A supplier can work with a business for years without causing a problem.
They know the people. They understand the systems. They may have helped the organisation through difficult periods, urgent projects and operational changes.
That history creates familiarity. Familiarity creates trust.
But trust is not the same as evidence.
The real question is not whether a supplier has been dependable in the past. It is whether the business still understands what that supplier can access, what depends on them, who owns the relationship and what would happen if the supplier were compromised or suddenly became unavailable.
The National Cyber Security Centre warns that vulnerabilities can enter or be exploited at different points in a supply chain, and that a vulnerable supply chain can cause damage and disruption. Its board guidance goes further, noting that an attack on a supplier can be as damaging as an attack on the organisation’s own network. (National Cyber Security Centre)
This is not an argument for distrusting every supplier.
It is an argument for knowing where trust has become access, where access has become dependency, and whether either has been properly evidenced.
Trust is often decided once
A supplier usually receives its greatest scrutiny at the beginning of the relationship.
The business may review the proposal, check references, negotiate the contract and approve the initial access required for the work.
After that, scrutiny can gradually weaken.
The relationship becomes familiar. The supplier understands how the organisation works. New people become involved. Its responsibilities may grow. Access granted for one project may remain available after the work changes.
Cris Martlew’s observation is that many directors can explain why a supplier was chosen several years ago but would struggle to describe exactly what that supplier can access today. Over time, the relationship becomes more trusted while the checking becomes less frequent.
Paddy Hearty reaches the same point more directly: a long relationship or strong reputation should not be treated as automatic proof that a supplier is secure. In his words, “Trust doesn’t equal security.”
The relationship itself may be perfectly sound.
The problem is the assumption that familiarity has removed the need for review.
The suppliers that feel routine are easily overlooked

Routine access can remain in place long after the original reason for granting it has changed.
Businesses usually pay attention to suppliers that already appear risky.
A new technology provider may receive a detailed questionnaire. A major outsourced service may go through formal procurement. A large supplier may be asked for certificates, policies and evidence.
The suppliers that feel ordinary may receive far less attention.
These can include:
- small IT support companies
- maintenance contractors
- payroll providers
- cleaning and facilities companies
- fire and alarm contractors
- software support providers
- logistics partners
- specialist engineers
- temporary contractors
- local firms that have worked with the business for years
Cris identifies the “boring” or routine suppliers as a particular blind spot. They may have been entering sites, handling information or connecting to systems for so long that their access no longer feels unusual. Paddy similarly notes that smaller suppliers are often overlooked while attention remains focused on larger names.
Size is not the most useful measure of supplier risk.
A small contractor with privileged access, specialist knowledge or responsibility for a critical machine may create more operational dependency than a far larger supplier that delivers a limited, easily replaced service.
The better question is:
What could this supplier reach, and what could the business no longer do without them?
Supplier access is wider than a system login
Supplier access is often discussed as though it means a username and password.
In practice, it can exist across three connected areas.
Physical access
A contractor may have:
- a key
- a key fob
- a door code
- access to a warehouse or plant
- permission to enter a server room
- knowledge of restricted areas
- unescorted access during maintenance work
That access may remain in place after a named employee leaves the supplier, after a contract changes or after the original reason for access has ended.
Data access
A supplier may have received information for one project or operational purpose.
That could include:
- customer information
- employee information
- production records
- system documentation
- site plans
- commercial information
- contact details
- technical configurations
The original access may have been reasonable. The question is whether it was later reduced, removed or reviewed.
System access
Suppliers may connect through:
- Microsoft 365 accounts
- virtual private networks
- remote support tools
- administrative accounts
- cloud platforms
- maintenance portals
- shared credentials
- supplier-managed systems
Paddy highlights that access risk appears whenever a supplier moves beyond simply delivering a service and gains the ability to enter systems, view sensitive data or access restricted areas.
