New Blog
Your Biggest Cyber Risk Might Be a Supplier: Lessons from Recent Breaches
A practical guide to understanding and managing supplier cyber risk. Using lessons from recent high-profile breaches, this article explores how attackers can exploit trusted third parties, why SMEs are an important part of the supply chain, and how frameworks such as ISO 27001 and Cyber Essentials can help businesses strengthen supplier assurance.


Your Biggest Cyber Risk Might Be a Supplier: Lessons from Recent Breaches
If you asked most business owners where a cyber attack would come from, they would probably say a hacker trying to break directly into their business. That still happens, but some of the most damaging recent breaches have taken a different route. Instead of forcing the front door, attackers have used a trusted supplier that already had a key.
The Weak Link in Security
Businesses spend thousands on their own security. They review infrastructure, improve technical controls, and train staff on good security behaviours. Where many still fall short is supplier due diligence: understanding which third parties have access to their systems, what data they can reach, and whether their controls are strong enough for the risk they create.
Recent breaches show that supplier risk is not theoretical. Attackers are actively targeting outsourced services, helpdesks, call centres, and smaller providers because those suppliers often sit between multiple organisations and trusted systems.
Look at the high-profile breach involving Marks & Spencer in 2025. M&S outsourced its IT helpdesk to a third party. The threat actor did not need to breach M&S directly, they used social engineering against the helpdesk provider and once they were breached used that access to reach M&S. Think of it as the attacker stealing the keys from the IT company and using that key to walk into M&S without being noticed.
This wasn’t a one off. Qantas discovered attackers had obtained customer data from an outsourced call centre. It was discovered later that the attackers had been inside the system for weeks.
What the stats say
Research into verified third-party breaches shows that each supplier breach can create multiple incidents further down the supply chain. Attackers only need to be patient and find the supplier that has not asked the right questions or put the right controls in place. It is similar to phishing: the attacker is not looking for the strongest person or organisation, they are looking for the weakest link.
The effect of the supply chain can be massive and costly. The Jaguar cyber-attack is estimated to have affected over 5000 businesses and cost the UK economy £1.9 Billion. Which shows that one breach can have a costly and wide-reaching impact.
Why SMEs should take note
You might be sat there thinking, this is a problem for the big companies. No one will target our business, we are too small.
Think again!
The small suppliers are often softer targets. Typically, these are the ones who spend the least on security. For example, a Small IT provider or payroll supplier will likely have the same level of access and data as an in-house team but on a fraction of the budget.
They are the path of least resistance to a large business, because attackers know that compromising a smaller supplier can give them indirect access to the systems, data, and people of a much larger organisation. Instead of trying to break through the strongest defences first, they look for the trusted partner with weaker controls, fewer resources, and established access. For SMEs, this means good security is not just about protecting their own business; it is also about protecting every customer, partner, and organisation that depends on them.
What can you do about supplier cyber risk?
There are a few options to help tackle cyber risk with suppliers, and it is not about picking just one. These controls work best together, giving you a clearer view of who you rely on, what access they have, and whether they are managing cyber risk to an acceptable standard. The aim is not to make supplier management overly complicated, but to ask the right questions before trust is given and to keep checking that trust is still justified. These options are not only what you can ask of your supply chain, you can implement them as well.
ISO 27001 is useful when you need confidence that a supplier manages information security in a structured and repeatable way. It shows that the supplier has an information security management system in place, rather than relying on informal or ad hoc controls. For suppliers that handle sensitive data, provide critical services, or have access to important systems, ISO 27001 can help demonstrate that they assess risk, manage incidents, control access, review suppliers, and continually improve their security arrangements. Having ISO 27001 yourself can also make a big difference. It helps you understand what good supplier assurance should look like, gives you a clear process for assessing and reviewing third parties, and shows your own customers that you take information security seriously. If a larger customer asks how you manage risk, ISO 27001 gives you evidence that your controls are documented, reviewed, and continually improved rather than based on trust alone.
Cyber Essentials is a good baseline for checking that a supplier has the core technical controls in place. It focuses on practical protections such as secure configuration, firewalls, access control, malware protection, and keeping systems up to date. Cyber Essentials does not prove that a supplier has a complete security management system, but it does give a useful level of assurance that basic cyber hygiene is being taken seriously. For lower-risk suppliers, or as a first step before asking for deeper assurance, it can be a simple and effective starting point. Having Cyber Essentials yourself is also valuable because it shows customers and partners that you have taken practical steps to reduce common cyber risks. It can make supplier conversations easier, particularly when larger organisations ask whether you have basic controls in place before giving you access to their data, systems, or supply chain. For SMEs, it is a straightforward way to demonstrate that security is being treated seriously, even if you are not yet ready for a more detailed framework such as ISO 27001.
The NCSC’s central message is that Cyber Essentials should be used as a baseline cyber security standard across supply chains, helping to improve the resilience of individual organisations and the wider UK economy.
And Finally
Cyber attacks are not going to stop, and suppliers will continue to be an attractive route into businesses because they are trusted, connected, and often given access to important systems or data. The lesson from recent breaches is clear: it is no longer enough to secure only your own organisation. You also need to understand who you rely on, what they can access, and how well they protect the services they provide to you.
For SMEs, this matters even more. A smaller business might not think it is a target, but it may hold the key to a much larger customer, partner, or supply chain. That makes good security more than an internal housekeeping exercise; it becomes part of the trust that customers place in you. Being able to show that you have asked the right questions, put proportionate controls in place, and reviewed supplier access can make the difference between a manageable incident and a wide-reaching breach.
This does not mean every supplier needs the same level of scrutiny. The level of assurance should match the level of risk. A supplier with no access to sensitive data will not need the same depth of review as an IT provider, payroll company, outsourced helpdesk, or managed service provider. However, every supplier relationship should be understood, documented, and monitored over time. Due diligence should not be a tick-box exercise completed once at onboarding; it should be part of how the business manages risk day to day.
In simple terms, know who has a key to your business, know what that key opens and make sure the lock is still strong enough. Supplier security will never remove every risk, but it can reduce the chance that your business becomes the weak link someone else is looking for.
To learn more, visit our ISO 27001 & Cyber Essentials page and discover how WorkNest Secure can help you strengthen your cyber resilience, demonstrate good security practice and build greater trust across your supply chain.
Share your challenge with us and we’ll help you find the right level of support for your business.












