Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      New poll undermines the case against a Starlink deal

      New poll undermines the case against a Starlink deal

      13 August 2026
      Meet the CIO | Discovery's Derek Wilcocks on AI, guardrails and growth

      Meet the CIO | Derek Wilcocks on how AI personalised Vitality

      13 August 2026
      AI spreads at Standard Bank, but the tech bill barely budges

      AI spreads at Standard Bank, but the tech bill barely budges

      13 August 2026
      Inside Google's frantic push to close the AI gap

      Inside Google’s frantic push to close the AI gap

      13 August 2026
      Why the AI gold rush may be smaller than Eskom hopes - Teraco CT2

      Why the AI gold rush may be smaller than Eskom hopes

      12 August 2026
    • World
      Russia building its own Starlink - and faster than expected - Vadym Skibitskyi

      Russia building its own Starlink – and faster than expected

      11 August 2026
      Meta AI will now tell parents if their teen is in crisis

      Meta AI will now tell parents if their teen is in crisis

      17 July 2026
      IBM shares crash 25% as AI upends software spending - Arvind Krishna

      IBM shares crash 25% as AI upends software spending

      15 July 2026
      Jony Ive's first OpenAI device: an AI smart speaker - Jony Ive and Sam Altman

      Jony Ive’s first OpenAI device: an AI smart speaker

      15 July 2026
      Stripe, Advent in talks to buy PayPal for $53-billion

      Stripe, Advent in talks to buy PayPal for $53-billion

      15 July 2026
    • In-depth
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
      What Wi-Fi 8 will mean for wireless networks

      What Wi-Fi 8 will mean for wireless networks

      1 June 2026
    • TCS
      TCS+ | Specops' Darren James on continuous trust in an AI world

      TCS+ | Specops’ Darren James on continuous trust in an AI world

      7 August 2026
      TCS+ | How AI is turning hardware into a subscription service - Shane van der Merwe Merchant West

      TCS+ | How AI is turning hardware into a subscription service

      6 August 2026
      TCS+ | Why South African workers must become supervisors of digital labour - Accelera Digital Group Cliff de Wit

      TCS+ | Why South African workers must become supervisors of digital labour

      31 July 2026
      TCS | Rapid deployment rules can't work without municipalities: ACT - Nomvuyiso Batyi

      TCS | Icasa’s rules skip the real bottleneck: ACT

      30 July 2026
      TCS+ | iStore Business on why Apple makes sense for SMEs - Sudesh Pillay and Tamia Nontsikelelo

      TCS+ | iStore Business on why Apple makes sense for SMEs

      30 July 2026
    • Opinion
      The author, Jannie van Zyl

      Selling vapour is corporate suicide in slow motion

      16 July 2026
      Brazil's online gambling crackdown is a lesson for South Africa

      How Amazon outmanoeuvred Starlink in South Africa

      15 July 2026
      The Popia problem with agentic AI - Herman Haasbroek

      The Popia problem with agentic AI

      14 July 2026
      The author, Fanie van Rooyen

      South Africa can still catch the AI wave – here’s how

      7 July 2026
      The author, Fanie van Rooyen

      The AI utopia South Africa can’t afford

      1 July 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM Telecom
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Kaspersky on how to secure a supply chain you do not control

    Kaspersky on how to secure a supply chain you do not control

    Promoted | Kaspersky’s Sergey Soldatov on treating supplier security as part of your own, from onboarding to exit.
    By Kaspersky13 August 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    Kaspersky on how to secure a supply chain you do not control

    A business today functions as a complex ecosystem in which every participant influences the results, the reputation and, more importantly, the sustainability of the wider organisation.

    Every business sits inside a vast network of partners, suppliers and service providers whose actions ripple across industries.

    Resilience therefore depends not only on internal protection measures but on the strength and security of those external connections. As technology ecosystems grow more complex, protecting a supply chain means accepting that risk can emerge from any link – including the ones furthest from view.

    The approach assumes that a vulnerability anywhere in the chain can directly affect the organisation itself

    According to a recent global study by Kaspersky’s internal market research centre, supply chain attacks ranked as the top threat companies faced in 2025. Large enterprises were especially vulnerable, given their extensive networks of contractors and third-party vendors.

    Business leaders, chief information security officers, information security managers and procurement executives now need not only to grasp the risks these attacks pose but to deploy protective measures that mitigate them.

    The key to managing this chain of interactions is an ecosystem approach: a model in which an organisation treats its own security and that of its contractors and partners as a single, interconnected system.

    Frontline defence: pre-contract control

    Rather than treating supplier risk as secondary, the approach assumes that a vulnerability anywhere in the chain can directly affect the organisation itself. It requires unified standards, shared responsibilities and coordinated controls across every stakeholder, and it covers the full lifecycle of cooperation – before a partnership begins, during collaboration and after a contract ends.

    Start by building an internal system of security requirements for suppliers and contractors that governs how they are assessed, approved and managed. Establish policies covering supplier onboarding, data processing, access rights and the minimum baseline every third party must meet. Compliance with globally recognised standards such as ISO 27001 or SOC 2 can be made a condition of admission to tenders.

    Simple open-source intelligence techniques will reveal whether a coordinated vulnerability disclosure programme, a history of published vulnerabilities and a bug bounty programme are in place. How quickly a vendor resolves issues reveals how seriously it treats product security. Starting with internal standards and rigorous verification ensures that every supplier enters the ecosystem at a verified level of maturity.

    Further action items on verifying the security of partners are set out in a dedicated checklist prepared by Kaspersky experts.

    kaspersky

    Another indispensable practice is embedding IT security requirements into supplier contracts. According to Kaspersky’s report, only 37% of businesses do this. Setting expectations in writing gives companies predictable control over how third parties handle sensitive information, manage vulnerabilities and respond to incidents.

