The Invoice Looked Fine. The Systems Weren't.
A lighting distributor in Rotterdam had a supplier they'd worked with for six years. The relationship was solid, the quality consistent, the prices fair. Then one invoice arrived with a changed bank account. The distributor wired $48,000 to it. The supplier never saw the money.
Nobody hacked the distributor. Attackers had been inside the supplier's email for weeks, reading order threads and waiting. When a real payment was due, they sent a near-perfect invoice from the supplier's own compromised address. The money was gone before anyone noticed.
The distributor did nothing wrong by normal procurement standards. Price, quality, lead time, certifications, all checked. The one thing nobody checked was whether the supplier's email could be trusted at all.
What Actually Flows Into Your Supplier's Systems
Think through a single order. You send the supplier product drawings, sometimes a customer's logo and specifications. You send purchase orders with quantities and prices. You exchange invoices, packing lists, and shipping details. If you use a shared portal or EDI link, your systems touch theirs directly.
That is not a one-way flow of harmless paperwork. It is your intellectual property, your pricing, your customer identities, and your money instructions, sitting on someone else's servers, protected by someone else's password policy.
Procurement has spent twenty years getting good at the physical and financial side of this. The digital side is still, for most teams, a checkbox that doesn't exist.
The Four Ways a Weak Supplier Hurts You
Supplier IT Risk, Mapped to Your Exposure
| Failure mode | What leaks | What you can check |
|---|---|---|
| Compromised email | Payment instructions, order details | Two-factor authentication on mail, payment-change confirmation by phone |
| Breached file server | Product drawings, customer data | Access controls, audit logs, third-party security report |
| Weak ERP or portal | Shared login, order history | Single sign-on, least-privilege access, SOC 2 report |
| Infected production software | Firmware or components you ship | Software bill of materials, patch and update policy |
The fourth row is the one that keeps procurement directors up at night. If a supplier's production software is compromised, the bad code can ride inside a component or firmware update straight into your product. That is no longer a payment problem. It is a product liability problem, and the chain of responsibility leads back to whoever didn't ask.
Why Procurement Skips This Check
The honest answer: because it wasn't in the playbook. Quality has AQL sampling. Compliance has certificates. Finance has payment terms. Cybersecurity has no owner in most buying processes, so it falls between the quality team, the IT team, and nobody.
There is also a fear factor. Buyers think they need to be security experts to ask useful questions. They don't. The same pattern that works for quality, ask for evidence, don't accept a verbal promise, applies here. You don't need to audit a supplier's firewall. You need to ask whether someone else already has, and look at the report.
A Lightweight Cyber Screen for Supplier Onboarding
You do not need a security team to close most of this gap. Add four lines to the same questionnaire you already send every supplier.
- Certification: do you hold ISO/IEC 27001 or a SOC 2 Type II report? If yes, ask for the certificate number and check it with the issuing body.
- Access: do you enforce two-factor authentication on the email and finance systems that touch customer orders?
- Changes: will you confirm any change to payment details by phone or video before we send funds?
- Response: how do you handle a suspected breach, and who is responsible? A named person beats a shrug.
Suppliers change behavior when buyers start asking. A factory that knows its biggest customers screen for security will turn on two-factor authentication the same way it bought a calibration certificate for its testing equipment, because the customer asked. The question is the cheapest control you can deploy, and it costs the supplier almost nothing to comply.
Common Questions from Buyers
Why does my supplier's cybersecurity have anything to do with me?
How do I check a supplier's cybersecurity without being an expert?
Is this just a problem for big companies?
What is the cheapest step I can take this week?
Compare verified suppliers and check certification records on Compare2Best, then add the cyber questions to your own onboarding form.