
Pondering Procurement · 2026-07-06 · 38 min
Key moments - from our scoring
Substance score
58 / 100
Five dimensions, 20 points each
As organizations outsource more functions and supply chains become increasingly complex, attackers are shifting focus from large tech companies with robust security to smaller suppliers that hold valuable data but lack mature security controls. Ben argues that procurement teams are uniquely positioned to mitigate this risk by embedding security requirements into supplier contracts early in the procurement process - not after signing. This contractual hardening ensures suppliers feel obligated to implement security controls before the relationship begins. The conversation covers supplier risk categorization (low, medium, high based on data sensitivity and system criticality), key security controls like access management and incident response processes, and relevant certifications like ISO 27001, Cyber Essentials, and ASOS tier reports. Ben emphasizes that cybersecurity isn't binary; organizations must define their risk tolerance and minimum acceptable controls based on supplier criticality. The episode also explores how procurement and security teams are often siloed, leading to overlooked risks and "shadow suppliers." For procurement leaders, this means understanding what data suppliers will access, ensuring contractual language addresses access control and least privilege, and building communication bridges with security teams to embed cyber risk management into the supplier lifecycle from onboarding through offboarding.
Because data shared with suppliers remains the organization's responsibility under regulations like GDPR - if a supplier is breached, the organization still faces fines and reputational damage. Embedding security obligations in contracts reduces risk by making suppliers contractually responsible for implementing controls before the relationship begins.
Suppliers should be categorized as low, medium, or high based on what data and systems they access and what impact their unavailability would have. Use the test: would a breach appear in major news outlets? If yes, it's high criticality and requires stronger controls like ISO 27001 certification; if no, lighter-touch requirements may suffice.
ISO 27001 is the primary UK standard for security maturity; Cyber Essentials and Cyber Essentials Plus are basic baselines showing security thought has been applied. For larger cloud providers like AWS and Azure, request SOC 2 Type II reports, where third-party auditors have already validated security controls.
Contracts should specify the right to audit suppliers, incident response timelines and reporting obligations, access control requirements (least privilege), security training standards, and data handling practices - with specificity varying by supplier criticality level.
Common mistakes include skipping security review to meet contract timelines, not understanding all data a supplier will actually access (beyond their core function), failing to involve security early in the procurement process, and not recognizing that shadow suppliers - vendors brought in without formal procurement oversight - create unmanaged cyber risk.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers moderately useful information about integrating cybersecurity into procurement processes, with several concrete frameworks (supplier tiering, contractual hardening, ISO/SOC2 standards) that a procurement professional would find actionable. However, much of the content relies on general principles rather than novel insights - the core message that procurement should collaborate with security on contracts early in the cycle is straightforward. The guest repeats key points multiple times (contract importance, early involvement, communication) which reduces density.
So one of the reasons why procurement needs to get more involved is because one of the best things that we can do is harden contracts. So we need to make sure that security language is within contracts
The earlier we can be involved at the start, the less hassle it is down the line. If you have it in the contract, you understand the criticality of the supplier.
The framing of procurement as a cybersecurity control is timely but not particularly novel - the concept has been gaining traction in security circles for several years. The host and guest largely rehearse established best practices (ISO 27001 certification, SOC2 compliance, access control, incident response plans) that are documented in widely available frameworks like NIST and OWASP. The 'back door' analogy and 'would it be on the Sunday Times' heuristic are mnemonic devices rather than original thinking. No contrarian arguments or first-principles reasoning are presented.
It's like if you were to try and get into someone's house, you may not go through the front door, you might go through the back door and it's because the back door is usually unlocked.
What would happen if it's on the newspaper? Um, would that be a massive impact?
Ben has legitimate credentials - 5 years of cybersecurity experience, a recent CISSP certification (master's-level equivalent), and Fortune 500 exposure across retail, manufacturing, government, and financial sectors. He has worked on multiple third-party security teams and understands the procurement-security interface from practical experience. However, his role and company are not clearly stated, and he comes across more as a mid-level practitioner/educator than a senior executive or founder who has personally led large-scale transformations. He is competent but not exceptional in terms of seniority or demonstrated business impact.
So my name's Ben. I've worked in cybersecurity for the last five years and I focus very much on third party security.
