Why Your Spreadsheet Can't Save You: Rethinking Supply Chain Risk with Risk Ledger

How the Risk Ledger CAF talk reveals why spreadsheet-based supplier checks are failing UK organisations, and what continuous, collaborative supply chain visibility looks like instead.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Techie Tuesdays

When Synnovis (which manages pathology testing services across South East London) suffered a cyber attack in 2024, the consequences went far beyond a data leak. The attack was primarily enabled by a lack of MFA on legacy entry points and the fallout included more than 12,000 patients affected, over 10,000 cancelled appointments, more than 1,700 cancelled surgeries, a blood emergency shortage, and at least one reported death, alongside the leak of patient data including names, dates of birth and medical results. A single supplier breach rippled straight into patient care!

This example was shared by Justin Kurugila, Chief Cyber Security Strategist at Risk Ledger, during our recent event on supply chain security and the Cyber Assessment Framework (CAF). The reality is that most organisations still don't really know what is happening in their supply chain, and the tools they rely on to manage that risk were never built for the job.

Supply chain attacks are not going away

Supply chain attacks have been a growing problem for well over a decade, and incidents that once felt rare now happen on a near weekly basis. Attackers, whether financially motivated cyber criminals or nation state groups, have realised that targeting one supplier can open the door to hundreds or thousands of downstream organisations. It’s a far better return on investment than attacking a single target directly.

The organisations most at risk are often not the household names, it’s the small, specialist suppliers working quietly behind the scenes, delivering services that dozens or hundreds of clients depend on, that most people have never heard of. That obscurity is exactly what makes them attractive targets and exactly why they are so dangerous when something goes wrong.

The spreadsheet problem

For most organisations, third party risk management still means a spreadsheet. A checklist is sent to a supplier, a few boxes get ticked, and the assessment is filed away for a year, or three, until the contract comes up for renewal.

The trouble is that supply chains are not static, they’re living, constantly shifting networks. A supplier you assessed three years ago may have changed its own vendors, its infrastructure, or its risk posture multiple times since. A spreadsheet tells you whether a supplier answered your questions once but tells you nothing about what happens the day that supplier is breached: which of your services would be affected, which incident response playbooks you would need, or whether you have even rehearsed them.

Governance and maturity should lead to compliance, not the other way round. A point in time checklist exercise can tick the compliance box without making an organisation any more secure.

Where the CAF fits in

Frameworks like the CAF, and equivalents such as DORA in the European financial sector, exist because regulators have recognised just how significant supply chain risk has become. Under the CAF, Principle A4 on Supply Chain sets out that an organisation understands and manages security risks to the networks and information systems supporting its essential functions that arise from dependencies on suppliers, including ensuring appropriate measures are in place wherever third party services are used. It splits into two objectives: A4.a Supply Chain, which covers understanding and managing supplier risk, and A4.b Secure Software Development and Support, which covers maximising the use of secure and supported software whether built in house or sourced externally.

The framework doesn’t prescribe specific tools or software; it asks a more fundamental question: can your organisation demonstrate that it understands and manages its supply chain risk? Public sector organisations tend to work toward this in five steps: knowing your supply chain in depth, assessing and tiering suppliers by criticality, managing risks continuously rather than at a single point in time, governing suppliers through clear contractual obligations, and having a defined process to detect and respond to incidents.

There is no pass or fail here. The goal is a defensible position, one where an organisation can show its board, its regulator, or the public that it took supply chain risk seriously and made informed decisions, rather than being caught off guard.

Why organisations struggle

The practical barriers most teams face when trying to complywith CAF Principle A4:

  • Limited resource and capacity. Many organisations have just one person juggling third party risk alongside procurement or wider security duties.
  • Siloed approach. Supply chain risk is often treated as a standalone task rather than something woven into wider security and procurement decisions, with little to no collaboration or intelligence sharing between peer organisations.
  • Point in time assessments. A supplier reviewed once under a multi year contract can change significantly before the next review comes around.
  • No supply chain visibility. Most organisations simply do not have a clear picture of who their suppliers depend on in turn.
  • Low supplier engagement, especially among smaller suppliers. Smaller organisations rarely have the commercial weight of a Microsoft to demand answers from a supplier.
  • No process when incidents occur. When a supplier is hit and the news breaks, most clients are left emailing for updates along with everyone else, with no dedicated channel for information, and ad hoc programmes are a poor defence during an active incident.

None of this is unique to small organisations as even large, well-resourced teams admit that resources never feel like enough for the scale of the challenge.

Collaboration as the answer

Risk Ledger's approach is built around the idea that trust and visibility come from human connections, not just automated scans of the internet. With more than 16,000 organisations already on the network, the chances are good that a given supplier already has a profile that has been reviewed by your peers.

Outside in monitoring, of the kind governments and threat intelligence teams already do well, can flag that a connection between two organisations exists. What it cannot tell you is what that connection actually means. Traffic to a cloud provider might indicate a critical hosting dependency, or it might just be a member of staff streaming a video. Only the organisation itself, and its direct relationship with the supplier, can answer that question with confidence.

