
We sat down with Ben Shariff, IT Manager at Salocin Group, to talk about the one security risk that keeps coming up whenever data protection gets discussed at board level: what happens when it isn’t your systems that fail, but a supplier’s.
Ben’s spent years working in ISO 27001 environments and supplier due diligence and is now building on Salocin Group’s day-to-day operations, which meant he had a lot more to say than the usual “vet your vendors” line.
You’ve said supply chain isn’t just a risk, it’s the main one. Why?
“It doesn’t matter what we do at home,” Ben says. “If our data goes somewhere, with someone, and they have a breach, our reputation is done. With supply chain there’s so much out of our control. At home we have all the toggles, we can make this place Fort Knox, and so can everyone else. But if we just pick up a supplier and take their word for it, and we haven’t done our due diligence, someone could plug in a USB device and take all their data.”
If our data goes somewhere, with someone, and they have a breach, our reputation is done.
The data agrees with him. Third parties were involved in 55% of breaches at small and medium-sized organisations in the Verizon Data Breach Investigations Report 2026, the bracket most charities sit in. Across all breaches the figure is 48%, up 60% in a single year. For a lot of organisations, that means the single biggest category of risk now sits outside their own perimeter.
Ben pushes it further: if you’re producing a CRM platform for a client, you’d expect that client to do their due diligence and ensure you’re not letting anyone plug in a USB and download their data. “We have that same thinking when we’re bringing on a supplier into our own environment.”
ISO 27001 and SOC 2 both get treated as proof a supplier “does security.” Are they the same thing?
Not remotely, according to Ben, who’s been through both. “SOC 2 Type 1 is a point in time. You read it and it’s telling you this control was in place on this date, for this population. Type 2 is different, they watch it operate over six or twelve months. ISO goes wider. They’ll interview the CISO right through to your basic admin person, asking the same questions, making sure the structure runs right through the business. So if something goes wrong, you press the red button, you notify the right people, and ISO makes sure that process flows through the whole organisation.”
You mentioned AI has changed how you assess new suppliers. How?
This is where the conversation got specific. “Anything that comes in, anyone who wants to use a piece of software, it goes through a flow that does a load of market research. It gets compared by three or four AI models. We do loads of deep research on it, and it pulls out a five or six page document with recommendations: what controls can we get in place, what package should we have with that supplier.”
The result, Ben says, is that a job which used to need a full-time hire now takes a fraction of the time. “That’s stopped me hiring someone to do that as a full-time job. It was done in fifteen minutes. It allows one or two people to review multiple supply chain risks in a very short space of time, and it’s querying way more data than I could. I can’t look at a thousand websites and give you an analysis of all of them in fifteen minutes.”

One real example came up while we were talking: a request to use a well-known video editing tool. “The document said recommendation decline, but it gave us a load of solutions. There’s a litigation case going on with privacy in there, that could lead us to GDPR issues, and with data stored in the US it brings a transfer problem.” Not just a no, then. A no with the homework already done, and a shortlist of alternatives attached.
Ben’s careful to flag that this only works if the AI doing the checking is itself governed properly, which is what ISO 42001, the AI-specific management standard, is for. “It makes sure you have an AI management system in place, that you’ve assessed the impact of the thing before you deploy it, and that you’ve got governance over the data going into it. What it won’t tell you is whether the vendor trains on your data. That’s a contract question, and you still have to ask it.”
Where does supplier risk break down in most organisations?
People treat suppliers differently depending on how they came in, and that’s the problem.
Not where people expect. “People treat suppliers differently depending on how they came in, and that’s the problem, ” Ben says. “You should treat every supplier initially as if they’re holding all your PII, regardless of what they do. You pick up a supplier that cross-sells you stuff, you do your due diligence, you’re not really using them for much. But eventually they become a main supplier, they’re already in your system, and you don’t go back and do due diligence because you already use them.”

“Suddenly they’re handling more of your data, and then there’s a breach, and they have a lot more access than you ever expected them to have. It’s just this natural progression: we’ve started using this tool, then we use that tool, then we’ve given them more and more data, and it slowly builds. The answer is deciding in advance what changes with a supplier trigger a fresh assessment, and actually running one when they happen.”
How often should suppliers be reviewed?
“We do a yearly review at the moment. That’s what our ISO risk assessment landed on. But the point is we actually do review them. A lot of people don’t.” The annual cycle isn’t where most of the work happens, though. “The real gate is at adoption. Anything new goes through the questionnaire before it’s approved, and it goes on the register. After that it’s the triggers. If a supplier has an incident, if they get acquired, if we start pushing significantly more data at them, that’s a fresh assessment. Not a diary entry twelve months out.”
Continuous, real-time monitoring is where we would love to be, Ben says, but he’s realistic about who can afford it. “It’s really difficult. You could turn around and say to a small charity, you should be continually reviewing and assessing. But that’s a full-time job, that’s another wage. It’s a really fine balance: what can we afford to do, but also how do we keep ourselves safe and what does the risk assessment say? That comes down to a board-level decision on how much you’re going to invest in security.”
He credits a specific structural setup for making that conversation easier at Salocin Group. “We’re fortunate that we have someone who’s CFO and CISO at the same time, so they have eyes on us from a security perspective, but also deal with the finances of the business. That’s really useful, because a lot of the time with this stuff you’re throwing a budget number into the dark, and if security isn’t front of mind for the board, it’s very easy for them to say, no, we don’t need that.”
Any final principle that organisations should apply, regardless of size?
Least privilege, applied consistently rather than as a one-off exercise. “It doesn’t matter who you have, you always give them as little privilege as possible, and that reviewed. Say you have a contractor for six months; that’s as far as their access should go. Even if you’re expanding the contract, it should still be reviewed at that point. Is this access enough? Was it too much? Can we take some off you and you still do your job?”
It’s a small habit, applied at every renewal, that stops the slow creep Ben described earlier from happening in the first place.
At Wood for Trees, we understand charities and the not-for-profit sector

So, while we pride ourselves on high-quality data and insight skills, we feel that the real value of these skills is supercharged by the knowledge and experience our team have in working with charity data.
We understand the challenges fundraisers face and know how to use data to give them the answers they need. This all starts with a good grounding and full understanding of your data and supporter landscape.