Yeah, so I've just passed my CISSP exam and that's the equivalent of a master's in cybersecurity. So you need 5 years experience to get a SISSP certification
The episode lacks concrete data, case studies with numbers, and specific examples that would anchor recommendations. The M&S breach is mentioned briefly but not explored with detail (timeline, cost, specific controls that failed). Accreditations (ISO 27001, SOC2, Cyber Essentials) are named but not compared quantitatively. The OWASP top 10 and NIST frameworks are referenced generically. Most claims are illustrated through principles rather than evidence: no metrics on breach impact, no cost-benefit analysis of early security involvement, no actual contract language examples despite discussion of 'contractual hardening.' The AWS example (4-hour outage) lacks financial impact detail.
So if you look at M and S, their breach was a third party supplier. They had poor security controls in place. They were then able to actually access the backend M and S website and then shut down the website.
there's one from IBM, there's one from Verizon and this basically tells you what is happening right now in terms of how are attackers trying to get into certain systems
Graham is a capable host who poses logical follow-up questions (e.g., 'Can you be more specific about what's embedded in contracts?', 'Where should we start?') and demonstrates genuine listening by referencing Ben's points. However, the conversation is largely non-adversarial and interview-like rather than investigative. Graham rarely challenges claims or asks for nuance - when Ben says security is 70% communication, Graham doesn't probe what evidence supports that or whether it's sector-dependent. The tone is collaborative and appreciative rather than critical. Ben is given substantial time to talk and is rarely interrupted, which is good for depth but reduces interrogation of soft claims. The conversation lacks productive friction or counterargument.
So let's make sure I fully understand, Ben. So when procurement is engaging with a new supplier, talk through more around the likes of those cyber risks that ah, could be introduced to the organization.
Can you be more specific? What are you looking to have embedded within a, uh, contract?
Computed from the transcript - who did the talking, and the words that came up most.
Cyber-attacks are increasingly exploiting weaknesses in the supply chain rather than targeting organisations directly. In this episode, Graham Crawshaw speaks with cybersecurity specialist Ben Jones about why procurement now plays a critical role in protecting the business. They discuss supplier risk, cyber due diligence, contractual safeguards, and the importance of closer collaboration between procurement and security teams. The conversation concludes with a practical framework procurement teams can use to assess supplier risk and strengthen cyber resilience.
Transcribed and scored by The B2B Podcast Index.
Speaker A: It's Graham Crawshaw, Procurement Content Director at casmi, here for another in the series of pondering procurement podcasts. Delighted, as always to have a special guest with us. And um, this is going to be a really interesting conversation because it's a very hot topic in procurement. Ben, would you like to introduce yourself?
Speaker B: Yeah, thanks very much, Graham. So my name's Ben. I've worked in cybersecurity for the last five years and I focus very much on third party security. So I've been working a lot with people in procurement, in legal and third party security doesn't just sit with the security team. And I think that's one of the things, one of the main things that we're going to go into today about how it's a business wide thing. So it's nice to be part of the podcast and it's come at a good time because as supply chains get more complex, the security risk is increasing. So I think it might be helpful for your listeners to listening to that.
Speaker A: Fantastic. Now you're pretty qualified in this. I've, uh, just learned from, uh, some of the things that you've been saying, so I think it's always nice to uh, get a feel you've just passed an exam. Tell us about that bit.
Speaker B: Yeah, so I've just passed my CISSP exam and that's the equivalent of a master's in cybersecurity. So you need 5 years experience to get a SISSP certification and then you have an exam and that was about six months of study for the exam. And then I've also worked for a Fortune 500 companies the whole time I've worked in cybersecurity. So yeah, I've, I've worked in this field, worked on multiple different clients. So government worked in the retail sector, worked in the manufacturing sector, uh, and now working in the financial markets. And that's really interesting in itself. And also worked in multiple different kind of third party security teams and it's been really interesting to see what works, what doesn't work. So, yeah, it's a field that I find incredibly interesting and um, looking forward to jumping into a bit more.
