leadership becoming more visible? These trends tell a story. And that story matters more than a single score. The Questions Boards Should Ask At the next Board meeting, instead of simply asking: "Has everyone completed their cybersecurity training?" Try asking: "Do our people know what good cyber behaviour looks like?" Instead of: "How many employees failed the phishing test?" Ask: "How quickly did people recognise and report it?" Instead of: "Do we have an AI policy?" Ask: "Do our people understand how to use AI responsibly?" Instead of: "How many cyber incidents did we have?" Ask: "What did we learn from them, and what changed as a result?" Different questions create different conversations. Different conversations create different behaviours. And behaviours shape culture. What Gets Measured Gets Discussed Boards influence organisations through the questions they ask and the measures they prioritise. If the Board focuses exclusively on compliance, management will naturally focus on compliance. If the Board asks about behaviours, confidence, trust, reporting and learning, those things become organisational priorities too. This does not mean abandoning traditional cybersecurity metrics. It means complementing them with human metrics. Because technology can tell you what your systems are doing. Compliance can tell you whether your processes are being followed. But culture tells you what your people are likely to do when something unexpected happens. And that is when resilience matters most. From Compliance to Capability The most cyber-resilient organisations will not necessarily be those with the highest training completion rates. They will be the organisations where people: Recognise unusual behaviour. Challenge assumptions. Ask questions. Use AI responsibly. Report concerns quickly. Learn from mistakes. And feel empowered to protect the organisation. That is why Boards must move beyond asking whether the organisation is compliant. They need to understand whether the organisation is capable. Because ultimately: Compliance tells you what the organisation has done. Culture tells you what your people will do. And when the next cyber incident occurs, it is what people do that can make all the difference. Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people. Why Cybersecurity is Really About Business Resilience "Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people."
For too long, organisations have viewed cybersecurity as an IT issue. When cyber threats increased, they purchased new technologies. Firewalls. Endpoint protection. Email security. Multi-factor authentication. Threat detection platforms. While these technologies remain essential, they represent only part of the solution. Because when a cyber incident occurs, the question quickly changes from: "How do we stop the attack?" To: "How do we keep the business operating?" That is not a technology question. It is a business resilience question. And that is why cybersecurity has become one of the most important governance responsibilities facing Boards and executive teams today. Cybersecurity Is a Means, Not the End Many organisations unintentionally measure success by the number of security controls they have implemented. How many policies exist? How many phishing emails were blocked? How many vulnerabilities were patched? These are important indicators. But they don't answer the question that matters most. Can the organisation continue to operate when something goes wrong? Because cyber resilience isn't measured on the day everything works perfectly. It is measured on the day it doesn't. Every Organisation Will Face Disruption Cyber incidents are no longer rare events. They have become part of the operating environment. Whether it's ransomware, a compromised supplier, accidental data disclosure, AI misuse, or a major system outage, every organisation should assume disruption will occur at some point. The organisations that recover fastest are rarely those with the most technology. They are the organisations that prepared their people, tested their plans, and built resilience into their culture. Resilience is not about avoiding every disruption. It is about responding effectively when disruption occurs. Business Resilience Is Built Before the Crisis The most important decisions during a cyber incident are often made long before the incident occurs. Before the first phishing email. Before the first ransomware demand. Before the first AI-related mistake. Boards influence resilience by asking questions such as:
Technology Alone Cannot Create Resilience Technology detects threats. Technology blocks malicious activity. Technology automates responses. But technology cannot:
This is why governance matters. Resilient Organisations Think Differently Many organisations ask: "How do we stop cyber attacks?" Resilient organisations ask: "How do we continue operating if an attack succeeds?" That subtle difference changes everything. Instead of focusing solely on prevention, they invest in:
People Are the Difference Every cyber incident eventually becomes a people issue. A manager deciding whether to disconnect a critical system. A finance team verifying an urgent payment request. An employee reporting suspicious activity. A customer service representative communicating with concerned customers. A Board making strategic decisions under pressure. Technology supports these decisions. People make them. This is why organisations that invest in leadership, culture and trust consistently recover more effectively. AI Has Expanded the Resilience Challenge Artificial Intelligence is transforming organisations. It is also changing the nature of organisational resilience. AI can improve productivity, automate decisions and enhance customer experiences. It can also introduce new risks. Confidential information may be shared unintentionally. AI-generated content may be inaccurate. Critical decisions may rely on incomplete or biased information. Deepfakes and AI-assisted fraud are becoming increasingly convincing. Business resilience now requires organisations to govern AI with the same discipline applied to cyber risk. Responsible AI governance is no longer optional. It is an essential component of organisational resilience. Culture Is the Hidden Strength Resilient organisations share one characteristic. People trust each other. Employees feel safe reporting concerns. Managers encourage learning. Cyber Champions promote good practices. Boards discuss cyber resilience regularly. Leaders communicate openly during uncertainty. This culture cannot be purchased. It is built. Every conversation. Every decision. Every day. The Board's Responsibility Boards are not expected to become cybersecurity experts. They are expected to provide leadership. Their role is to ensure the organisation is prepared to withstand disruption, make informed decisions under pressure and recover with confidence. Boards should regularly ask:
And governance shapes resilience. Measuring What Really Matters Traditional cyber metrics often include:
But resilient organisations also measure:
Resilience Creates Competitive Advantage Customers trust organisations that continue delivering services during disruption. Investors value organisations with mature governance. Employees remain engaged when leadership communicates with confidence. Business partners prefer organisations that manage risk responsibly. Resilience therefore creates value. It protects reputation. Strengthens relationships. Supports innovation. Builds confidence. And enables sustainable growth. Cybersecurity is not simply about preventing loss. It is about enabling success. The Future Belongs to Resilient Organisations Technology will continue to evolve. Artificial Intelligence will reshape every industry. Threats will become faster, more sophisticated and increasingly unpredictable. The organisations that succeed will not necessarily be those with the most advanced technology. They will be those with the strongest leadership. The clearest governance. The most engaged people. And the greatest ability to adapt. Because cybersecurity has never really been about technology. It has always been about protecting the organisation's ability to achieve its purpose. Ultimately, cybersecurity is really about business resilience. And business resilience is created when leadership provides direction, governance enables good decisions, and people are empowered to respond with confidence. That is how organisations build lasting trust. That is how organisations create resilience. And that is how organisations thrive in an increasingly digital world. |
AuthorPatrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate Archives
September 2026
Categories |
RSS Feed