When a manufacturer’s systems are breached through a vendor, attackers do not bypass the manufacturer’s defenses directly. Instead, they compromise the vendor’s security controls and use a legitimate, trusted connection to gain access.
This is supply chain cyber risk in practice, and it has become one of the most significant and consistently underestimated challenges in manufacturing cybersecurity.
Why the Supply Chain Is a Target
Attackers follow the path of least resistance. For manufacturers, that path increasingly runs through the supply chain.
It may be:
- A Tier 1 supplier with a trusted EDI connection
- A controls vendor with remote access to operational technology (OT) systems
- A logistics platform integrated with an ERP system
- A software provider whose compromised update mechanism distributes malicious code to every customer
Each of these relationships represents a legitimate, credentialed connection into your environment. If a third-party vendor has weak cybersecurity controls, including inadequate multi-factor authentication (MFA), unpatched systems, or poor access management, your organization’s security becomes dependent on theirs.
Major incidents such as the SolarWinds and Kaseya attacks have demonstrated how attackers use trusted vendors as force multipliers. By compromising one supplier, they can potentially gain access to hundreds or even thousands of customer environments.
What Vendor Risk Management Actually Requires
Most manufacturers have some form of vendor risk management, typically consisting of a security questionnaire completed during onboarding and filed away after review.
That is a starting point. It is not a comprehensive vendor risk management program.
Effective vendor risk management requires four essential components:
Risk-Based Vendor Tiering
Not every vendor presents the same level of cybersecurity risk.
A vendor with remote access to production systems presents significantly greater risk than a vendor supplying office products.
Organizations should classify vendors based on:
- System access
- Data sensitivity
- Operational dependency
- Business impact
Higher-risk vendors should receive greater scrutiny and more frequent reviews.
Validation Beyond Security Questionnaires
A completed security questionnaire reflects what a vendor reports about its cybersecurity posture.
For critical vendors, organizations should request objective evidence such as:
- SOC 2 reports
- ISO 27001 certifications
- Penetration testing summaries
- Independent security assessments
- Information regarding subcontractor security practices
Verification provides greater confidence than self-attestation alone.
Ongoing Vendor Monitoring
Vendor cybersecurity programs change over time.
A vendor that met security expectations during onboarding may later experience a breach, organizational changes, or technology modifications that introduce new risk.
Vendor risk management should include periodic reassessments, at least annually for high-risk vendors, and additional reviews following significant business or security events.
Strong Contractual Security Requirements
Vendor agreements should clearly define:
- Required cybersecurity controls
- Incident notification timelines
- Audit rights
- Security responsibilities
- Breach reporting expectations
Healthcare organizations frequently accomplish this through Business Associate Agreements (BAAs).
The Access Management Dimension
Vendor cybersecurity assessments are only part of the equation. Manufacturers must also actively manage the access vendors have within their environments.
That includes:
- Granting only the minimum access required to perform assigned work
- Using temporary or task-specific credentials instead of permanent access
- Requiring MFA for all vendor remote access
- Logging and monitoring vendor activity
- Promptly removing access when projects or contracts end
A vendor that completed a maintenance project years ago but still has active credentials represents unnecessary risk.
Regular reviews of third-party access often identify outdated accounts, excessive permissions, and dormant connections that should no longer exist.
Manufacturers should establish similar contractual protections for vendors with access to critical systems or sensitive information.
Starting Where You Are
Building a mature vendor risk management program takes time, but organizations do not need to implement everything at once.
A practical starting point includes:
- Creating an inventory of vendors with system access
- Classifying vendors by cybersecurity risk
- Prioritizing reviews of high-risk vendors
- Incorporating stronger security requirements into future contracts
- Conducting annual reviews of vendor access and cybersecurity posture
Vertikal6 helps manufacturers develop vendor risk management programs that are practical, scalable, and aligned with broader cybersecurity objectives. Through elevate™ ADVANTAGE, our vCISO services provide the governance, oversight, and risk management framework needed to turn vendor management into an ongoing security program.
Bottom Line
Your supply chain is an extension of your attack surface.
Managing vendor relationships, controlling third-party access, and continuously evaluating supplier cybersecurity are essential components of a modern manufacturing cybersecurity strategy.