Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Your own supply chain

The part of the obligation suppliers forget

You were told to certify. You were probably also told to make sure your own sub-contractors do, and that half is the one that gets missed.

DCC Level 0 › Flowing down to suppliers

DEFCON 658 flows down. When it reaches you, it does not stop: where your own sub-contractors handle the information covered by the contract, the same obligations pass to them, and you are responsible for making sure they do.

This is the half that gets missed, partly because the flow-down clause is easy to skim and partly because it involves conversations with your own suppliers that nobody enjoys starting.

Which of your suppliers are actually caught

Not all of them. The test is whether the supplier handles, stores, processes or has access to the information the contract covers. That is narrower than "supplies you" and wider than "works on the contract".

Applying the test
SupplierUsually caught?Why
IT support provider with administrative accessYesAdministrative access to the systems holding the information is access to the information.
Cloud hosting for systems in scopeYesThe data sits on their infrastructure.
Design or engineering sub-contractorYesHandles the technical information directly.
Manufacturing sub-contractor working to your drawingsYesReceives and holds the drawings.
Logistics provider moving finished goodsSometimesDepends whether shipment detail is itself sensitive, which it can be.
Accountant, payroll, cleaning, cateringNoNo access to the covered information.
Recruitment agency supplying contractorsDependsThe agency usually not; the contractors they place, yes, as your users.

The one people miss is IT support. An outsourced provider with domain administrator rights has more access than most sub-contractors, and is frequently not thought of as part of the supply chain at all.

What to put in your contracts

Four provisions, in plain language.

  1. The obligation itself. That the supplier meets the cyber requirements applicable to the contract, at the level you specify.
  2. Evidence. That they provide certificates on request and tell you if certification lapses. The second part is the one that gets left out and the one you will want.
  3. Incident notification. That they tell you, within a stated period, of any incident affecting information relating to the contract. Your own notification obligation runs to a deadline, and you cannot meet it if your supplier tells you a fortnight later.
  4. Further flow-down. That they impose equivalent obligations on their own sub-contractors where relevant.

Keep it proportionate. A four-page cyber schedule sent to a three-person machine shop produces either a refusal or a signature nobody has read, and neither helps you.

Evidencing that you have done it

Assessors and customers increasingly ask, and "we sent everyone an email" is not evidence. What works is a short register recording, for each supplier in scope: what information they handle, what level they are required to meet, what they currently hold, the expiry date, and when you last checked.

A spreadsheet is fine. What matters is that it is current and that somebody owns it, because a register last updated fourteen months ago is worse than none: it demonstrates that the process existed and stopped.

When a supplier will not or cannot comply

It happens, particularly with small specialist suppliers who have no other defence work and no appetite for certification. Four options, roughly in order of preference.

Start with the list

Before any of this, produce the list. Every supplier, what information each one touches, and whether that brings them into scope. Most organisations doing it for the first time find two things: a handful of suppliers they had not thought of, usually including IT support, and several they assumed were in scope who are not.

That list is also the thing an assessor will ask to see, so producing it is not overhead, it is the deliverable.

What to actually send your suppliers

The obligation is easier to discharge than it looks, and the most common reason it stalls is that nobody wants to write the first message. Something like this works, and is short enough to be read.

We hold a contract that carries Ministry of Defence cyber security requirements under DEFCON 658. Because you handle information relating to that contract, the same requirements apply to you.

In practice this means holding a current Cyber Essentials certificate, telling us if it lapses, and telling us within [x] hours of any cyber incident that affects information relating to our work together.

If you already hold Cyber Essentials, please send us the certificate and we will keep a note of the expiry date. If you do not, it typically costs a few hundred pounds and takes a few weeks, and we are happy to point you at how to go about it.

We are asking because we have to, and we would rather have this conversation now than when a customer asks us.

Proportionate, honest about why, and it offers help. A four-page cyber schedule sent to a three-person machine shop produces either a refusal or an unread signature, and neither of those protects you.

The register, and what to put in it

Six columns, kept current, and it satisfies most of what an assessor or a customer will ask.

Verification takes a minute per supplier because certificates are on public registers. Put the expiry dates in a calendar with a month's warning and the register largely maintains itself.

What to do when your customer asks for it

Send the register. Not a statement that you have a process, the actual register, with the reasoning column filled in for the suppliers you determined were out of scope as well as the ones in it.

The out-of-scope reasoning is the part that demonstrates you applied the test rather than guessed. "Payroll provider: no access to covered information" is a decision. An absence from the list is an omission, and the two are indistinguishable to somebody reading it.

Does every supplier need to be certified?

No. Only those handling, storing, processing or with access to the information the contract covers. Your accountant and your cleaning contractor are not in scope. Your IT support provider almost certainly is.

What level do our suppliers need?

Generally the level appropriate to the information they handle, which may be lower than yours if they see only part of it. Where a supplier has the same access you do, expect the same level to apply.

How do we check they still comply?

Certificates are on public registers, so verification takes a minute per supplier. Put a reminder against each expiry date, and put an obligation in the contract that they tell you if certification lapses.

What if a supplier refuses?

Help them certify, remove their access to the covered information, substitute them, or escalate to your customer with the reasoning. What is not an option is leaving a non-compliant supplier in the chain and not mentioning it.

Working out who is in scope?

Send us your supplier list and what each one touches, and we will tell you which are caught and at what level.