forumNew topic

Supplier security: most of the risk isn't ours, it's from the companies we work with

AAycanMember
Job title
Corporate procurement
Joined
Dec 2023
Message
98
#1

I work in corporate procurement. Almost all the security-related disruptions we've had in the last two years came from our suppliers, not our own systems.

One of our suppliers' systems was breached; they didn't access our data directly, but they got hold of our correspondence with them and then sent us a fake invoice.

I'll share how we've integrated this into our procurement processes and where we're struggling, open to additions.

YYavuzExpert
Job title
Information Security Manager
Joined
Jul 2023
Message
168
Most Helpful#2

Spot on. Supplier-related risk determines the weakest link regardless of an organization's own maturity level.

Let me suggest an actionable framework that can be integrated into procurement processes.

First, categorize suppliers by criticality. Suppliers who access our data, connect to our systems, and those who just issue invoices can't be subject to the same audit. Sending everyone the same 100-question checklist creates bureaucracy that nobody fills out correctly.

For critical suppliers, I recommend including these clauses in the contract: reporting security incidents to us within a specific timeframe, disclosing subcontractor usage, destroying our data at the end of the contract and documenting it, and ensuring access is via named accounts.

The fake invoice case you described is a separate issue: this is a process gap, not a technical one. Changes to payment details shouldn't be accepted solely via correspondence; they must be verified via a second channel using a known phone number. This single rule prevents the most common financial losses.

PPelin D***Expert
Job title
Finance Manager
Organization type
early-stage startup
Joined
Nov 2023
Message
138
#3

Finance strongly supports this last point, we experienced almost the exact same thing.

Our rule is this: when a request to change bank account details comes in, we don't reply via the channel it came from. We call the old phone number on file. We never call the number listed in the email, because that number could also be fake.

We also set a threshold amount: first payments above a certain amount require two signatures. It slowed things down, yes. But it saved us once, and that one time paid for all the delays.

EErcan T***Member
Job title
Corporate Account Manager
Joined
Jan 2024
Message
96
#4

As an account manager, let me look at this from the supplier side, because we get these audits too.

I must say: a well-prepared security annex benefits suppliers too, because it clarifies expectations. Where we struggle is every client sending question lists in different formats and scopes. We write the same info ten times a year on different templates.

Here's a suggestion: if you accept independent certifications, state that upfront. Use a short form for suppliers with certifications, and a long form for those without. It reduces work for both you and us.

NNergisMember
Job title
Compliance Officer
Joined
Jan 2024
Message
104
#5

Adding from Compliance: the subcontractor chain is often overlooked in most assessments.

You audit your supplier, they outsource part of the work to another company, and your data reaches that company. If the contract doesn't require prior notification of subcontractor usage and passing the same obligations down to them, you're essentially blind to the second link in the chain.

NNeslihan Y***Member
Job title
Social media manager
Sector
Advertising and promotion
Organization type
family business
Joined
Oct 2024
Message
307
#6

There's one point I'm curious about. Your time to detect an issue directly determines its cost.

FFiliz Ö***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
cooperative
Joined
Jan 2026
Message
88
#7

I'd appreciate it if you shared the outcome.

KKader A***New member
Job title
Network Administrator
Sector
Consulting
Organization type
medium-sized business
Joined
Sep 2026
Message
10
#8

I went through the same thing.

DDilara G***ExpertCommunity member
Joined
Jun 2023
Message
20
#9

Three different views emerged, they all complement each other. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

The biggest time-waster for us was not knowing who had the final say... Hope this helps.

GGamze U***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
family business
Joined
May 2024
Message
255
#10

It's rare to find an explanation this clear. Taking measures without an inventory leaves doors you haven't seen open.

Start with a small trial; don't commit to everything at once. If you post the result here, it will help others too.

DDilara D***Expert
Job title
Chief Information Security Officer
Sector
IT services
Organization type
boutique agency
Joined
Mar 2026
Message
2
#11

Let me summarize the topic, since several different answers were given. An automated scan report is not the same as a penetration test.

Correct me if Im wrong.

TTülay K***MemberCommunity member
Joined
Mar 2023
Message
216
#12

Let me summarize the topic, since several different answers were given. The harder it is to reverse a decision, the slower you should make it.

Hope this helps.

AAyşe A***Member
Job title
Customer service representative
Sector
Automotive aftermarket
Organization type
chain store
Joined
Feb 2023
Message
29
#13

Noted, thanks.

MMeryem S***Member
Job title
System administrator
Sector
Electrical-electronics
Organization type
two-branch business
Joined
Mar 2026
Message
398
#14

Don't miss this: Having backups accessible on the same network and with the same identity makes them part of the target.

Processes without records never improve, because you don't know what to fix. Correct me if I'm wrong.

YYasemin Ö***MemberCommunity member
Joined
Apr 2023
Message
20
#15

Let me clarify the technical side. People defend habits, not processes. Resistance comes from there.

Most incidents start with a leaked password, not a vulnerability. Correct me if I'm wrong.

MMert D***MemberCommunity member
Joined
Feb 2023
Message
40
#16

I feel the same way. The answer varies greatly by industry; there is no one-size-fits-all rule.

If you post the result here, it will help others too.

GGökhan D***Member
Job title
System administrator
Sector
Retail
Organization type
300-person organization
Joined
Dec 2024
Message
5
#17

let me summarize the topic, since several different answers were giveen then when making decisions, write down the worst-case scenario too not just the best.

if I were you I'd go this route.

MMetin Y***Member
Job title
Accounting Manager
Sector
Construction
Organization type
120-person company
Joined
Dec 2024
Message
168
#18

Let me summarize the topic, since several different answers were given. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

That's all sorry if I went on too long.

ZZeynep K***Member
Job title
Production Manager
Sector
IT services
Organization type
regional distributor
Joined
Feb 2025
Message
143

Doki · Interface design · 2026

#19

Yes, that's exactly how it is with supply chain. Trying to do this alone is the most expensive way.

Of course, it varies if your situation is different.

AAyşe B***Member
Job title
Operations manager
Sector
Real estate
Organization type
two-branch business
Joined
Mar 2023
Message
20
#20

I felt relieved reading this answer, so it's not just me. The harder it is to reverse a decision, the slower you should make it.

Hasty decisions become decisions you have to fix six months later. Good luck with that.

Reply