Many organisations spend most of their IT. From cloud hosting to helpdesk and security monitoring: The dependence on external parties is enormous today. Often there is a blind trust: •Our IT partner will handle it •Our IT partner will handle it •Our IT partner will handle it •Our IT partner will handle it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will manage it •Our IT partner will. But what if that partner is hit by a cyber attack, ransomware or bankruptcy?

A good cyber security strategy not only looks at internal processes and systems, but also at suppliers. Especially now the NIS2 (Dutch Cybersecurity Act) nis2 chain responsibility It is time for board members and IT board members to take this seriously in their cyber strategy.

What do we mean by a cyber security strategy?

A cyber security strategy is more than firewalls, antivirus and password policy. It is an integrated approach that connects digital risks to business goals and continuity.

  • What risks threaten our digital continuity?

  • How do we ensure prevention, detection and recovery?

  • How do we divide responsibilities between management, IT and suppliers?

  • How do we monitor and report on progress and incidents?

An adult strategy shall consist of:

  1. Risk assessment . Where are the vulnerabilities, internal and in the chain?

  2. Policy and governance .determine who is responsible (including suppliers).

  3. Measures .

  4. Incident Response (including partners).

  5. Continuous improvement .

Dependence of IT partners is generally high

Many companies trust their crown jewels – data, processes, customer information – to external IT partners. But:

  • They also have vulnerabilities. Think of an IT supplier that is hit by ransomware itself.

  • Their incident is your incident. If their systems fail, you stand still.

  • Insufficient insight. Often the management does not know what measures the partner has taken or has not taken.

This creates a blind spot: Your cyber security strategy is in order for your own environment, but stands or falls with your suppliers and chain responsibility.

NIS2 chain responsibility: why this is now urgent

Regulation and purchasing conditions of large customers emphasize this nis2 chain responsibility: You need to prove that your critical suppliers have appropriate security. In concrete terms, this means:

  • Board members remain responsible for risk management in the entire chain.

  • You show that suppliers meet agreed standards.

  • Incidents at suppliers affect your reporting and communication obligations.

  • Contracts, SLAs and due diligence are strategic instruments, not annexes.

In other words, The board cannot hide behind .our partner regulates the .

Examples from practice

  1. Ransomware with an IT service provider
    An RMM solution used by many MSP service providers was hostage to ransomware. Customers who used this software via IT parties were all victims of ransomware. They couldn't access their data for weeks, or the data was damaged irreparably by missing backups.

  2. Insolvement of a hosting party
    A web store lost data when the hosting party went bankrupt. There was no exit strategy and the backups were in the same data center at the bankrupt hosting party.

How do you include suppliers in your cyber security strategy?

1) Make supplier risks visible

  • Identify who your critical IT partners are.

  • Name which processes/data run through them.

  • Weigh the impact on failure or data breach.

2) Set requirements and set agreements

  • Process security requirements in contracts and SLAs.

  • Ask for certifications (e.g. ISO 27001, SOC2) and relevant reports.

  • Set reporting deadlines and responsibilities.

3) Key and monitor

  • Request periodic reports and discuss findings.

  • Plan joint evaluations and improvement actions.

  • Practice an incident together (tabletop exercise): Who does what, when?

4) Build alternatives in

  • Get an exit strategy: how do you migreate in case of trouble? Where is the code stored and can I get to it?

  • Judge whether you are too dependent on one supplier.

  • Consider fallback options for critical processes.

5) Involvement of the Board and the CoC

  • Make supplier risks part of quarterly reports.

  • Set choices and priorities administratively.

  • Give the CoC insight into chain responsibility and progress.

Board-level and supervisory role

For directors and supervisory directors, it is about direction and oversight. Not firewalls, but for the right questions:

  • Which IT partners are crucial to us?

  • How was their resilience secured and tested?

  • What agreements are contractually committed (security, notification, exit)?

  • What's our exit plan like?

  • Is chain responsibility secured in our cyber security strategy?

Checklist: suppliers and your cyber security strategy

  • Critical IT partners identified
  • risks and impact identified (including chain responsibility)
  • Security requirements and reporting obligations contractually laid down
  • Certifications/reports
  • Exit strategy defined and tested
  • Subject discussed in board and CoC
  • Periodic reporting and review

Conclusion

A cyber security strategy that only looks at its own organisation is incomplete. The dependence of IT partners is often the biggest blind spot. With nis2 chain responsibility, the time is right to address this structurally.

For board members and IT board members, there is an opportunity here: from obligation to strategic advantage. Organisations that control their chain are more resilient, reliable and attractive to customers and partners.