Security risk in the suppliers that keep production moving.
F Creative Studio 360 helps manufacturers and operators in any country see which suppliers can affect a product, a plant or a customer’s data, and what evidence they can actually produce.
A supplier is part of the system.
NIST SP 800-161 is a usable way to write supply-chain cyber risk. It is not a certification. Where a customer or a regulator names a different method, that method is used instead.
The work covers technology suppliers and the parties who can reach operational systems. It is not a legal review of the contract. Counsel owns that.
- Evidence, not a questionnaire score
- A returned spreadsheet is the start. The review asks what sits behind the answer.
- Software and services
- Libraries in the product, and firms that maintain the plant, are both suppliers.
- Concentration
- One firm that every site depends on is a different risk from a long list of small ones.
- We do not audit the supplier for you by surprise
- Contact with a supplier happens only if you ask for it and the supplier agrees.
What the review covers
The suppliers you depend on for the product or the plant in scope.
- Who matters
- Parties whose failure or compromise would stop production or expose data.
- What you hold
- Contracts, reports and access lists, and how old they are.
- How they connect
- Remote access, software updates and data feeds.
- What you will do
- If the evidence is thin, or if the supplier will not provide it.
How an engagement runs
Suppliers can sit in any country. The review follows the dependency, not the headquarters.
- 1
List the dependencies
Product, plant and data. You set the cutoff.
- 2
Read the evidence
What you already have, before anyone is contacted.
- 3
Rank the gaps
By the effect on production or on a customer.
- 4
Hand back an oversight rhythm
What to ask again, and when.
What you receive
- A ranked view of suppliers in scope.
- The evidence you have, and the evidence you do not.
- A suggested oversight rhythm.
- No legal opinion on a contract, and no certificate.
What this is not
This is not a penetration test of a supplier, and it is not a promise that a supplier is safe because they answered a form.
Common questions
Will you contact our suppliers?+
Only when you ask, and only the suppliers who agree. The default is a review of the evidence you already hold.
Who is this for?+
Manufacturers and operators in any country. Suppliers can sit anywhere. A local rule is added only when it applies to you.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Rank the suppliers who can stop the line.
F Creative Studio 360 will look at the dependencies you name, then say what the review includes.
