Global Supply-Chain Cyber Risk Intelligence by Kai London
Most third-party programmes collect questionnaires and call it assurance. Regulators, insurers and boards increasingly want something harder: an accurate picture of what the organisation depends on, ranked by consequence, monitored over time and evidenced. This book sets out how to build that.
What the book covers
Discovery and tiering
Finding the suppliers that actually matter — including those procurement never recorded — and ranking by consequence rather than spend.
Software supply chain
SBOM practice, dependency and build-pipeline integrity, and vulnerability response across acquired components.
Fourth-party and concentration
Shared upstream providers, sub-processors and the systemic exposure they create.
Assurance that means something
Moving from questionnaires to evidence: certifications, testing, contractual rights and continuous monitoring.
Regulatory obligations
NIS2 Article 21 supply-chain duties, DORA third-party requirements and the Cyber Resilience Act's product expectations.
Incidents involving suppliers
Notification chains, joint response, exit rights and the record that must exist afterwards.
General guidance on risk and compliance practice, not legal advice, and independent of any regulator or standards body.
Who it is for
CISOs and third-party risk teams, procurement and vendor management, internal audit, and financial-services and critical-infrastructure entities with statutory supply-chain duties.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.