Wood for Trees
Contact us
Salocin Group Leaders in data and AI-enabled connected customer experiences
Edit Engineers of connected customer experiences
Join the Dots Independent, data-led media thinking for sustainable growth
Wood for Trees Optimisers of future fundraising performance
  • Home
  • Our services
    • AI consulting services and AI enablement
    • Cloud solutions
    • Data science
    • Microsoft Dynamics 365 CRM consultancy
    • Modern Data Platform
    • Privacy and AI compliance
  • Our solutions
    • Organised for Intelligence
  • Our partners
    • Apteco
    • Creatio
    • Microsoft
    • Salesforce
  • Our insights
    • Blog
    • Case studies
    • Webinars
    • Whitepapers
    • Authors
  • Learn
    • AI in marketing
    • Data
  • About Salocin Group
    • Careers
  • Contact Salocin Group
  • Home
  • Who we are
    • B Corp
    • Careers
  • Our work
  • What we do
    • Intelligent data
    • Marketing technology
    • Transformational CRM
    • Our technology partners
    • Privacy review
  • Our insights
    • Blog
    • Case studies
    • Whitepapers
  • Contact Edit
  • Home
  • Broadcast media
  • Digital media
  • Print
    • Direct mail
  • Data
    • Our work with Herdify
    • EPiC
  • Media agency
  • Our insights
    • Blog
    • Case studies
    • Webinars
    • Whitepapers
  • About Join the Dots
    • Careers
  • Contact Join the Dots
  • Home
  • Services
    • Actionable insight
    • Data discovery
    • Data engineering
    • Data hygiene
    • Privacy review
  • Products
    • InsightHub
    • Apteco
    • Microsoft
    • Data management
    • Consent and preference management
  • Our insights
    • Blog
    • Case studies
    • Reports
    • Webinars
    • Whitepapers
  • About Wood for Trees
    • Operating principles
    • Careers
  • Contact Wood for Trees
Blog

The weakest link: Why your suppliers are your biggest security risk

By Wood for Trees | 11 Aug 2026

We sat down with Ben Shariff, IT Manager at Salocin Group, to talk about the one security risk that keeps coming up whenever data protection gets discussed at board level: what happens when it isn’t your systems that fail, but a supplier’s. 

Ben’s spent years working in ISO 27001 environments and supplier due diligence and is now building on Salocin Group’s day-to-day operations, which meant he had a lot more to say than the usual “vet your vendors” line.

You’ve said supply chain isn’t just a risk, it’s the main one. Why?

“It doesn’t matter what we do at home,” Ben says. “If our data goes somewhere, with someone, and they have a breach, our reputation is done. With supply chain there’s so much out of our control. At home we have all the toggles, we can make this place Fort Knox, and so can everyone else. But if we just pick up a supplier and take their word for it, and we haven’t done our due diligence, someone could plug in a USB device and take all their data.”

If our data goes somewhere, with someone, and they have a breach, our reputation is done.

The data agrees with him. Third parties were involved in 55% of breaches at small and medium-sized organisations in the  Verizon Data Breach Investigations Report 2026, the bracket most charities sit in. Across all breaches the figure is 48%, up 60% in a single year. For a lot of organisations, that means the single biggest category of risk now sits outside their own perimeter.

Ben pushes it further: if you’re producing a CRM platform for a client, you’d expect that client to do their due diligence and ensure you’re not letting anyone plug in a USB and download their data. “We have that same thinking when we’re bringing on a supplier into our own environment.”

ISO 27001 and SOC 2 both get treated as proof a supplier “does security.” Are they the same thing?

Not remotely, according to Ben, who’s been through both. “SOC 2 Type 1 is a point in time. You read it and it’s telling you this control was in place on this date, for this population. Type 2 is different, they watch it operate over six or twelve months. ISO goes wider. They’ll interview the CISO right through to your basic admin person, asking the same questions, making sure the structure runs right through the business. So if something goes wrong, you press the red button, you notify the right people, and ISO makes sure that process flows through the whole organisation.” 

You mentioned AI has changed how you assess new suppliers. How?

This is where the conversation got specific. “Anything that comes in, anyone who wants to use a piece of software, it goes through a flow that does a load of market research. It gets compared by three or four AI models. We do loads of deep research on it, and it pulls out a five or six page document with recommendations: what controls can we get in place, what package should we have with that supplier.”

The result, Ben says, is that a job which used to need a full-time hire now takes a fraction of the time. “That’s stopped me hiring someone to do that as a full-time job. It was done in fifteen minutes. It allows one or two people to review multiple supply chain risks in a very short space of time, and it’s querying way more data than I could. I can’t look at a thousand websites and give you an analysis of all of them in fifteen minutes.”