Speaker A: Excellent. Well, congratulations on that, uh, success with your exam and qualifications. And it confirms I'm talking to the right man here on the subject of cybersecurity, which is fantastic. It's everywhere. At the moment we're talking about cybersecurity. It's one of those very hot topics. But I would say that it's not something that procurement is part of that conversation. What's changed. Why should procurement leaders be now paying attention to cybersecurity?
Speaker B: Well, I think organizations are, uh, outsourcing things more than they ever have and the supply chain is increasing in complexity and therefore the risk is increasing. And anytime you bring a new supplier into your organization, there's the potential of a cyber attack. And what I was told when I joined cybersecurity was that actually attackers aren't going to focus on the big organizations, the Google, the Apples that have got really good security in place. They're going to focus on the small organizations that hold all of that data, but that don't have the security controls in place. And that's why third party security is such an important thing. It's like if you were to try and get into someone's house, you may not go through the front door, you might go through the back door and it's because the back door is usually unlocked. And that's the way that I think about it when I'm thinking about, um, third party security. So one of the reasons why procurement needs to get more involved is because one of the best things that we can do is harden contracts. So we need to make sure that security language is within contracts so that we're not passing all of the responsibility to the supplier, but we're making sure that the supplier is partly responsible for making sure that the organization's security is in a good place. And that contractual hardening is something that I've seen massively increase over the last two, three years. And procurement hold the relationship with the supplier, they hold those contractual negotiations and they need to happen as soon in the procurement process as possible. If you do it once you sign the contract, then the supplier has no obligation and they're unlikely to introduce those security controls. So you've got to make it a contractual requirement so that that hardening is done at an earlier stage. And interestingly, you said that this is becoming more and more prevalent. One of the things that we look at in cybersecurity is called owasp, uh, which is your top critical security risks. Now in 2021, supply chain security wasn't in the top 10, it's now stirred. So it's the third, uh, most critical security risk. And that is why we need to make sure that procurement understand the risk and ah, that they work with security. It's all about working in a team to making sure that these suppliers have the correct controls in place.
Speaker A: Fascinating. And of course, Certainly in the UK, what we experienced in 2025 with those attacks has really brought it to attention and people are sort of recognizing what happened there. And, and therefore the risk has suddenly become much more real because people can relate to what they heard, what they saw in the press, specifically from those companies that were sort of targeted. So you're saying that in reality, I mean, procurement has to be involved as early as possible to get it managed through that, uh, contract. In terms of actually managing that risk, where does procurement sit in that?
Speaker B: So I think in terms of managing the risk, one of the things that we do as security professionals is that we categorize suppliers. So not every supplier is going to have the same risk to the organization. And you would usually categorize in either tiers or you would either say low, medium and high. Now, depending on the category will depend on what kind of data that supplier has. It will also depend on what systems. But everybody thinks of cyber security is keep everything confidential. It's not necessarily the case. We're also looking at availability of the system. So what happens if that system goes down? What would then be the impact on the organization? And that's such a key thing. So one of the key things that we need to work with procurement is them understanding what the criticality is of that supplier and then how it should be managed throughout that procurement cycle. And that then links to all of the next stages. So once you've categorized your suppliers, you then need to look at how you're going to ask the questionnaires, how you're going to put your contractual hardening in place. But because of the time and resources it takes to do all of that, you wouldn't do the same hardening for a supplier that holds personally identifiable information and a supplier that does the cleaning. And that's where we want to really understand. One of the things as well with procurement actually that I've learned is that I need to learn about the supplier as a security professional. I need to understand exactly what service they're providing. I need to understand exactly how important they are to the organization. And that is something that you get through speaking with the procurement teams. So that's one of the reasons why the kind of relationship side is so important. And if you don't have that, then the security team are, uh, guessing more in terms of what the supplier actually offers to the business.
Speaker A: That makes so much sense in terms of getting that understanding and sort of from your perspective, wanting a, ah, level of planning, talking with the supplier, knowing what that supplier is being brought into the organization for, to then to be able to assess what actually needs to be done. So I Hear very loud and clear. It's not one size fits all. There has to be some adjustment. And you get your information by having those conversations with procurement. So actually that's a really good starting point that procurement needs to be aware of security needing that level of uh, information from the outset. And what you're saying is the earlier you do it then, uh, the better and the easier it becomes and probably quicker because let's face it, we're always under pressure to get these contracts into uh, place.
