Cyber Security
The security questions your customers will start asking
For years, supplier security assessments were something only large enterprises dealt with. That has changed, and it has changed quickly.
Large manufacturers have worked out that their weakest security exposure is often not their own network — it is a supplier's. So the questionnaires are moving down the chain.
What is actually being asked
The assessments vary in length, but the substance is consistent.
Who has administrative access to your systems, and how is that access granted and revoked? Do you enforce multi-factor authentication? How quickly are security patches applied? Have you tested your ability to recover from a ransomware incident? Do you have a documented incident response process?
None of these are exotic. They are the same questions I would ask in any security review.
Why firms fail them
In my experience the failure is rarely technical. It is documentary.
The business is doing several of the right things, but nothing is written down, nobody owns the process, and there is no evidence to present. An assessment that asks for proof cannot be satisfied with good intentions.
The practical position
If you supply a large OEM, assume the questionnaire is coming — if it has not already.
The worst time to discover your position is when a customer sets a deadline. Working through the same questions on your own schedule costs a fraction of doing it under commercial pressure, and you keep control of the timeline.