Could your suppliers be your cyber weak spot?
Very few businesses in Bermuda operate entirely on their own. Whether it’s an IT provider, payroll company, cloud platform, payment processor, accountant or specialist contractor, most organisations rely on other businesses every day.
Those relationships make modern business possible. But they also mean that looking after your own cybersecurity is no longer quite enough. If another company can access your systems, store your information or provide a service you depend on, its security can have a direct impact on yours.
That doesn’t mean treating every supplier with suspicion. It simply means understanding where those connections exist and making sure the protection around them reflects their importance.
Cyber-risk doesn’t stop at your front door
A cyber incident doesn’t always begin inside the organisation that ultimately feels the impact. An attacker might compromise an IT support account, steal credentials from a contractor or target a cloud service used by hundreds of different businesses.
So while strong passwords, multi-factor authentication and secure devices remain essential, businesses also need to think about the organisations they connect to.
Since Bermuda’s Personal Information Protection Act came into force in January 2025, this has become part of a wider conversation about responsibility and trust. Passing personal information to a third party does not pass on your responsibility for protecting it.
Bermuda saw an example of this type of interconnected risk that same month, when a breach affecting PowerSchool, the student information system provider used by Bermuda public schools, exposed information relating to local families and teachers.
It is a useful reminder that where a breach happens and where its impact is felt can be two very different places.
Start with one simple question: who does your business depend on?
This doesn’t need to become an enormous cyber exercise.
Start by thinking about the services your business would struggle to operate without.
For a retailer, losing access to its payment provider could mean being unable to take sales. For a professional practice, an unavailable booking or case-management system could disrupt operations. If an outsourced IT provider’s account is compromised, the access it has may make that particularly significant.
Supplier size is not necessarily the important factor. A small contractor with administrator access can represent a greater risk than a much larger supplier with tightly restricted access.
Instead, ask:
• What information does this supplier hold?
• What systems can it access?
• Does it have administrator or remote access?
• What would happen if its service stopped tomorrow?
• How quickly could we replace it or work around the problem?
Those questions will usually tell you where to focus first.
Do some supplier housekeeping
One of the simplest improvements is making sure you actually know who has access to your business. Over time, organisations accumulate software subscriptions, contractors, old user accounts and services that nobody quite remembers owning.
Compare your supplier contracts, recurring payments and system access records. You may find former contractors who still have logins, software that is no longer being used or suppliers with more access than they genuinely need.
From there, create a simple supplier list. Record what each supplier provides, what data or systems it can access, how important the service is and who within your business manages the relationship.
Give people the access they need, not more
Another practical step is to review permissions. If a supplier needs access to one system, it doesn’t automatically need access to everything else. Administrator rights should be reserved for situations where they are genuinely required.
Multi-factor authentication should also be used wherever available, particularly for accounts with elevated or remote access. And when a project or contract ends, access should end with it.
These are simple controls, but they can significantly reduce the chances of a compromised supplier account becoming a wider problem.
Ask suppliers to show you how they manage security
For your most important suppliers, it is reasonable to ask how they protect themselves and the information entrusted to them.
That conversation doesn’t need to begin with a lengthy technical questionnaire. You might start by asking how they control access, whether multi-factor authentication is used, how they respond to incidents and whether they hold recognised cybersecurity certifications.
IASME Cyber Baseline provides a structured way to demonstrate fundamental cyber hygiene, while IASME Cyber Assurance looks more broadly at cybersecurity governance, privacy, risk management and data protection. ISO 27001 provides a formal information security management framework.
Certification can’t guarantee that an organisation will never suffer an incident, but it can provide useful evidence that defined controls and processes have been assessed.
Your customers are asking the same questions about you
There is another side to supplier security that is easy to overlook. You’re probably somebody else’s supplier too.
If customers trust you with personal information, give you access to their systems or depend on your service, your cybersecurity becomes part of their risk. That makes good security more than an internal IT issue. It becomes part of how dependable you are as a business partner.
Cybersecurity is a shared responsibility
Cybersecurity no longer stops at the boundaries of your own business. The suppliers you rely on can affect your risk, just as your own security can affect the customers and partners who depend on you.
The practical response is to understand those relationships, focus first on the suppliers with the greatest access or importance, and put sensible controls and assurance around them. You can’t remove third-party risk completely, but you can make it visible, manageable and better controlled.
• Louise Ralston is chief operating officer of Cyber Tec Security, a cybersecurity specialist business providing cyber certification-led resilience and adherence to regulatory compliance
