Cooperation with service providers

Cloud computing and cybersecurity
Cloud computing gives businesses and public authorities flexible access to IT resources – but it also comes with security risks. The NCSC explains what needs to be considered in relation to data protection, maintaining control over data and systems, and contractual arrangements.

Cybersecurity in the supply chain
To mitigate cybersecurity risks along the supply chain, organisations need to understand and assess their risks, define their requirements and specifications for their suppliers, subcontractors and providers, and verify compliance. To this end, companies, public authorities and organisations should take a strategic approach to cybersecurity risks in their IT/OT supply chain. This is known as Cyber Supply Chain Risk Management (C-SCRM).

Working with IT service providers
While larger companies often have their own IT departments, many smaller companies outsource these tasks. It is important to ensure that responsibilities for IT security are clearly defined between you and your IT service provider, particularly when it comes to technical and organisational measures. Your contract should also clearly set out who is liable if agreed security measures are not implemented and this results in damage.