As significant investment flows into UK automotive, resilient supply chains will be critical to turning that confidence into long-term growth. Marking Cyber Security Awareness Month, Jack Salsbury, Autotech Group’s Head of IT & Information Security, argues that in an increasingly connected industry, resilience is no longer simply about components, sourcing and logistics. Supply chain cyber security matters too: businesses also need to consider the digital resilience of the organisations around them.

When the automotive industry talks about supply chain resilience, the conversation has traditionally centred on physical components, sourcing, logistics and the ability to maintain production when disruption occurs.

With more than £1 billion of new investment announced across UK automotive in the space of just seven days recently, the resilience of the wider supply chains needed to support future growth is becoming increasingly important. Bentley, McLaren and Nissan have all announced significant UK investment spanning manufacturing, R&D and new vehicle production.

Those supply chain considerations remain critical. But resilience today extends beyond components, sourcing and logistics. OEMs, dealer groups, fleets and other automotive organisations now depend on a broad digital ecosystem of recruitment businesses, training providers, software platforms, managed service providers and other third parties.

As those relationships become more connected, automotive cyber security can no longer stop at the boundaries of an individual organisation. The level of maturity varies considerably. Larger organisations may already have established processes for assessing supplier risk, while smaller businesses that have not previously been exposed to these requirements may still be managing supplier relationships much as they did five or ten years ago.

“The mindset has to change,” says Jack. “Your supply chain is an extension of your business and, as such, should be subject to the same standards the organisation sets for itself.”

It is an issue receiving growing attention across automotive. The SMMT’s Supply Chain Resilience Programme identifies heightened cyber-security risks and a lack of tier-to-tier visibility among the challenges facing UK automotive suppliers.

Looking beyond your own cyber defences: third-party cyber risk

A business can invest heavily in protecting its own systems and still remain exposed through the organisations around it. Jack describes this wider network as the “shadow perimeter” – the suppliers, platforms and services sitting outside an organisation’s immediate security environment which may nevertheless have access to its data, systems or processes.

“You can have very strong internal controls, but if there is little visibility or governance around your suppliers, there is still exposure,” he explains.

“Employees might have the autonomy to sign up to a service without that supplier’s security posture ever being assessed. Suddenly that organisation is part of your supply chain and potentially accessing confidential data, but with no visibility of the risk or a clear route to mitigate it.”

This changes the question businesses need to ask.

Rather than simply “How secure are we?”, organisations increasingly need to understand who they depend upon, what those businesses can access and how effectively those suppliers manage their own cyber risk. The consequences of getting that wrong extend beyond IT. A cyber incident can disrupt operations, prevent customers accessing services, create significant financial losses and damage trust.

The 2025 cyber-attack on Marks & Spencer provided a high-profile example of third-party exposure. M&S subsequently confirmed that the attackers used social engineering to gain entry through a third party rather than by breaking through the retailer’s digital defences. For automotive organisations operating within complex and increasingly interconnected supply chains, understanding that wider exposure is becoming an important part of resilience planning.

Supplier risk management: why a proportionate approach works

Not every supplier presents the same risk. That does not mean subjecting every organisation within a supply chain to identical security requirements. The key, according to Jack, is proportionality.

He defines a secure supply chain as one where an organisation maintains visibility of its suppliers and has assurance that each implements security controls proportionate to the risk they present, which includes the data they process and the systems they can access.

A business delivering stationery or catering, for example, will naturally require a different level of scrutiny from a managed IT provider, CRM platform or strategic supplier regularly processing confidential or sensitive information.

“The level of assurance should be risk-based,” Jack explains. “For lower-risk suppliers, an organisation might encourage Cyber Essentials. But for critical or strategic suppliers, you would expect a much greater level of assurance. This could include independently verified standards such as ISO 27001 or Cyber Essentials Plus, or a security questionnaire that allows the organisation to assess the supplier’s controls in more detail.”

This risk-based approach to third-party risk management is increasingly reflected at national level. The Government’s Cyber Resilience Pledge, launched in 2026, calls on organisations to make cyber security a board-level responsibility and to take a risk-based approach to requiring Cyber Essentials across their supply chains. The principle is important: cyber resilience is increasingly a collective responsibility.

The suppliers businesses don’t see: island hopping and supply chain security

One potential weakness is that the organisations presenting cyber risk are not necessarily the largest or most obvious suppliers. Major strategic technology partners tend to attract scrutiny precisely because businesses understand their importance. Smaller suppliers and platforms can be less visible.

