In August 2026 the National Cyber Security Centre published guidance for organisations managing third-party suppliers, with the central point that managing a supplier is an ongoing process rather than something completed at procurement.
The timing follows a period where supply chain compromise has been the pattern rather than the exception.
Why this is the shape of the risk now
In May 2026 a breach of the Canvas learning management system affected multiple New Zealand universities and tertiary institutions. Each institution had its own security arrangements; the entry point was a shared platform they all depended on.
That is the structural problem. An attacker who compromises one supplier reaches every customer of that supplier, which is a far better return than attacking each organisation individually.
For a business, it means your security posture is only as strong as the weakest supplier with access to your systems or data — and you may not know who all of them are.
Start with an inventory
Most organisations cannot list every third party with access to their systems or data. The list is longer than expected and typically includes:
- Cloud and SaaS providers, including ones bought by individual teams.
- IT support and managed service providers, who frequently hold administrative access.
- Payroll and accounting providers.
- Marketing platforms holding customer data.
- Logistics and fulfilment partners.
- Contractors and consultants with system access.
- Anyone with physical access to premises or equipment.
For each: what access do they have, what data can they reach, is it still necessary, and who owns the relationship internally.
What to ask suppliers
- Security posture — do they hold independent certification, and can they evidence it rather than assert it?
- Access — who at the supplier can reach your data, and how is that controlled?
- Location — where is your data stored and processed, which matters for Privacy Act obligations around comparable protections offshore?
- Sub-processors — who do they rely on, since their supply chain becomes yours?
- Breach notification — what will they tell you, how fast, and is it contractual?
- Exit — can you get your data out in a usable format, and what happens to their copy?
Ongoing rather than one-off
The NCSC’s framing matters because most organisations assess a supplier at onboarding and never again. Suppliers change — ownership, sub-processors, security practice, financial position.
A proportionate approach: reassess significant suppliers annually, require notification of material changes contractually, and review access whenever a relationship changes.
Contract terms that actually help
Beyond the standard commercial terms:
- Security obligations stated rather than implied, at a level proportionate to the data involved.
- Breach notification with a defined timeframe, because your own Privacy Act obligation runs from when you become aware.
- Audit or evidence rights, even if only the right to request current certification.
- Sub-processor notification, so their supply chain changes do not happen invisibly.
- Data return and deletion on exit, in a usable format.
You are also someone’s supplier
Expect the same questions from your customers. Security questionnaires are now routine in enterprise and public sector procurement, and a business that cannot answer loses contracts on that basis regardless of the quality of what it sells.
Having current answers ready — access controls, multi-factor authentication, patching practice, backup testing, incident response and notification commitments — turns a procurement obstacle into a differentiator.
The privacy overlay
Using a third-party provider is a disclosure of personal information and you remain accountable for it. Where information goes offshore, obligations apply around ensuring comparable protections.
Where a supplier breach exposes personal information you hold responsibility for, your notification obligation to the Privacy Commissioner and affected individuals applies — you cannot pass it to the supplier.
The NCSC and CERT NZ publish free guidance for New Zealand organisations, and the Office of the Privacy Commissioner publishes material on third-party providers and offshore disclosure.
Source: National Cyber Security Centre supplier security guidance, published 4 August 2026. General information only, not legal advice.








