Spot on. Supplier-related risk determines the weakest link regardless of an organization's own maturity level.
Let me suggest an actionable framework that can be integrated into procurement processes.
First, categorize suppliers by criticality. Suppliers who access our data, connect to our systems, and those who just issue invoices can't be subject to the same audit. Sending everyone the same 100-question checklist creates bureaucracy that nobody fills out correctly.
For critical suppliers, I recommend including these clauses in the contract: reporting security incidents to us within a specific timeframe, disclosing subcontractor usage, destroying our data at the end of the contract and documenting it, and ensuring access is via named accounts.
The fake invoice case you described is a separate issue: this is a process gap, not a technical one. Changes to payment details shouldn't be accepted solely via correspondence; they must be verified via a second channel using a known phone number. This single rule prevents the most common financial losses.