One real example came up while we were talking: a request to use a well-known video editing tool. “The document said recommendation decline, but it gave us a load of solutions. There’s a litigation case going on with privacy in there, that could lead us to GDPR issues, and with data stored in the US it brings a transfer problem.” Not just a no, then. A no with the homework already done, and a shortlist of alternatives attached.

Ben’s careful to flag that this only works if the AI doing the checking is itself governed properly, which is what ISO 42001, the AI-specific management standard, is for. “It makes sure you have an AI management system in place, that you’ve assessed the impact of the thing before you deploy it, and that you’ve got governance over the data going into it. What it won’t tell you is whether the vendor trains on your data. That’s a contract question, and you still have to ask it.”

Where does supplier risk break down in most organisations?

People treat suppliers differently depending on how they came in, and that’s the problem.

Not where people expect. “People treat suppliers differently depending on how they came in, and that’s the problem, ” Ben says. “You should treat every supplier initially as if they’re holding all your PII, regardless of what they do. You pick up a supplier that cross-sells you stuff, you do your due diligence, you’re not really using them for much. But eventually they become a main supplier, they’re already in your system, and you don’t go back and do due diligence because you already use them.” 

“Suddenly they’re handling more of your data, and then there’s a breach, and they have a lot more access than you ever expected them to have. It’s just this natural progression: we’ve started using this tool, then we use that tool, then we’ve given them more and more data, and it slowly builds. The answer is deciding in advance what changes with a supplier trigger a fresh assessment, and actually running one when they happen.”

How often should suppliers be reviewed?

“We do a yearly review at the moment. That’s what our ISO risk assessment landed on. But the point is we actually do review them. A lot of people don’t.” The annual cycle isn’t where most of the work happens, though. “The real gate is at adoption. Anything new goes through the questionnaire before it’s approved, and it goes on the register. After that it’s the triggers. If a supplier has an incident, if they get acquired, if we start pushing significantly more data at them, that’s a fresh assessment. Not a diary entry twelve months out.”

Continuous, real-time monitoring is where we would love to be, Ben says, but he’s realistic about who can afford it. “It’s really difficult. You could turn around and say to a small charity, you should be continually reviewing and assessing. But that’s a full-time job, that’s another wage. It’s a really fine balance: what can we afford to do, but also how do we keep ourselves safe and what does the risk assessment say? That comes down to a board-level decision on how much you’re going to invest in security.”

He credits a specific structural setup for making that conversation easier at Salocin Group. “We’re fortunate that we have someone who’s CFO and CISO at the same time, so they have eyes on us from a security perspective, but also deal with the finances of the business. That’s really useful, because a lot of the time with this stuff you’re throwing a budget number into the dark, and if security isn’t front of mind for the board, it’s very easy for them to say, no, we don’t need that.”

Any final principle that organisations should apply, regardless of size?

Least privilege, applied consistently rather than as a one-off exercise. “It doesn’t matter who you have, you always give them as little privilege as possible, and that reviewed. Say you have a contractor for six months; that’s as far as their access should go. Even if you’re expanding the contract, it should still be reviewed at that point. Is this access enough? Was it too much? Can we take some off you and you still do your job?” 

It’s a small habit, applied at every renewal, that stops the slow creep Ben described earlier from happening in the first place.

At Wood for Trees, we understand charities and the not-for-profit sector

So, while we pride ourselves on high-quality data and insight skills, we feel that the real value of these skills is supercharged by the knowledge and experience our team have in working with charity data.

We understand the challenges fundraisers face and know how to use data to give them the answers they need. This all starts with a good grounding and full understanding of your data and supporter landscape.

Find out more

Share this

  • Email
  • WhatsApp
  • LinkedIn
  • Facebook
  • X (Twitter)

More insights

  • Blog
  • Case studies
  • Reports
  • Webinars
  • Whitepapers

More insights

Supporting charities to create connections that last 
Blog

Supporting charities to create connections that last 

By Wood for Trees | 5 Sep 2025
What the 2025 fundraising reports really tell us about the sector 
Blog

What the 2025 fundraising reports really tell us about the sector 

By Wood for Trees | 11 Jul 2025
20:20 Insight: Soft opt-in – what charities need to know
Blog

20:20 Insight: Soft opt-in – what charities need to know

By J Cromack | 10 Jul 2025
More insights
  • Privacy policy
  • Cookie policy
  • Ts&Cs
  • Report a concern

© 2026 Wood for Trees, part of Salocin Group Ltd. All rights reserved. Company no.: 0362​4881. VAT no.: 4208​34911.

Salocin Group Certified B Corporation | Cyber Essentials Certified | British Assessment Bureau, ISO 27001 Information Security Management
Salocin Group
Your cookie preferences

We use cookies to ensure this website functions properly, to analyse website traffic and for marketing purposes.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}