Supplier cyber risk FAQ for small businesses
A business can have strong internal controls and still be exposed through suppliers that hold data, access systems or send trusted payment requests. Supplier cyber risk is therefore part of normal business risk management, not just an IT issue.
6 practical answers.
### Which suppliers create the greatest cyber risk?
Prioritise suppliers with administrator access, remote access, sensitive data, payment influence or operational importance. Examples can include IT providers, cloud platforms, payroll, accountants, payment services and specialist software vendors.
### What should we ask a supplier about cyber security?
Ask about MFA and privileged access, security updates, incident notification, backup and recovery, subcontractors, data location where relevant, independent assurance, access removal and how they protect support channels.
### Should every supplier complete a long questionnaire?
No. Use proportionate due diligence. A low-risk stationery supplier does not need the same review as an IT provider with administrator access to Microsoft 365.
### How should supplier access be controlled?
Give only the access required, use named accounts where possible, protect privileged access with strong authentication, monitor important activity and remove access promptly when it is no longer needed.
### What should a contract say about incidents?
Important contracts should make responsibilities clear, including how quickly incidents must be reported, what assistance and evidence will be provided, data handling expectations and how access is ended. Obtain legal advice for contractual wording.
### How often should supplier risk be reviewed?
Review high-impact suppliers periodically and when the service, access, ownership, data processed or risk changes. Do not treat onboarding due diligence as a one-time exercise.