An organization can have strong firewalls.
Mature identity controls.
Well-trained employees.
Advanced security monitoring.
And still experience a cybersecurity incident through a third party.
That is the reality of the modern digital supply chain.
Today's organizations depend on an expanding ecosystem of:
Cybersecurity is no longer limited to the infrastructure an organization owns.
It increasingly depends on the security of organizations it connects with.
This is one of the reasons CyFun 2025 expanded its focus on supply-chain security. The updated framework also aligns with NIST CSF 2.0 and broader European cybersecurity expectations.
For compliance and cybersecurity teams, this creates a major challenge:
How do you continuously manage cybersecurity risk when part of your technology environment belongs to someone else?
The Third-Party Security Illusion
Many organizations believe they manage vendor risk because they have a vendor questionnaire.
The process often looks like this:
The problem is that cybersecurity risk does not remain unchanged for 12 months.
Between assessments, a vendor may:
The annual questionnaire can therefore create a false sense of assurance.
A completed questionnaire proves what the organization knew at one moment. It does not automatically prove ongoing security.
CyFun 2025 specifically expands its focus on supply-chain security.
This follows a broader international trend.
NIST CSF 2.0 also increased emphasis on cybersecurity supply-chain risk management, reflecting the growing importance of third-party and ecosystem risks.
The reason is simple.
Organizations are becoming more interconnected.
A modern business may rely on dozens or hundreds of external technology relationships.
The cybersecurity perimeter has expanded beyond the traditional enterprise boundary.
The New Cybersecurity Perimeter Is an Ecosystem
The old model of cybersecurity focused on protecting:
Our network.
The modern model needs to consider:
Our ecosystem.
That ecosystem may include:
Cloud platforms, SaaS tools and infrastructure providers.
Organizations processing or storing sensitive information.
Third parties with privileged access to systems.
External libraries, APIs and development tools.
Models and services integrated into business processes.
Every connection can introduce risk.
The Four Supply-Chain Questions Organizations Need to Answer
A modern CyFun program should help organizations answer four ongoing questions.
Organizations need visibility into:
2. What Do They Have Access To?
Not every vendor relationship carries the same risk.
Access to a public website is different from access to:
Risk management needs context.
3. What Security Obligations Apply?
Organizations should define appropriate requirements based on risk.
These may include:
4. What Has Changed?
This is where continuous assurance becomes important.
Organizations should avoid treating third-party risk as static.
Risk can change when:
The Growing Problem of AI in the Supply Chain
One of the newest supply-chain challenges is AI.
A software vendor may suddenly introduce:
These changes may affect:
The World Economic Forum's 2026 cybersecurity analysis highlights how AI adoption is creating assurance challenges and pushing organizations toward more continuous approaches to validation and security assessment.
For third-party risk teams, this means vendor due diligence is becoming more complex.
It is no longer enough to ask:
"Is this vendor secure?"
Organizations may need to ask:
"How is this vendor changing?"
Moving From Vendor Assessments to Vendor Assurance
There is an important difference.
A periodic review of a vendor's security posture.
An ongoing approach to maintaining confidence in a vendor relationship.
The second approach requires more than questionnaires.
It requires:
A Practical CyFun Supply-Chain Operating Model
Centralize information about vendors and technology partners.
Track:
Step 2: Classify Risk
Not every supplier requires the same level of oversight.
Risk classification can consider:
Step 3: Map Relevant Controls
Map cybersecurity requirements to vendor relationships.
This reduces ad hoc assessments and creates consistency.
Step 4: Define Evidence Expectations
Determine what evidence is required from high-risk relationships.
Step 5: Track Changes
Maintain visibility into changes that could affect risk.
Step 6: Manage Findings
Vendor findings should follow structured remediation workflows.
A risk identified during assessment should not disappear into an email thread.
How Quantarra Helps Manage CyFun Supply-Chain Risk
Quantarra helps organizations centralize compliance and risk operations across complex environments.
For supply-chain cybersecurity, organizations can use a connected operating model to manage:
Cross-framework mapping can also help organizations avoid recreating vendor requirements for every cybersecurity or regulatory framework.
The objective is to create one clearer view of cyber risk across the extended enterprise.
Conclusion
Supply-chain cybersecurity is becoming one of the defining challenges of modern compliance.
The question is no longer whether your organization has strong cybersecurity controls internally.
It is whether you can maintain confidence across the broader ecosystem your organization depends on.
CyFun 2025's increased focus on supply-chain security reflects this changing reality.
The organizations that continue treating vendor security as an annual questionnaire exercise may struggle to keep pace.
The future is moving toward:
Connected risk. Continuous visibility. Ongoing assurance.