
The global pandemic has underscored the need to understand risk associated with critical third parties in your cyber supply chain as they can bring your business to a halt or at least have a major negative impact. So it’s no wonder that the National Institute of Standards and Technology (NIST) listed “Know and Manage Critical Suppliers” as one of its “Key Practices in Cyber Supply Chain Risk Management: Observations from Industry.” Unfortunately, this advice can be hard to put into practice, especially for organizations trying to manage cyber supply chain risk using manual or disparate systems.
Aravo’s 2020 benchmarking research found that 25% of survey respondents didn’t know what percentage of their third parties would be categorized as critical. And fewer than one-third felt they could report on critical third parties quickly and completely. Not having access to data related to critical vendors exposes organizations to serious risk and limits the ability to create effective business continuity and organizational resilience plans.
This is the third in a series of Aravo blogs exploring NIST’s Key Practices. Previous installments focused on integrating C-SCRM across the organization and establishing a formal C-SCRM program.
A critical supplier is a third party whose failure or disruption would significantly impair your operations, revenue, or compliance.
Before you can leverage technology to identify critical suppliers, the first step is to identify what criteria is used to define a critical supplier. Beyond a complete inability to function if they were disrupted, critical supplier designation can be based on multiple factors, such as amount of spend, volume or sensitivity of data processed, or ability to act as a threat vector. The NIST guidance includes links to additional resources that can help you determine the criteria that is most appropriate for your organization.
In Aravo industry research, organizations that are able to track supplier criticality typically report that about 10% of their third of their suppliers are categorized as critical. However, there is no universal heuristic for how many suppliers should be considered critical. That decision will be driven by the nature of your business and your supplier ecosystem.
Even with perfectly defined criteria, trying to identify and tier suppliers using spreadsheets can be complicated and prone to error. To streamline this process and reduce exposure, you’ll want to choose technology that can:
Check out the other installments of this blog series to explore the rest of NIST’s Key Practices. The complete list includes:
1. Integrate C-SCRM Across the Organization
2. Establish a Formal C-SCRM Program
3. Know and Manage Critical Suppliers
4. Understand the Organization’s Supply Chain
5. Closely Collaborate with Key Suppliers
6. Include Key Suppliers in Resilience and Improvement Activities
7. Assess and Monitor Throughout the Supplier Relationship
8. Plan for the Full Life Cycle
Identifying critical suppliers is crucial for preventing business disruption and mitigating major negative impacts from third-party risks. It enables organizations to develop effective business continuity and resilience plans, safeguarding against potential cyber supply chain failures and ensuring operational stability.
Organizations define critical suppliers based on various factors, including the potential for business disruption if the supplier fails, the amount of spend, the volume or sensitivity of data processed, and their ability to act as a threat vector within the cyber supply chain.
To classify critical suppliers, consider if their disruption would halt your business operations, the volume and sensitivity of data they handle, and their potential as a cybersecurity threat vector. Align your criteria with your organization’s specific business model and risk appetite.
While there’s no universal rule, organizations often categorize approximately 10% of their third-party suppliers as critical. This percentage varies significantly based on the specific nature of the business, its operational dependencies, and its unique supplier ecosystem.
Technology can systematically identify critical suppliers by applying defined criteria, automate due diligence based on risk, and proactively alert to continuity threats. It also helps monitor contractual terms and triggers escalation processes for non-compliance or adverse events.
Not knowing critical suppliers exposes an organization to serious risks, including widespread business disruption, significant financial losses, and regulatory non-compliance. It also severely limits the ability to create and execute effective business continuity and organizational resilience plans during a crisis.
Supplier criticality should be re-evaluated periodically, such as annually or biennially, and whenever there are significant changes to the supplier’s services, the contractual terms, or the organization’s business needs. This ensures designations remain accurate and relevant.
Share with Your Friends: