13 October 2022

UK’s cybersecurity agency issues guidance on how to secure supply chain


UK’s cybersecurity agency issues guidance on how to secure supply chain

The UK National Cyber Security Centre (NCSC) has released a 29-page guidance meant to help medium and large organizations to asses defences and resilience in their supply chains.

The move comes as a response to a significant increase of cyberattacks targeting supply chains in recent years. The new guidance urges organizations to work with their suppliers to identify weaknesses and boost resilience.

It also describes ways that organizations are exposed to vulnerabilities and cyberattacks via the supply chain, defines expected outcomes and offers key steps to help organizations assess their supply chain’s approach to cybersecurity.

These include understanding why supply chain security matters; developing an approach to assess supply chain security, prioritising critical assets, and create key components for this approach; ensuring that the team who will be involved in assessing suppliers are trained in cybersecurity; integrating the approach into existing supplier contacts; evaluating the approach and its components regularly.

Back to the list

Latest Posts

Cyber Security Week in Review: April 26, 2024

Cyber Security Week in Review: April 26, 2024

In brief: Cisco and CrushFTP patch zero-days, researchers sinkhole C&C server used by PlugX malware, and more.
26 April 2024
US charges Samourai cryptomixer founders with laundering $100 million

US charges Samourai cryptomixer founders with laundering $100 million

The cryptocurrency mixer facilitated over $2 billion in illegal transactions.
25 April 2024
ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

The attackers exploited two zero-day vulnerabilities in Cisco networking equipment.
25 April 2024