Home · Blog
GRC

Supplier risk in an SME: which suppliers can stop your business

9 September 2026 · 7 min read · ODCUS
Hand-drawn illustration: a business hangs on a few threads to its suppliers, a person examines the load-bearing connections with a magnifying glass, next to an ignored stack of questionnaires

The cyberattack that stops your company does not have to happen on your premises. When your IT provider gets encrypted, your systems stand still, even if your own firewall did everything right. That is the core of supplier risk: with every contract, you buy the provider's security posture along with the service. Every SME has dependencies like these. The difference lies in whether you know which of them can stop your business.

TLDR

You do not manage supplier risk with questionnaires sent to all 200 creditors, but with an honest list of the few suppliers that can stop your business: IT providers with admin rights, hosts of your core systems, software in critical processes. For these you need transparency, contractual reporting duties and a plan B. The rest get standard clauses and your peace of mind.

What is supplier risk and why does it hit SMEs particularly hard?

Supplier risk is the risk that a security incident at a supplier hits your own business: through remote access to your systems, through compromised software or through the outage of a service your operations depend on. It hits SMEs particularly hard because they outsource more than large companies and at the same time have less negotiating power to enforce security requirements.

A company with 50 to 500 employees rarely runs everything itself. IT runs partly or fully at a service provider, the ERP at a hoster, payroll at a fiduciary, and the production machines hang on the manufacturer's remote maintenance. Each of these relationships makes commercial sense. Taken together, they form an attack surface that is visible in none of your own systems.

Responsibility still stays with you. Your customers do not care whether the failure happened at your site or at your hoster's; their contract is with you. You can outsource work, not responsibility.

The Swiss Federal Office for Cybersecurity BACS has dedicated its own guidance to the topic: Cybersicherheit in der Lieferkette describes a cycle of understanding dependencies, categorising suppliers, setting requirements and verifying them. The approach is remarkably calm: no certificate mandate for everyone, but first the question of where you actually depend on someone.

Why questionnaires for everyone protect no one

The standard reflex in supplier management is the questionnaire. Forty questions to every supplier, once a year, answers filed, box ticked. It feels like control and produces one thing above all: paper. Large companies can afford this ritual, they have teams for it. An SME that copies it gets the form without the effect.

Let's be honest: what happens with the answers? In most companies, nobody who could draw consequences ever reads them. The supplier who would tick No next to "password policy in place?" does not exist. And the supplier who can endanger you does not stand out in a questionnaire, because the danger sits not in his answers but in your dependency on him.

The question that appears on no form: what do you do on Monday if this supplier got encrypted on Friday? If the answer is "no idea", no completed questionnaire in the world will help you.

Supplier risk is also a right-sizing problem. More questionnaires do not make you safer, sharper ones do: a few critical suppliers you understand in detail, instead of complete files on everyone. More protection, less effort.

Which suppliers do you have to check?

Three groups: suppliers with privileged access to your systems, operators of your core systems, and manufacturers of software or hardware in critical processes. In its guidance, BACS recommends exactly this categorisation by risk rather than by purchasing volume. In our experience, out of a few hundred creditors, ten to twenty suppliers remain that meet one of these criteria.

What that looks like in practice: a Swiss industrial company with around 120 employees we worked with carried over 300 creditors. Procurement checked the 30 largest by purchasing volume, among them the coffee supplier and the building cleaner. Not on the list: the external IT provider with domain admin rights, the ERP hoster and the machine builder with permanent remote maintenance access. The three firms that could have stopped operations in an afternoon had never been looked at, because they were inconspicuous in procurement. The new list ended up with twelve names. Three of them led to conversations and adjusted contracts, the rest were covered with evidence and standard clauses. The effort: a few working days spread over a quarter, with no new tool and no new position.

The list therefore comes not from procurement but from a conversation with operations: which systems must not stand still, who has access, which software sits in which process. A usable supplier register ends up with three tiers. Critical suppliers get a deeper review, clear contracts and a plan B. Elevated ones get evidence and reporting duties. The rest get standard clauses in procurement. This sorting is manageable effort and holds for years.