Speaker B: Well, it's quicker, but it's also so much cheaper in the future because if you have it in the contract and there's a breach, then you could then link back to the contract in terms of why that breach occurred. And there might be a level of responsibility on the supplier as well as the organization. You can't transfer the risk completely, completely, but you can reduce it. And also by putting it within the contract, the supplier then feels responsible to have the security controls in place before they start the relationship with the organization. And that's the really important part. They still responsible. And if you don't have that, then they don't feel the responsibility and therefore you're going to have more issues further down the line. And when we're looking at then auditing them and assurance and saying you don't have these particular security controls in place, they have no obligation to then fix that. So it's the obligation that's so important. And with all contracts and procurement people know this better than security people, contract is king. So we just want to make sure that security side is within the contract as well.
Speaker A: So let's make sure I fully understand, Ben. So when procurement is engaging with a new supplier, talk through more around the likes of those cyber risks that ah, could be introduced to the organization. Yes.
Speaker B: So in terms of the risk that could be introduced. So, uh, any data that you're giving to the supplier is data that then could be compromised. So if I'm giving personally identifiable information from my business to a organization that's managing the HR system, this is a key example, then they could then get access to all of that information that you've given to them, which is still your organization's data, but actually your suppliers managing that data. So they then have the same risk as you would if you held that. And people don't quite understand that. Sometimes they think we've transferred the risk, it's gone to the supplier, but you're still responsible. And when you look at things like gdpr, that personally identifiable information, if it's Breached, you will be fined even if your supplier, uh, are the people that were compromised. So the way that I would see it from a procurement point of view, if you were thinking about your supplier is what does my supplier do? What data, uh, does it hold? So of the organization's data and what would happen if that data was breached? Would that be on the front page of the Sunday Times? Would it be on BBC News? Would it ruin the reputation of the organization? These are all things that you should be thinking about. And that then defines the criticality level. Could we have an alternative supplier? So if the supplier is not available because of something called a denial of service attack, which is where somebody uses computers, uh, to basically shut down an organization and your supply chain, could you then move to an alternative quickly? If you could, it's low risk. If you can't and it's on a critical system, that's very high risk. That might not be because of the data, that might be because of the system itself. But I really like that analogy of would this be on the Sunday Times? It's something that I always say to people when I'm working with them, um, because it actually makes you think about risk in terms of what would happen if the supplier is breached.
Speaker A: So is it a question that the supplier is either secure or not secure? Uh, is it as black and white as that? Ah, I can't.
Speaker B: No, it's is not because nothing can ever be fully secure. It's something that we actually talk about a lot in security. You can't have a risk of zero. There's always going to be a risk that there will be a cyber attack. We something called a zero day vulnerability, which is something you just don't know about. And actually it's something that's then breached and then you have access to the system. So first of all, you can't have a perfectly secure organization. And also there's particular areas that I would say are key focuses. So access control. So who has access to your systems and how many people have access to those systems and what data's on those systems. If more people have access, there's more chance that they'll be breached. So if you, we call it unleashed, uh, privilege, you've got to make sure that the fewest people in the organization have access to the data so that there's less chance of it being breached. So that's one of the things. Access control is like a key thing. Another key thing is your instant response process. So when there is an incident, how does your organization speak to your Supplier to then coordinate that, uh, instant response process. And when do they need to report to you? That has been an instant. The longer it takes them to report, obviously, the bigger impact the that particular attack could have. And then you want to think about things like your security awareness training. And these are the really basic principles, but these are the things that you should be thinking about all of your suppliers and if you're more interested in this. So the NCSC has some really good cybersecurity advice on the real basics that you need to secure your supply chain. And then also you have things like Cyber Essentials, which is again, a very basic cybersecurity certification. But just to go on, um, from this point, one of the things that you should be looking at with your suppliers is if they're accredited in anything. So we have Cyber security accreditations, which basically says that this organization is good or decent at Cyber Security. Now, ISO 27001 is the UK, uh, kind of accreditation, but you also have, uh, Cyber Essentials and Cyber Essentials Plus. And if an organization has that, that would suggest to me that they at least have thought about their security controls and they have a relatively mature security posture when you start looking at bigger organizations. So your cloud companies, so aws, Azure, they do things called a SOP tier report. Now this is where an external organization will come in and they will audit the organization and say these either the security controls are secure or not secure, but the audit's already done for you. So all that you then need to do is read it and make sure that it's in place. But it and just kind of round this off. What you have to be thinking about consistently with your supply chain is what is your risk tolerance. So like say no securities pass Act, Uh, but what are we willing to accept? Do we want all of our suppliers to have the security controls that we have as an organization, or are we happy, depending on the criticality of the supplier, that there be different security controls? Because actually that particular data, it doesn't matter too much if it's breached, for example. So I wouldn't say that there's good and bad security. I would say that you would have to look at the security depending on the criticality of the supplier and then start to look at what are the minimum controls that you're willing to accept. So for some of the suppliers that I've worked on in the past, we say they have to be ISO 27000 on compliant. That's a minimum requirement that we say because of the criticality of the data that you hold, you need to have this and that then gives us assurance in that respect.
