Cyber Risk Compendium

Supply chain & key supplier relationships

The organisation's ability to deliver its own product or service often depends on suppliers and their systems being fit and available — cloud providers, software vendors, logistics partners, or even a single specialised supplier with no easy substitute.

This is closely related to the Supplier / third-party service provider (sub-processor) stakeholder, but here we're evaluating the relationship and dependency itself as something to protect and diversify, not the supplier as a party to manage.