    Data privacy clauses oblige suppliers to protect corporate information and customer data, preventing unauthorised disclosure or misuse. Technical standards mandate encryption, two-factor authentication, secure coding practices and regular software updates, all of which reduce the likelihood of exploitation through outdated or vulnerable systems. Clear incident response rules specify how quickly a contractor must report a breach and what it must do to support investigation and containment.

    For critical environments, it is also essential to request a source code review. Code offers the deepest visibility into how a product actually behaves and where hidden risks may sit. Examining it directly – particularly the components handling authentication, data processing and communication – gives technical specialists assurance that the product is trustworthy at its core.

    Trust, but verify: collaborating with confidence

    Once those first checks are complete and a supplier’s conformity with the security criteria is confirmed, attention shifts to the risks that emerge once work begins. Suppliers may run outdated software, depend on vulnerable third-party tools of their own, or employ staff whose credentials have been compromised. Their systems may be targeted precisely because they offer an indirect path into your environment.

    Step two is therefore continuous, advanced infrastructure monitoring through extended detection and response (XDR) or endpoint detection and response (EDR). It detects unauthorised access and exploitation attempts early, narrowing the window available to attackers. It also allows organisations to correlate threat intelligence with real activity inside their environment, so that emerging vulnerabilities or relevant threat campaigns are identified before they escalate. Advanced monitoring turns supply chain security from a series of one-off checks into a dynamic defence layer that protects the ecosystem throughout the lifecycle of cooperation.

    To confirm that long-term partners maintain a consistently strong security posture, organisations should also run at least one comprehensive audit a year. These reviews should include compliance checks and technical assessments such as penetration testing and simulated attack scenarios originating from the supplier’s network.

    kaspersky

    Before any vendor update is deployed into production, it should be run in a controlled, isolated sandbox to check for abnormal behaviour and compatibility with the software environment. Pre-deployment testing prevents compromised or poorly implemented updates from reaching critical systems.

    Organisations must also take a systematic approach to cyber education, assessing the team’s cyber literacy regularly and running training to close the gaps. Resources should go not only to training internal staff but to improving the security proficiency of partners. Joint workshops build a common language around risk and reduce the probability of attacks that exploit the human factor on either side. Gamified security competitions such as capture-the-flag challenges let teams practise attack and defence techniques safely.

    Offboarding without blind spots

    Ending a supplier relationship is a high-risk moment in the supply chain lifecycle, which is why organisations need structured offboarding processes that eliminate access and protect sensitive data.

    First, revoke all digital access and dismantle system integrations so that former contractors cannot remain connected to internal infrastructure. That means disabling accounts, API keys, single sign-on links and VPN profiles, and removing any cloud resources they deployed.

    Ending a supplier relationship is a high-risk moment in the supply chain lifecycle…

    Second, secure and retrieve all data, verifying that the supplier has deleted corporate information, returned intellectual property and given up any future access to confidential or personal data. Formal destruction certificates and strict data minimisation practices help prevent unauthorised retention or misuse once the relationship ends. Together these measures close every remaining entry point and ensure a clean disengagement that leaves no lingering vulnerabilities.

    At a time when supply chain weaknesses regularly surface in global news, proactive preparation is a fundamental requirement rather than an optional extra. Organisations that engage thoroughly with suppliers at every stage, formalise contractual expectations and invest in the security of their partners do not merely embed resilience into their operations – they gain a competitive advantage.

    • The author, Sergey Soldatov, is head of the security operations centre at Kaspersky
    • Read more articles by Kaspersky on TechCentral
    • This promoted content was paid for by the party concerned
    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Kaspersky Sergey Soldatov
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleMeet the CIO | Derek Wilcocks on how AI personalised Vitality
    Next Article New poll undermines the case against a Starlink deal

    Related Posts

    Hackers are hiding malware behind AI agents that antivirus cannot see - Sergey Lozhkin

    Hackers are hiding malware behind AI agents that antivirus cannot see

    27 July 2026
    Finding focus: a strategic approach to cybersecurity for SMBs - Kaspersky

    Finding focus: a strategic approach to cybersecurity for SMBs

    6 July 2026
    Kaspersky's blueprint for industrial cyber resilience

    Kaspersky’s blueprint for industrial cyber resilience

    25 June 2026
    Add A Comment

    Comments are closed.

    Company News
    Kaspersky on how to secure a supply chain you do not control

    Kaspersky on how to secure a supply chain you do not control

    13 August 2026
    Build or buy software? AI is rewriting the answer - BBD Software

    Build or buy software? AI is rewriting the answer

    12 August 2026
    Max zoom meets max speed with the new 5G Huawei Pura 90s series

    Max Zoom meets Max Speed with the 5G Huawei Pura 90s series

    11 August 2026
    Opinion
    The author, Jannie van Zyl

    Selling vapour is corporate suicide in slow motion

    16 July 2026
    Brazil's online gambling crackdown is a lesson for South Africa

    How Amazon outmanoeuvred Starlink in South Africa

    15 July 2026
    The Popia problem with agentic AI - Herman Haasbroek

    The Popia problem with agentic AI

    14 July 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    New poll undermines the case against a Starlink deal

    New poll undermines the case against a Starlink deal

    13 August 2026
    Kaspersky on how to secure a supply chain you do not control

    Kaspersky on how to secure a supply chain you do not control

    13 August 2026
    Meet the CIO | Discovery's Derek Wilcocks on AI, guardrails and growth

    Meet the CIO | Derek Wilcocks on how AI personalised Vitality

    13 August 2026
    AI spreads at Standard Bank, but the tech bill barely budges

    AI spreads at Standard Bank, but the tech bill barely budges

    13 August 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}