Speaker A: It's only like other ISO standards. Makes it really easy to know is then, have you got it or haven't you? So that I can definitely see makes the whole process of understanding the supplier so much easier. So do you see procurement making mistakes around this at the moment? I guess there are two sides. You've got the procurement teams that aren't involved at all and therefore not helping. Are, uh, mistakes also being made?
Speaker B: Yeah, so I think there's a couple of things, and I think sometimes it's a mistake and sometimes it's trying to avoid the process altogether, to be honest. So I think that sometimes procurement people are incredibly busy and they need contracts to go out and people have certain timelines and sometimes security can be seen as the delayer to get a contract out. And it's so important that people understand what happens when those steps are skipped. That's why I like to have these conversations with people in procurement to make them understand how, how important it is that the security team is checking the individual suppliers. So, first of all, we can be skipped. We can be seen as a blocker, and I think as security professionals, actually one thing that we need to do is work with the business to understand where we do block and understand where we can speed up that process. Because the more that we can work together, the better we're going to be overall. In terms of the lack of understanding, I think sometimes people don't think enough about the data that is going to sit on that supplier. So they say, okay, well, that's a supplier that works in, I don't know, they're a manufacturer, for example, so they won't have any personal identifiable information. But actually somebody logs into that system, somebody's given that data to be part of, I don't know, the security awareness training. This is just an example. But people don't think about all of the data that that, uh, supplier will hold. They just think about the core thing that they do, and therefore they're never going to have personally identifiable information. And I think it's that understanding of what exactly does your supplier do, what systems will they have access to and what would happen if that's breached? And I think that would really help procurement people in terms of just thinking about those three key things. And then I'll go back to that. What would happen if it's on the newspaper? Um, would that be a massive impact?
Speaker A: It's a really good way to, uh, keep that fresh in your mind, because everyone can think of that and uh, understand the implications for their own organization. So what would you like to see procurement doing more of? You talked about sometimes it's a bit of a struggle, but clearly there's a relationship between the two functions here. What could we do to make life easier and more, more effective?
Speaker B: So I think what I've seen is that procurement and security are completely segregated sometimes and they're just two different, almost two different organizations in an organization. Right. And actually if we spoke to each other more to understand exactly what we're both doing and how we could both help each other, then that's something that's going to massively help. So just keep security involved in the conversation. In security we have something called um, DevSecOps, which is where security is in the development cycle. But we make sure that it's as early on in the development cycle as possible so that further down the line you don't have to deal with those security vulnerabilities. And that costs a lot of money. And the reason why I mentioned this is I see it the same in procurement. The earlier we can be involved at the start, the less hassle it is down the line. If you have it in the contract, you understand the criticality of the supplier. If you've done your security checks before, your suppliers onboarded, the headaches are going to be a lot less once that supplier is then in run and when it's off boarded as well. So I think that's one of the things I'd like supercare to do more. I think also there's so much good information out there that we give as cybersecurity professionals. So we have a threat intelligence report, there's one from IBM, there's one from Verizon and this basically tells you what is happening right now in terms of how are attackers trying to get into certain systems still data and ultimately compromise your organization. And you don't need to be a cybersecurity expert but even reading those five minute kind of reports, it's just going to help you think about these things. So Access control is OWASP top 10 critical vulnerability. It's the critical risk. Sorry. So when you're thinking about your supply chain, access control is the thing that you should be thinking about as a most and I don't like even that very basic uh, knowledge would really help people when they're then thinking about their contract. Is there contractual uh, language that talks about access? Is there contractual language that talks about least privilege? And I think that really Helps. I think it's an education piece, and I think it's a communication piece of. And actually, one of the things I learned on my SIS course, which was really interesting, was that Cyber security is 70% communication, because we are professionals and we can help with cyber security, but it has to be across the organization because as soon as people start not understanding it or forgetting it or believing it's not important, the whole system goes down. Our, uh, cyber security professionals, we can't manage the whole organization. It has to be something that's embedded within the culture. And I think hopefully over the next few years, we see that communication happening more between procurement and cybersecurity. Interestingly, I have a question for you, Graham. Actually, do you see any cybersecurity people come to procurement events and talk about the need for cybersecurity in procurement?
