Technology

Kaspersky on how to secure a supply chain you do not control

A business today functions as a complex ecosystem in which every participant influences the results, the reputation and, more importantly, the…

Kaspersky on how to secure a supply chain you do not control — article image

The Full Story

A business today functions as a complex ecosystem in which every participant influences the results, the reputation and, more importantly, the sustainability of the wider organisation.

Every business sits inside a vast network of partners, suppliers and service providers whose actions ripple across industries.

Resilience therefore depends not only on internal protection measures but on the strength and security of those external connections. As technology ecosystems grow more complex, protecting a supply chain means accepting that risk can emerge from any link – including the ones furthest from view.

According to a recent global study by Kaspersky’s internal market research centre, supply chain attacks ranked as the top threat companies faced in 2025. Large enterprises were especially vulnerable, given their extensive networks of contractors and third-party vendors.

Business leaders, chief information security officers, information security managers and procurement executives now need not only to grasp the risks these attacks pose but to deploy protective measures that mitigate them.

The key to managing this chain of interactions is an ecosystem approach: a model in which an organisation treats its own security and that of its contractors and partners as a single, interconnected system.

Frontline defence: pre-contract control

Rather than treating supplier risk as secondary, the approach assumes that a vulnerability anywhere in the chain can directly affect the organisation itself. It requires unified standards, shared responsibilities and coordinated controls across every stakeholder, and it covers the full lifecycle of cooperation – before a partnership begins, during collaboration and after a contract ends.

Start by building an internal system of security requirements for suppliers and contractors that governs how they are assessed, approved and managed. Establish policies covering supplier onboarding, data processing, access rights and the minimum baseline every third party must meet. Compliance with globally recognised standards such as ISO 27001 or SOC 2 can be made a condition of admission to tenders.

Simple open-source intelligence techniques will reveal whether a coordinated vulnerability disclosure programme, a history of published vulnerabilities and a bug bounty programme are in place. How quickly a vendor resolves issues reveals how seriously it treats product security. Starting with internal standards and rigorous verification ensures that every supplier enters the ecosystem at a verified level of maturity.

Further action items on verifying the security of partners are set out in a dedicated checklist prepared by Kaspersky experts.

Another indispensable practice is embedding IT security requirements into supplier contracts. According to Kaspersky’s report, only 37% of businesses do this. Setting expectations in writing gives companies predictable control over how third parties handle sensitive information, manage vulner…

Sources