By building a shared network where organisations and their suppliers are connected, and where peer organisations can see overlapping dependencies, Risk Ledger's model allows:

  • Assessment sharing, so that work already done by one organisation on a shared supplier does not need to be repeated from scratch by every client.
  • Continuous  assurance, replacing a three year review cycle with ongoing visibility as suppliers and peers update their own postures.
  • Faster incident response, with information pushed directly to connected organisations rather than each one having to chase answers individually.
  • Systemic risk visibility, surfacing what Risk Ledger calls concentration risk: cases where many organisations, often without realising it, depend on the same small handful of underlying suppliers.

Concentration risk in practice

Two case studies illustrate the scale of the problem oncevisibility improves.

UK councils. In a project run with a group of local authorities, the goal was simply to help councils understand their supply chains. Within the first two weeks, 10 councils had mapped 180 suppliers between them and identified 20 concentration risks. Fifteen months later, the community had grown to 33 councils, with 1,540 suppliers mapped, 823 of them unique, and 65 concentration risks identified.

UK central government. A separate programme covering 31 client departments and arm's length bodies mapped a supply chain of 7,116 suppliers in total: 2,499 third parties, 2,539 fourth parties and 2,078 further tier suppliers. Within that, 928 concentration risks were identified overall,289 of them among direct third party suppliers and 88 among fourth parties. Of the third party concentration risks, 139 were rated critical, 117 important and33 minor or unknown, meaning nearly half of all direct third party concentration risks are rated critical, so an incident at one of those suppliers is likely to disrupt essential services at multiple public sector organisations at once. Separate analysis found 28 suppliers rated critical by three or more organisations, though inconsistent tagging between departments risks excluding genuinely key suppliers from proper scrutiny.

Cyber Essentials adoption told its own story. Among suppliers rated critical, 56 percent held Cyber Essentials, against 45.6 percent across third parties as a whole. The instinct in many organisations is simply to push that number toward 100 percent. Focus first on the critical suppliers that lack basic assurances such as Cyber Essentials or ISO 27001, since those are the relationships that carry the most risk if something goes wrong.

How Cyber Vigilance helps put this into practice

Understanding why continuous, collaborative supply chain visibility matters is one thing. Operating it week in, week out is another, and it is exactly where most internal teams run out of capacity.

That is the gap our Managed TPRM service is built to close. Delivered on top of your Risk Ledger account, it turns the platform into a fully operated programme rather than another dashboard someone has to remember to check.

The service pulls your entire supplier portfolio from Risk Ledger every six hours, so scores, risk levels and open issues never go stale between review cycles. That picture is then enriched with open-source intelligence from ten sources, including Companies House, breach history, NCSC advisories, and certificate and email-security hygiene, giving you outside-in context that a self-reported assessment alone cannot provide.

From there, the service does the work most teams struggle to find time for:

  • Triage and remediation. New critical and high risks are automatically turned into tracked remediations with a defined action plan and due date, and a ten-point drop in any supplier's score triggers an immediate analyst-reviewed follow-up.
  • Supplier chasing. Overdue and at-risk suppliers receive analyst-approved chase emails. Nothing goes out without human sign-off.
  • Board-ready reporting. A weekly analyst-reviewed report covers portfolio health, new activity and next-week actions in plain English, with quarterly reviews consolidating the trend for board and audit purposes.
  • Framework mapping. Findings are framed against whichever frameworks you report against, including DSPT, CAF, Cyber Essentials, CE Plus, DTAC, ISO 27001,     DORA and NIS2.
  • Corporate due diligence. Gap-scope checks against Companies House, ICO registration, OFSI sanctions and the Charity Commission confirm every supplier entity is legitimate and sanctions-clean.

Every chase email and every report is reviewed by a human analyst before it reaches a supplier or your board.

Cyber Vigilance Final Thoughts

Supply chain risk is not going to shrink. Organisations are relying on more third party services than ever, and attackers know exactly how much leverage a single compromised supplier can provide. A yearly spreadsheet exercise cannot keep pace with a supply chain that changes daily.

What can help is visibility built on genuine relationships: knowing who your suppliers are, understanding what they depend on in turn, and being able to draw on the assessments and intelligence of peer organisations facing the same challenges. That shift, from static point in time checklists toa living, collaborative picture of the supply chain, is what frameworks like the CAF are pushing organisations toward, and it is the gap that platforms like Risk Ledger are trying to close.

The message here is ultimately a hopeful one. Cyber incidents are a case of when, not if. But an organisation that has genuinely mapped its dependencies, understood its concentration risks, and prepared its response can face a regulator, a board, or a journalist with confidence, rather than admitting it had no idea.

 

©2025 Cyber Vigilance

Powered by Disruptive

+44 (0) 1483 948090

info@cybervigilance.uk

Naggs Stable, Old Portsmouth Road, Guildford, Surrey, England, GU3 1LP