Speaker A: No. It's a new area. I mean, it's fascinating hearing what you're saying, but it's just not something that is really coming about. Um, and I think that's going to change, and I think it's good that that is changing. I know, Kasmi, we did some benchmarking last year, and, um, very few organizations even seem to know when there is an issue, let alone being proud, proactive. Let's avoid an issue by talking, by making sure everything's covered in the contract. So I think that almost makes it such a hot topic, a topic of interest, because I think it's an area where change is necessary and we're responding because of some of the criminality that we've seen over the last year.
Speaker B: Yeah, and I think it's an interesting point, actually, that procurement as a function, understand what contracts the organization has, cybersecurity don't. So if we don't understand all of the contracts that's going on and all of the suppliers that's happening, there's no way that we can secure something that we don't know about. So that's why you have all of these organizations having these, we would call them almost shadow suppliers that we don't know that they exist. And then there's a breach. And then we go, well, did we ever look at the security of that supplier? Did we ever have contractual conversations? And the answer is probably no. So that is why, even though it might be a new thing in procurement, it is so important because like I said, every single time you implement, you bring in a new supplier, you are bringing in security risk, and you need to manage that risk effectively.
Speaker A: So, Ben, can I pick up on a point? You've now said it a few times. You keep talking about sort of that robust contract and of course that sounds great. Can you be more specific? What are you looking to have embedded within a, uh, contract?
Speaker B: Yeah, so, uh, it's a good question. And again, it depends on the criticality of the supplier. So if it's a low criticality supplier, we're not going to need that much contractual hardening within it. However, a high level criticality of a supplier, we would be looking to have the right to audit them. So we would be looking to have the right to go into the organization, go into their, um, particular offices and test their security control. If they're of that criticality risk. We need to make sure that's within the contract. We need to have a right to interview the suppliers to understand exactly what they're doing about their security controls. Because actually by that point, questionnaires, if it's a self assessment, they could say that they're great, but until we actually have conversations with them. So that's the first part. The first part is making sure that they're obligated to be involved in our security process. And another part of that actually is answering the questionnaires, which we find quite difficult at times. And I'm sure that's something that you know procurement all too well. The second side of it is what we call the minimum security controls. So things like, and I won't bore you with the details, but when we're looking at encryption, making sure that it's TLS 1.2, because 1.1 is insecure now. Okay, so it's making sure that those minimum security requirements are within the contract. So if it turns out that the supplier didn't have those things in place, then that's then on the supplier because they've signed a contract to say that those security controls are in place. And what we have, and um, what a lot of organizations have, is a security schedule that's been created by the security team that we want embedded into all of the contracts. And then we'll then have negotiations with the supplier. And what's interesting is when the supplier says we're not doing that, because if they say they're not doing that, it suggests that that control isn't within place. So then you have a further discussion. So that's one of the main reasons why contracts are so important is because the supplier is not going to sign something that they can't do. But we want to know why they can't do it. And it can be a negotiation point of view as well, um, which can be helpful. So I think all of those things means that the contract is one of the most important things and that makes perfect sense.
Speaker A: And flushing out, as you're describing, that awareness, that understanding of what that risk level is like, then the organization can decide is that an acceptable level that they're prepared to take on board or no, something needs to uh, change, even if it's that supplier cannot be authorized.