Illustration of a three-tier supplier register: a few critical suppliers at the top are examined in detail, the middle tier shows evidence and certificates, the wide base holds many suppliers with standard clauses
Three tiers in the supplier register: critical, elevated, standard.

What can an SME demand from suppliers at all?

Less than you would like, and more than you think. Microsoft will not answer your questionnaire, your local IT provider will, and the actual work lies in between: deciding per supplier which evidence is realistic and which contract point counts.

With the big ones, it runs on existing evidence. Hyperscalers and established software vendors publish certificates and audit reports, above all ISO 27001 and SOC 2. Your job there: read the answers that already exist, including the scope. Which proof says what, we have written up in our comparison of ISO 27001 and SOC 2.

With the small ones, and these are often the most critical, dialogue works better than audit theatre. Your IT provider with 15 people has no SOC 2 report and will not have one any time soon. A conversation about how he protects his own admin access says more than 40 form fields. BACS argues in the same direction: enable suppliers rather than punish them, because a secure supplier is worth more to you than a caught one.

In the contract, few points count: that the supplier reports security incidents to you within a defined deadline, that he discloses subcontractors, that your data comes back at the end of the contract and that you get information when it matters. These clauses cost almost nothing in negotiation as long as the contract is not yet signed. Afterwards they cost a lot.

Concentration risk: when there is no plan B

The hardest form of supplier risk is not the insecure supplier but the irreplaceable one. If your ERP hoster, your industry software or your IT provider fails tomorrow or doubles its prices and you have no realistic alternative, your operations stand just as still as after an attack. Vendor lock-in is supplier risk in its purest form, only without an attacker.

A plan B in an SME does not mean running every system twice. That would be the expensive answer to the wrong question. It means knowing the exit costs before they fall due. Is your data available in a format another provider can read? Does the contract say you get it back in full on termination, and within what deadline? Is there a second provider who could in principle deliver the most critical service, even if the switch would take months? Whoever can answer these questions negotiates differently. Not because he threatens, but because both sides know that he could.

A board that asks for the biggest risks often gets a list with malware and phishing. In many SMEs the more honest answer would be: the one service provider without whom nothing runs any more.

At the latest here, supplier risk turns from an IT task into a management task. The decision to enter a dependency deliberately, because the provider is plainly the best, can be right. It just should not happen by accident, because nobody asked the question.

How the ISG, NIS2 and DORA put the topic on your desk

The regulation does not target you, but it arrives at your door. The Swiss Information Security Act (ISG) obliges operators of critical infrastructures: since April 2025 a reporting duty for cyberattacks within 24 hours applies, and by the end of 2026 organisations subject to the act need a working ISMS. Those affected pass these requirements on to their suppliers by contract. NIS2 does the same from the EU side, and we have described separately how the rule arrives in Switzerland through customer contracts. DORA does it for suppliers of EU financial institutions.

Which also means: if your customers are regulated, you are their supplier risk. The same sort of questionnaire you send to your suppliers lands on your desk from the other side. Whoever has their own supplier management under control answers these questions more credibly. A compliance exercise turns into a sales argument.

Frequently asked questions

Is a supplier's ISO 27001 certificate enough as evidence?

It is a good filter, not a guarantee. The certificate proves a working management system within the defined scope. Whether the service you are buying sits inside that scope is written in the scope statement, and almost nobody reads it. Certificate plus matching scope plus a contractual reporting duty is a solid basis.

How often should you reassess suppliers?

Event-driven beats calendar-driven. You look at critical suppliers again when something changes: a new subcontractor, new access, an acquisition, a publicly known incident. An annual review of the critical list is enough of a rhythm, as long as these triggers are defined. A rigid yearly ritual for all 300 creditors keeps you busy without protecting you.

Does an SME need a dedicated tool for supplier risk?

In most cases no. Ten to twenty critical suppliers fit into a table in your existing risk register. Tools pay off when hundreds of suppliers with continuously updated ratings need managing, which is rare below corporate scale. First the process, then the question of tooling.

Supplier risk remains part of ongoing security leadership: the list lives, access and contracts change. That is why, for us, the topic belongs in the ongoing CISO retainer rather than in a yearly project. Whether that adds up for your company, one conversation settles faster than yet another questionnaire.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call