26 August 2026 | By James Thomas
Four challenges every organisation must solve to adopt AI safely
Discover four key challenges affecting AI adoption and how organisations can build confidence in their approach.
Read moreThe digital landscape has evolved rapidly in recent years, creating deep, complex connections between businesses, their suppliers, and their customers — connections that would have been hard to imagine just a few decades ago. While this interconnectedness offers clear advantages, like greater efficiency and better service delivery, it also introduces new risks. In fact, 54% of large organisations now cite supply chain challenges as the biggest obstacle to achieving cyber resilience.
Today, it’s no longer enough for businesses to secure their own systems. They also need to stay alert to the security practices of their partners, making strong cyber security more challenging, but definitely achievable with the right approach.
Every point in the supply chain has its own set of vendors handling various products and solutions, creating a vast attack surface. This makes supply chain attacks attractive to threat actors because they can often extort hundreds of businesses by compromising only one environment — taking the ‘path of least resistance’. And because organisations don’t have direct control over their suppliers, protecting against this form of threat can be a significant challenge.
If a supply chain attack is successful, the consequences can be catastrophic, as seen in a number of high-profile cases including SolarWinds, Kaseya VSA and, most recently, MOVEit.
As a result of this growing threat, many government and certification bodies including the National Institute of Security and Technology (NIST), the National Cyber Security Centre (NCSC) and the International Organization for Standardization (ISO) have produced guidance and recommendations for supply chain risk management. Conducting cyber due diligence on a new supplier is an imperative step in this process, ensuring the supplier’s cyber practices don’t introduce vulnerabilities into an organisation’s own operations.
This begins by assessing the supplier’s cyber security posture, examining its information security policies, incident response plans and any prior breaches. It’s essential to understand the controls it has in place in terms of both technology (eg, firewalls, intrusion detection systems and encryption protocols) and procedure (eg, employee awareness training and access controls).
Requesting third-party audits or certifications such as ISO 27001 or SOC 2 reports can provide an objective view of security maturity. Additionally, ensuring the supplier has a clear data management policy, especially if it handles sensitive or personal data, is crucial. And due to the dynamic nature of cyber security, continuous monitoring and periodic reassessments are vital — because a once-secure supplier can become vulnerable if it doesn’t adapt to evolving threats.
Of course, it’s important to remember that your organisation forms part of a supply chain to its own customers too, so managing your own cyber hygiene is also a key business priority. In many industries, being able to demonstrate this is now a prerequisite to trade. For example, an architecture firm may need to have Cyber Essentials Plus to work with a government body, or a motor dealership may need to meet certain requirements to work with a specific manufacturer.
To effectively minimise cyber risk, a multifaceted approach is required. Firstly, implementing cyber security measures in alignment with proven frameworks or standards such as the NIST Cybersecurity Framework or ISO 27001 can provide structured methodologies for addressing and managing cyber threats. Regular employee awareness training on best practices such as recognising phishing attempts and the importance of good password hygiene is crucial, as human error is often a significant vulnerability.
Additionally, businesses should invest in advanced threat detection software, maintain up-to-date software patches and carry out periodic vulnerability assessments and penetration tests. However, despite all this, recently well-documented examples such as sophisticated AiTM phishing campaigns demonstrate that bad actors are becoming more creative, and a breach should now be considered a matter of when, not if.
Ultimately, there’s no real substitute for 24/7 monitoring and interrogation such as Managed Extended Detection and Response (MXDR). This is designed to proactively and efficiently identify a compromise and swiftly neutralise the impact long before an attacker achieves their goal. Without this, threat actors can potentially remain undetected in a system for months, having access to critical data for the duration.
Fundamentally, an organisation should only collaborate with partners whose security stance is as robust or stronger than its own — while not forgetting the importance of its own cyber hygiene. At Bistech, we take a tailored, defence-in-depth approach to help your business stay ahead of the curve. To discuss your security needs, call our specialist team today on 01202 33 22 00.