This is particularly important in operational technology environments. The NCSC notes that manufacturers, integrators and managed service providers often help manage or maintain operational systems. Because the organisation does not directly control the supplier’s own security arrangements, those connections require additional consideration and documented processes. (National Cyber Security Centre)
The most useful questions are therefore not limited to:
Does the supplier have access?
They should also include:
What could they reach through that access?
What depends on them?
Would we know if the access were used unexpectedly?
Could we remove or isolate it without stopping an essential operation?
The evidence leadership assumes exists
Directors may reasonably assume that someone holds an up-to-date record of supplier access.
Perhaps IT knows. Procurement may have it. The managed service provider might keep a list. The contract owner probably reviews it.
Sometimes that evidence exists.
Sometimes it is spread across:
- old contracts
- email conversations
- spreadsheets created during onboarding
- IT account lists
- access-control systems
- procurement records
- the memory of an employee
- information held by a supplier or outsourced IT company
Both Cris and Paddy describe the same evidence gap.
Leadership may assume that supplier assessments, access reviews and risk monitoring have been documented. When the organisation is asked to produce that evidence, it may discover that records are incomplete, outdated or missing altogether.
That becomes especially uncomfortable when the request does not come from the internal security team.
It may come from:
- a major customer
- a prospective client
- an auditor
- a certification assessor
- an insurer or broker
- a regulator
- the board after an incident
- a client investigating its own supply chain
The weakness is not always that the organisation has done nothing.
It is that the organisation cannot clearly show what was done, who owns it, when it was last reviewed or whether the information still reflects reality.
Why questionnaires do not show the complete picture
Supplier questionnaires can be useful.
They may confirm whether a supplier has policies, security controls, certifications, incident procedures or defined responsibilities.
But a completed questionnaire is not the same as verified understanding.
Paddy puts the limitation plainly: questionnaires show what someone says they are doing, but they do not necessarily show whether those controls operate effectively in practice.
Cris adds another distinction. A questionnaire may collect information about the supplier but still fail to show how that supplier actually connects to the client’s business. It may not reveal what access is active today, whether that access is monitored, whether it remains proportionate or what would happen if the supplier became unavailable.
The NCSC’s guidance reflects this wider view of assurance. It recommends identifying important assets and dependencies, prioritising contracts according to risk, monitoring supplier performance and continuing the process throughout the relationship rather than treating assurance as a one-off onboarding exercise. (National Cyber Security Centre)
The questionnaire is therefore one piece of evidence.
It is not the complete picture.
When a supplier issue becomes your operational problem
A supplier problem does not remain neatly inside the supplier’s business.
It becomes your problem when it affects your ability to operate.
That could happen when:
- the supplier’s account is used to access your systems
- a supplier outage prevents staff from working
- maintenance support is unavailable
- customer or employee data is exposed
- a critical software platform stops functioning
- the business cannot access specialist knowledge
- production cannot continue safely
- orders cannot be processed
- contractual commitments cannot be met
- incident information arrives too slowly
The NCSC advises boards to understand their dependencies on suppliers and to consider how an outage or breach at one organisation could affect the operations of another. It also recommends addressing incident responsibilities and reporting expectations within supplier arrangements. (National Cyber Security Centre)
Paddy describes the dividing line simply: a supplier issue becomes operational the moment it begins affecting the business’s ability to serve customers, meet its obligations or continue trading.
This is the commercial “so what?”
A supplier failure can become:
- lost production
- delayed deliveries
- customer complaints
- missed contractual obligations
- recovery costs
- leadership distraction
- weak assurance evidence
- difficult renewal or insurance-related conversations
The exact insurance position will always depend on the policy, the circumstances and the information disclosed. FaultLine-CS does not provide insurance advice. The practical point is narrower: “we trusted the supplier” is unlikely to be a satisfactory substitute for evidence of assessment, ownership and proportionate controls.
What leadership should examine first
A business with many suppliers cannot sensibly treat every one of them as equally important.