Speaker B: Yeah. And it does depend on the amount of negotiation power that you have. But usually suppliers are going to. When they're signing a contract, they're much more likely to implement security controls and say we will do this because they want the contract, they want the financial reward of that. Uh, once contract signed, it's almost. They forget about it and try and move on to the next deal. So that's the problem we have. And I'm sure you see that in procurement on a daily basis.
Speaker A: Absolutely. And it's interesting hearing you talk like this because I think what we're now saying is, as well as some of the other requirements that you really need to have in place, whether it's connected with esg, all the fundamentals around sustainability, and so the list goes on, we're actually adding security to that list of what really does need to be negotiated in advance. Equally, you talk about questionnaires and um, that can be a source of frustration. We've spoken about questionnaire fatigue. It can get a bit sort of too. It can be a problem if there are just too many questionnaires. But I guess from what you said earlier, that's where the ISO standards or the SoC2 comes into play. Because if they can say that they've achieved that level, then there's less of a need for a questionnaire.
Speaker B: Yeah, I mean, I would say you need to be careful on how much you rely on a ISO 27001 like it. It provides a good level of assurance. But if it's a critical supplier, you can't just only say that they're ISO. And they say, but in terms of that, questionnaire fatigue is definitely something that we see. I think there's a couple of things with that. One of them is that if they're ISO or if they're SOC compliant, you can descope a lot of the questions in the questionnaire, uh, and make sure that you're only answering the questions that uh, are uh, actually useful. I think also I've seen some really good examples of automation of questionnaires, so making it a lot easier for the supplier to answer. So this is an Excel. This is using something, uh, I use something called Risk Ledger, um, on one of my clients. And that was just something that really helped in terms of them answering the questionnaires and us tracking that. And we had some good response rates, so. And there's lots of other tools out there. One, trust all of them. But that particular side of it, making it as easy as possible for the supplier to answer the questionnaire, uh, is definitely something that's important, but we need to see a level of assurance that certain, um, controls are in place. And there's really two ways that you can do that. One of that is questionnaires. And then the other way is to audit them. And we would rather do a questionnaire because it's a lot lower expense on us. But also, uh, you know, you're not going to audit all of your suppliers.
Speaker A: You would need a third party auditor to be brought in to do that because your own company is not likely to be qualified sufficiently to do that audit.
Speaker B: Depends on the size of the organization. So some organizations will have their own internal audit team that they go out to the suppliers with. Some organizations will hire, you know, your big consultancies to go in and do that themselves. And that's what SOC2 gives you. So if the organization is SOC2 compliant, that's basically the fact that they've gone in, done an audit and then you get the report. So working with suppliers that are SOC2 compliant is very helpful in that respect.
Speaker A: In terms of what you're pushing to the supplier, in terms of risk and responsibility and words like indemnity start cropping up. What are you expecting the supplier to demonstrate and be responsible for? Perhaps when things go wrong and there is a breach or there is an issue, what is that, uh, level of reasonableness that you can't just sort of say, oh, it's down to the supplier, they can cover all that cost. Again, if you think of some of the examples that we experienced in 2025. So what are you really looking for from those suppliers when there are issues?
Speaker B: Yeah, it's a really good question. Uh, and I think it comes back to that, that 70% of cybersecurity is communication. So we expect suppliers to communicate with us once there's been a breach. We expect them to have an instant response plan that means that they can respond to it as quickly as possible and they should have one in their organization. But ideally that would be linked with what, uh, we do as well. And also as an organization, we need to look at our supply chain, concentration, risk and say, actually, do we have too much reliance on this particular supplier? If it goes down, if it's breached, would that completely ruin our organization? And it's something that we're starting to look at more in cybersecurity in terms of if all of your data sits on AWS and AWS is breached, would that then mean that your whole system goes down? And people used to say, well, AWS won't be breached or AWS won't go down. It did for four hours. And pretty much all of the different applications around the world just shut down for four hours. Some lost a lot of money during. So we look at that supply chain concentration. But in terms of what we expect from the supplier, it really is that communication and it's also working with the security team that is what we try and embed within our contracts is almost making sure that they have an obligation rather than just goodwill. Because as much as we like to think that everybody loves about security, it's not always the case. So, uh, sometimes we need to make sure it's an obligation.