Yet size does not necessarily correspond with risk. Attackers often target smaller organisations as a route towards larger businesses – an approach sometimes referred to as “island hopping”. Rather than attempting to breach a heavily protected organisation directly, a less secure business within its wider ecosystem can provide another route in.

Jack believes this makes visibility fundamental: “Businesses often know a lot about their major suppliers, but could they confidently identify all of the smaller organisations within their supply chain, what information those businesses hold and what systems they can access? Probably not.”

For automotive organisations working with potentially hundreds of third parties, that is a significant challenge. It also reinforces why supplier governance cannot simply be a procurement exercise completed when a contract is signed. As services, technology and access change, the associated risk can change too.

Technology alone isn’t enough: people and leadership

There is another part of cyber resilience that can be overlooked: people. For Jack, the human element is arguably as important as the technology, although neither can work effectively without the other.

“You can have the most complex lock in the world, but if somebody leaves the door open, the attacker is inside.”

Staff awareness, training and organisational culture therefore sit alongside technical controls.

Leadership matters too. Board and senior management engagement determines whether sufficient resources are committed to cyber security, whether employees understand their responsibilities and whether cyber risk is treated as a business issue rather than something belonging solely to the IT department.

This becomes particularly important in supply chain security. Employees making decisions about new platforms, services and suppliers need to understand that bringing another organisation into the business ecosystem can also introduce another potential point of exposure. Clear procedures and the right culture are therefore essential, ensuring supplier risk is considered before new services are introduced rather than after a problem emerges.

From accreditation to resilience

Autotech Group’s own approach has evolved considerably, with the business achieving ISO 9001, ISO 27001 and Cyber Essentials Plus as part of its wider investment in quality, information security, governance and compliance.

But the significance of independently verified standards goes beyond having another accreditation to display. The process requires businesses to understand their processes, risks, responsibilities and controls – disciplines which become increasingly important when customers are placing their own data and operations in the hands of suppliers.

For some organisations, however, knowing where to start can be one of the biggest barriers.

“We shouldn’t lose sight of the fact that actually doing something about this can be difficult,” says Jack. “For some businesses, governance, risk and compliance are relatively new concepts. They may not know what approach to take or what level of assurance is appropriate.”

The answer is not necessarily to attempt everything at once. A logical starting point is understanding the supplier landscape: Who are your suppliers? What do they do? What data do they process? What systems can they access? And what would happen to your organisation if they were compromised or unavailable?

That visibility allows businesses to prioritise risk and determine the level of security assurance appropriate to each relationship.

A changing expectation for automotive suppliers

Jack expects the ability to demonstrate cyber resilience to become increasingly important when organisations select suppliers.

There is already precedent. Cyber Essentials requirements have been applied to certain UK government contracts for more than a decade, depending on the cyber risk associated with the work.

As automotive becomes more connected – across vehicles, workshops, data, training, recruitment, software and business operations – it is reasonable to expect greater scrutiny of the organisations sitting within those networks. That creates a broader definition of what makes a strong automotive supplier.

Cost, quality, capability and service will remain fundamental. But organisations may increasingly need to demonstrate that they can also be trusted with the systems, information and processes their customers depend upon.

The substantial investment currently flowing into UK automotive is a positive signal of confidence in the industry’s future. Protecting that future will require resilient manufacturing operations and physical supply chains – but also greater understanding of the digital ecosystem that now sits around them.

As Jack concludes: “Your supply chain is an extension of your business. It should be subject to the same standards you set for yourself.”

Jack Salsbury, Head of IT & Information Security at Autotech Group, will be speaking at DTX London this October on ‘The Shadow Perimeter: Managing the Reality of Third-Party Cyber Risk’, exploring the growing challenge of managing cyber risk across increasingly complex supplier and third-party ecosystems. See Jack at DTX London or view the full agenda for more information.

FAQ: supply chain cyber security

What is a shadow perimeter?

The shadow perimeter is the network of suppliers, platforms and services outside an organisation’s immediate security environment that may still have access to its data, systems or processes.

What is third-party cyber risk?

Third-party cyber risk is the exposure an organisation takes on when a supplier or service provider can access its data or systems, and that supplier’s own security controls are weak or unassessed.

Which standards can show a supplier is secure?

Cyber Essentials suits lower-risk suppliers. For critical or strategic suppliers, independently verified standards such as ISO 27001 or Cyber Essentials Plus, or a detailed security questionnaire, give stronger assurance.

Related Posts

Speak to Us