Strengthening your supply chain security
The National Cyber Security Centre (NCSC) has released cyber security guidance for businesses who use third party providers to collect and store information.
Many businesses handle sensitive personal information, such as medical records and financial details. Often, this information is stored or managed by third party suppliers rather than the business itself.
Following a number of cyber security incidents involving third party suppliers earlier this year, the NCSC released new guidance to help businesses better manage cyber security risks when working with third party suppliers.
Under the New Zealand Privacy Act 2020, businesses must take reasonable steps to protect personal information from unauthorised access, loss, or disclosure. This responsibility extends to information held by third party providers.
Personal data is a valuable target for cyber criminals. Suppliers can sometimes be more vulnerable to attack if they do not have strong security measures in place. The good news is that many common cyber threats can be reduced by implementing basic, effective security controls.
Read the guidance here.(external link)
The guidance outlines practical steps businesses can take to protect information and strengthen supplier relationships. It also includes useful questions to ask when selecting and working with third party providers.
Managing supplier cyber security is not a one time activity. It should be an ongoing process, starting from the initial supplier selection and continuing throughout the relationship. By considering cyber security from the outset, businesses can reduce risk and better protect the information entrusted to them.