Speaker A: So, Ben, as we now have a much better understanding of security, what do you advise? What do you recommend that procurement does, if it is aware that perhaps it's not been as thorough as some of the points that you've been talking about? Where should we start? What's the first actions that should be done?
Speaker B: So I think first of all, procurement should have it a list of all of their suppliers. So almost, you know, these, these are all of the suppliers that we have in the organization.
Speaker A: And then I'd hope that everyone listening has got that so good.
Speaker B: I would hope so. I started easy and it's going to get more difficult to carry on. So. So then I would say that you need to classify, so you need to understand what are your different tiers within your organization and what risk are you willing to accept. And then that should go in a low, medium and a high category. And that should be defined with procurement, with legal and with security. Once you've done that, then look to see what particular accreditations you're going to accept. So are you going to accept ISO 27001? Are you going to accept Cyber Essentials? Are you going to accept SoC2? And then link that back to your classification. So say, okay, well actually they've got SOC2, they're a medium supplier, that's fine. We're not going to do any more particular checks on them. And that will also link to how big your organization is, how much resourcing you have, how much Capacity you have to manage this. Then I would look at the contracts. So based off the criticality of your supplier, what does a high contract look like? Well, there's a medium contract, like what does a low contract look like in terms of that criticality? What are the key things that need to be included within those? And how do we make sure that all of our new contracts are done? Uh, that. But also if there's a renewal, how we're having those conversations and surprised because those conversations will need to start quite early. Then you then look at the questionnaire, uh, and then as you work through your supply chain security and you start to embed that, constantly think about what risk tolerance are you willing to accept? Are we within our risk tolerance? Are we outside of our risk tolerance? And how can we improve security 1% every day? And you're not going to get a place straight away where security is going to be perfect. In organizations, security is never perfect. It's one of the things that I learned quite early on in my career. But we just need to try and improve and get better and make it harder and harder for attackers to be able to compromise. And we spoke about it right at the start. If you look at M and S, their breach was a third party supplier. They had poor security controls in place. They were then able to actually access the backend M and S website and then shut down the website. So there was a lot of controls there that failed. And if you had a few of those controls in place, the chances of that happening would have been less. So it's about that continuous improvement and continuously looking at your supply chain and making sure that as many of the suppliers as possible, you understand what risk you have by having them as a supplier of the business.
Speaker A: Excellent. What I particularly like is you're very much advocating security and procurement working together. And I think what we've seen over the years is procurement is great at facilitating those conversations with the other functions of the business so that departments aren't working in isolation but are uh, collectively working to a common uh, objective. And I think that is going to be the, the way that procurement will be able to add value and make it really much more robust in terms of security.
Speaker B: I completely agree. And hopefully more security professionals will be joining procurement podcast and helping uh, give the message. And more people will be going for lunch together in procurement and security and be able to have proper conversations because that's where this all gets better is if there's that communication between the two areas and they're not segmented and it's so interesting. You know, a lot of what we do in third party security is actually looking at the procurement cycle and you almost then feel like you're sort of in procurement, but then there is a big kind of separation. And I think you should almost have a security professional in the procurement cycle that works in the procurement team. I think that's the best way to implement it. We're not there yet, uh, but I think if we could get there, that would be probably the best way to do third party security.
Speaker A: So, Ben, thank you so much for your insights today. And I think what's going to be fascinating is to revisit this in the future to really see how procurement and security are able to work together with that objective of reducing risk and reducing threats to the organization.
Speaker B: Well, thank you very much, Graham. It's been great to be on. I've really enjoyed the conversation. Um, something that I am generally quite passionate about because I do think that supply chain is one of the most important parts of security. That, you know, the whole backdoor analogy, you're going to go through the weakest point, so you've got to make sure that that weakest point is as secure as possible. Um, and I hope that I can join more procurement talks and things and start to build that network with more people in procurement, because I think that would really help in third party security as a whole.
Speaker C: We hope you enjoyed this CASB Podcast. All episodes can be found on Spotify and the Apple Podcast app. Remember to subscribe so you don't miss a future one. If you'd like to find out more about casme's procurement events, research and benchmarking, get in touch with us@casmi.com home.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.