Cyber Third-Party Risk, Part 2: Supplier Standards, Assurance and Metrics

Co-authored by Joanna Harding and Susanne Alfs

In Cyber Third-Party Risk, Part 1: Aligning Suppliers, Strategy and Risk Appetite, we proposed that cyber third-party risk management starts with a supplier inventory that reflects business criticality. This requires collaboration between the business, risk management, procurement, legal and technology teams, because only together can they understand what the supplier enables, what dependency is being created, and whether the resulting risk sits within risk appetite.

C-TPRM should cover all suppliers, not only technology providers. Cyber risk does not follow procurement categories. A supplier may provide laboratory, logistics or facilities services, yet still depend on digital systems, connectivity and subcontractors to deliver what your organisation relies on. The UK Cyber Security and Resilience Bill[1] reinforces this broader view by allowing regulators to designate critical suppliers whose disruption could affect the continuity of essential, digital or managed services. 

Boards should approve standards suppliers are expected to meet on quality, security, resilience, data protection and performance[2], depending on the criticality level assigned to the supplier. These standards express risk appetite and help align C-TPRM across the business. Suppliers can affect all three dimensions of cyber risk: confidentiality, integrity and availability. They may expose sensitive data, compromise the integrity of information or decisions, or disrupt the availability of services the organisation depends on. As McKinsey notes, availability, and the resilience of business-critical systems, deserves the same attention as confidentiality and integrity[3].

How can the executive team achieve this? The starting point is to translate supplier-risk expectations into contractual commitments and assurance mechanisms. Contracts should define the obligations that matter for the service: data hosting and location requirements, security standards, incident notification and response protocols, transparency obligations, audit or evidence rights, recovery expectations and participation in incident simulations where appropriate.

Assurance should be proportionate. According to your risk tolerance, those suppliers considered as low risk may only need to meet baseline requirements and provide periodic attestation of security measures in place. A supplier considered critical to business operations may require independent evidence, evidence of notification of incidents and visibility toward material subcontractors. Assurance mechanisms test whether supplier commitments are credible. These mechanisms may include:

  • certifications, such as ISO 27001 or Cyber Essentials in the UK

  • independent assurance reports, such as SOC 2 reports, where relevant to the service used

  • audits conducted by the organisation or by an independent auditor

  • verifying remediation of maturity levels as agreed in contracts or post-incident

  • assessing changes to subcontractors or service delivery arrangements

  • understanding the dependencies in the chain of additional suppliers 

For critical suppliers, assurance should also cover incident and crisis communication: named escalation routes, notification expectations, access to relevant evidence, participation in exercises, recovery coordination and clarity on how supplier incidents will be communicated. Contractual obligations matter, but they only become useful when they can be exercised under pressure.

Assurance also needs to remain current. For critical material suppliers, this requires risk-based continuous monitoring rather than a point-in-time assessment at onboarding. Monitoring may include reported cyber incidents, service outages, remediation of overdue actions, changes in subcontractors, financial distress or material changes in data processing procedures.

Board reporting should reflect supplier criticality and show more than technical control status. A practical board reporting model could group metrics into four areas:

1.     Coverage and ownership

  • percentage of material suppliers classified by criticality

  • percentage of material suppliers assigned an internal employee, representative of the business, and “owner” of the relationship

  • suppliers identified outside the formal procurement or onboarding process

2.     Assurance and control effectiveness

  • covering all suppliers – not only critical ones: number of lapsed certifications, expired attestations or outdated evidence and overdue high-risk findings from all supplier assessments and audits

  • percentage of critical suppliers with current and relevant assurance evidence

  • number of supplier risks that are above the threshold of acceptable risk appetite, with agreed mitigation or acceptance

3.     Resilience and incident readiness

  • percentage of critical suppliers with tested (and to what measure of success) business continuity and disaster recovery plans

  • material supplier incidents, near misses or service failures reported during the period

  • evidence that agreed incident notification and escalation routes have been tested

4.     Dependency and change

  • percentage of dependency across key suppliers or common fourth parties supporting critical services

  • material supplier changes that triggered reassessment, such as new data use, new subcontractors, expanded access or increased dependency

  • critical suppliers without a credible fallback, transition or offboarding plan

  • supplier relationships where exit difficulty or lock-in has moved beyond acceptable risk tolerances

Some of these metrics are indicators which should prompt the board to ask whether supplier risk is increasing. For example, rising dependency on a small number of suppliers or common fourth parties should trigger questions about concentration risk and fallback options. Expired certifications should prompt management to refresh evidence, agree on remediation actions or mark the supplier for contract renegotiations. Material changes in data use, access, subcontractors or service scope should trigger reassessment before the supplier becomes more embedded in operations. A board should ask which decision a metric is meant to support; is it meant to continue, mitigate, renegotiate, or plan exit based on the risks of the supplier.

As regulatory requirements in the EU and the UK tighten supply-chain oversight for organisations considered critical, boards face a governance challenge: ensuring that C-TPRM is resourced and managed against an agreed risk appetite. This is not a procurement or technology task: It requires the wider executive team to align business priorities and operational resilience requirements with supplier assurance. 

[1] UK Department for Science, Innovation and Technology, Policy Paper: Designating critical suppliers, 2026 https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/designating-critical-suppliers

[2] KPMG, Innovating Supply Chain Assurance, https://kpmg.com/uk/en/insights/technology/innovating-supply-chain-assurance.html

[3] McKinsey & Company, Taking a business-critical approach to supplier nth-party IT risk management, 2025: https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/taking-a-business-critical-approach-to-supplier-nth-party-it-risk-management

Next
Next

Preparing for Quantum Computing to impact encryption: What should boards do now?