A supply chain is the network of people and companies involved in creating and delivering goods or services to the customer. When it comes to data and cyber security, if good practice is not followed, you may not only place your own organisation at risk but also others within your supply chain.
Under data protection law, you are responsible for managing your suppliers. You need to have a written contract with any suppliers that hold, create or amend personal data on your behalf.
How?
The first thing to do is to keep track of who your suppliers are and to check that you have contracts or service level agreements in place with all suppliers that handle personal data or supply IT systems or services, such as care planning or rostering system suppliers, IT support company, HR and payroll services etc.
We have a template you can use to list your suppliers. We also have guidance about the contracts you should have in place with these 3rd party suppliers.
IT supplier due diligence
For your IT system suppliers, or IT support company, you need to do more. You should undertake due diligence to check that they have good cybersecurity arrangements in place.
A good way to demonstrate that you have assured your suppliers’ cyber security arrangements is to check whether they have cyber security certification from a recognised scheme such as:
- Cyber Essentials is a UK government scheme to help organisations protect themselves against common online threats. Cyber Essentials has two levels –Cyber Essentials Plus is more rigorous and includes independent penetration testing of their arrangements. You can ask to see a copy of their certificate and you can use the iasme website to confirm that suppliers have an in-date Cyber Essentials certificate.
- ISO27001 is an international standard for managing information security. Certified companies will have been issued with a certificate by their certification body so you can ask to see a copy. You can also check the UK CertCheck website or the global CertSearch
- NHS Data Security and Protection Toolkit covers all aspects of information governance including cyber security. Check that your supplier has at least Standards Met and ideally Standards Exceeded. If their status is Standards Exceeded this means that they also have Cyber Essentials Plus. You can search the DSPT to check a supplier’s Toolkit status.
If your Digital Social Care Record Supplier is on the NHS Assured Solutions List then this means they have Cyber Essentials Plus and (from 1/9/26) ISO27001 as well as an up-to-date business continuity and recovery plan.
If your supplier does not have a recognised cyber certification, there are other things you can do. You could check that the supplier can provide proof of some form of officially recognised cyber security training for its key staff such as ISC2 or CompTIA or NCSC certified training. In addition, you could ensure that minimum cyber security requirements are included in the contracts you have with your suppliers.
If you are going to talk directly to your suppliers or potential suppliers, you could focus on these issues:
- Control or transparency of where your data is located
- Data access control and encryption (of data at rest and in transit)
- Testing of security arrangements e.g. penetration test or vulnerability scan
- Backup arrangements and how often these are tested
- Vulnerability management and incident response; what will happen if things go wrong?
Some organisations may provide information about their cyber security and privacy arrangements on their website, for example, see the Google Cloud Trust Centre and the Microsoft Trust Centre.