Supply chain · Third-party risk

Global Supply-Chain Cyber Risk Intelligence by Kai London

Most third-party programmes collect questionnaires and call it assurance. Regulators, insurers and boards increasingly want something harder: an accurate picture of what the organisation depends on, ranked by consequence, monitored over time and evidenced. This book sets out how to build that.

What the book covers

Discovery and tiering

Finding the suppliers that actually matter — including those procurement never recorded — and ranking by consequence rather than spend.

Software supply chain

SBOM practice, dependency and build-pipeline integrity, and vulnerability response across acquired components.

Fourth-party and concentration

Shared upstream providers, sub-processors and the systemic exposure they create.

Assurance that means something

Moving from questionnaires to evidence: certifications, testing, contractual rights and continuous monitoring.

Regulatory obligations

NIS2 Article 21 supply-chain duties, DORA third-party requirements and the Cyber Resilience Act's product expectations.

Incidents involving suppliers

Notification chains, joint response, exit rights and the record that must exist afterwards.

General guidance on risk and compliance practice, not legal advice, and independent of any regulator or standards body.

NIS2DORACRAISO 27036NIST CSF 2.0

Who it is for

CISOs and third-party risk teams, procurement and vendor management, internal audit, and financial-services and critical-infrastructure entities with statutory supply-chain duties.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.