You’ve done everything right. Firewalls in place, staff trained on phishing, backups tested, MFA rolled out across the business. And yet your data could still end up compromised – not because of anything you did, but because of a supplier you trust.
This is the uncomfortable reality of a supply chain attack. Rather than targeting your business directly, criminals go after a vendor, contractor or software provider that already has access to your systems or data – then use that trusted relationship to slip past your defences entirely.
A Small Door Into a Very Big Building
The clearest illustration of how devastating this can be is the SolarWinds attack, discovered in December 2020. Attackers managed to insert malicious code into a routine software update for Orion, a network management tool used by thousands of organisations, including US government agencies and some of the world’s largest companies. Because the update came from a trusted vendor and carried a legitimate digital signature, it was installed without a second thought – handing the attackers a backdoor into roughly 18,000 organisations at once.
It’s a striking example, but it’s easy to read it as a “big company problem” and move on. That would be a mistake. The mechanism behind it – trusting a third party’s access without questioning it – plays out at every scale of business, including yours.
What This Looks Like for an SME
Most small and medium-sized businesses don’t run enterprise software with a global customer base, but nearly all of them rely on a web of external suppliers who have some level of access to their systems or data. Your outsourced accountant logs into your finance software. A marketing agency has admin rights to your website. An IT vendor holds remote access credentials for your network. A payroll provider stores sensitive staff data. A CRM plugin, installed years ago and never reviewed, quietly has permission to read your customer records.
Each of these relationships is a potential entry point. If any one of those suppliers suffers a breach, gets their credentials phished, or simply has weaker security practices than you’d assume, the attacker doesn’t need to break into your business at all. They just need to walk in through a door you didn’t know was unlocked.
This is precisely why cybercriminals increasingly favour this route. Compromising one supplier with dozens or hundreds of clients is far more efficient than attacking each client individually – and smaller suppliers, who may lack the security resources of the businesses they serve, are often the easiest target of all.
Trust Isn’t a Security Control
None of this means you should stop working with external suppliers, or treat every contractor with suspicion. It does mean that “we’ve used them for years and never had a problem” isn’t a security strategy, however reassuring it feels.
A more resilient approach starts with visibility. Many businesses genuinely don’t have a clear list of which third parties have access to their systems, what level of access they hold, or whether that access is still needed. A supplier who was granted admin rights for a one-off project two years ago may still have that access today, long after the project ended and long after anyone thought to check.
From there, it’s about applying the same principle you’d apply to your own staff: access should match what’s actually needed, nothing more. A bookkeeper doesn’t need access to your entire network. A web developer doesn’t need visibility into your email system. Where possible, third-party access should be time-limited, monitored, and reviewed regularly rather than left in place indefinitely.
It’s also worth having a straightforward conversation with key suppliers about their own security practices – not as an accusation, but as a normal part of doing business together. Do they use MFA? Do they have a plan if their own systems are compromised? Would they tell you promptly if something went wrong on their end? A supplier who can’t answer these questions with confidence is a bigger risk to your business than you might realise.
The Bottom Line for SMEs
Supply chain attacks are effective precisely because they exploit relationships built on trust, and trust is exactly what makes a business run smoothly day to day. The goal isn’t to eliminate that trust, but to back it up with visibility and control, so that a problem at one of your suppliers doesn’t automatically become a problem for you.
Reviewing who has access to your systems, and why, is one of the simplest yet most overlooked security steps a business can take – and it costs nothing but a bit of time.
Not sure who currently has access to your systems, or whether that access still makes sense? Talk to our IT Security team about tightening up third-party access across your business.

