The five actions every CISO should run this quarter
Supply-chain risk actions
- Material service provider register. CPS 230-style register identifying suppliers without whom a critical operation cannot continue.
- Tiering and right-sized due diligence. Tier 1 enterprise, Tier 2 important, Tier 3 commodity — diligence and contract terms scale with tier.
- Fourth-party visibility. Ask your top suppliers about their critical sub-processors. Concentration in one cloud, one CDN, one identity provider is a board-level risk.
- Continuous monitoring. Security ratings, external attack-surface monitoring and breach-feed alerts beat annual questionnaires.
- Joint incident playbook. Pre-agreed comms, evidence-sharing and decision authorities with Tier 1 suppliers — rehearsed annually.
Australian regulatory anchors
- APRA CPS 230 — operational risk management including material service providers and concentration risk (in force July 2025).
- APRA CPS 234 — information security including with third parties.
- SOCI Act — supply-chain hazards must be addressed in CIRMP for responsible entities.
- Cyber Security Act 2024 — mandatory ransomware reporting and ransom-payment reporting affect both you and your suppliers.
- Privacy Act — APP 11 obligations extend to personal information handled by third parties.
FOR THIRD-PARTY RISK LEADS
Generate your supply-chain risk decision in one mission.
FORTE/CYBERx produces a defensible vendor concentration and uplift plan anchored to CPS 230, SOCI and ISO 27001 — ready for the audit committee.
Try a TPRM missionThe board conversation
The two questions every audit committee now asks: where is our concentration, and what happens if our largest critical supplier is down for seven days. Neither answer is in the supplier’s SOC 2 report. Both need a structured analysis you can defend.
FAQ
What is supply-chain cyber risk?
The risk that a security incident at a third or fourth party causes loss, downtime, regulator exposure or reputational harm to your organisation. It now accounts for an increasing share of material Australian breaches.
How is this different from TPRM?
TPRM is the programme; supply-chain cyber risk is the threat. TPRM is how you manage the threat — assessments, tiering, contracts, monitoring, response — but the underlying risk extends beyond direct suppliers to nth-party concentrations.
What does APRA CPS 230 require here?
In force from 1 July 2025, CPS 230 mandates identification and management of material service providers including a register, written agreements with specified terms, BCP testing and incident notification timeframes. Concentration risk gets explicit attention.
Where does SBOM fit?
A Software Bill of Materials inventories the components in the software you buy or build, so that a CVE like Log4Shell or a supplier compromise like 3CX can be triaged in hours instead of weeks. Increasingly required in federal and critical-infrastructure procurement.