Paddy’s recommendation is to begin with the suppliers that create the greatest potential impact.
That means asking:
1. Which suppliers could stop an important part of the business?
Consider production, logistics, customer service, communications, payments, payroll, cloud systems and specialist maintenance.
2. Which suppliers have meaningful access?
Look across physical locations, systems, administrative accounts, remote connections and sensitive information.
3. Which suppliers would be difficult to replace?
A small supplier may hold knowledge, permissions or operational familiarity that cannot be replaced quickly.
4. Who owns each relationship?
There should be a named business owner, not only a technical contact or an old procurement record.
5. Why was the access approved?
The business should be able to connect current access to a current operational need.
6. When was it last reviewed?
Long-standing access should not become permanent simply because removing it is inconvenient.
7. What would the business know during an incident?
Consider reporting times, escalation contacts, evidence, system logs and responsibility for customer communication.
8. What happens when the relationship ends?
Accounts, keys, access tokens, shared information and remote tools should not quietly survive contract closure.
This risk-based approach is consistent with NCSC board guidance, which recommends proportionate assurance rather than expecting every supplier to demonstrate the same level of maturity. The depth of review should reflect the criticality of the service and the value or sensitivity of the information involved. (National Cyber Security Centre)
What useful supplier assurance looks like
Useful supplier assurance is not necessarily a large compliance programme.
For an operational SME, it may begin with a clear, current record showing:
- the supplier
- the service provided
- the internal relationship owner
- the information handled
- physical access held
- systems and accounts available
- level of operational dependency
- last assessment date
- last access-review date
- contract and incident obligations
- named escalation contacts
- offboarding arrangements
- outstanding concerns
- next review date
The organisation should also be able to distinguish between:
- a supplier that delivers a low-impact commodity service
- a supplier that processes sensitive information
- a supplier with administrative access
- a supplier that supports critical operations
- a supplier whose outage could stop the business
That distinction allows leadership to spend time and money where the commercial exposure is greatest.
It also creates a more useful conversation with the supplier.
The aim is not to catch suppliers out.
It is to make expectations clear, resolve gaps and understand how both organisations would respond if something went wrong.
Where FaultLine-CS adds clarity
Most organisations do not have one complete view of supplier exposure.
Procurement sees the contract.
IT sees the account.
Facilities sees the key fob.
Operations understands the dependency.
Finance understands the payment relationship.
Leadership sees parts of the risk, but not always how those parts connect.
FaultLine-CS’s role is to bring those views together.
An Exposure Assessment looks at where supplier dependency, cyber exposure, physical access, operational trust and unclear accountability may overlap. It does not replace specialist technical testing or formal certification. It helps leadership understand what needs examining, which assumptions require evidence and what action should come first.
The point is not to produce another pile of supplier questionnaires.
It is to answer the questions that paperwork often leaves unresolved:
Who can reach the business today?
What could they reach?
What depends on them?
Who owns the decision?
What evidence would leadership be able to produce tomorrow?
A supplier may be trusted.
The business should still be able to evidence why that trust remains proportionate.
Review where supplier trust becomes business exposure
Supplier relationships keep businesses moving.
The strongest relationships are not weakened by sensible scrutiny. They are made clearer by it.
Where supplier access, operational dependency or assurance evidence is difficult to explain, that is usually the right place to begin.
Discuss your supplier exposure with FaultLine-CS.
Key points box
- A trusted relationship does not automatically provide current assurance.
- Smaller and routine suppliers may hold significant access or operational importance.
- Supplier access can cross physical locations, data and business systems.
- Questionnaires collect useful information but may not show how exposure connects to the organisation.
- Supplier reviews should be proportionate to access, sensitivity and operational impact.
- Leadership should be able to evidence ownership, current access, dependency and review decisions.
- A supplier incident becomes a business incident when it affects customers, operations or continuity.


Leave a Reply