
22 June 2026 • 4 minute read
Breaking the chain: Cyber risk in supply chains
In this episode of DLA Piper’s ‘Better Contracts’ podcast series, Verena Grentzenberg catches up with Nicholas De Lacy-Brown and Piotr Czulak to explore one of the most pressing challenges in modern supply chain management: cyber risk.
Listen now
Data indicates that supply chain attacks have increased materially in the past five years, with threat actors targeting key service providers and ecosystems to maximise disruption. Just this month, there was a worm attack on trusted open‑source repositories that are widely used by software developers, impacting businesses across various industries.
A vulnerability in one supplier can ripple across the entire supply chain, which has two immediate implications for a business: cyber risk is no longer confined to its own business, and supply chain dependencies – particularly where multiple organisations in one industry or market rely on the same few suppliers – can significantly increase legal, operational, and financial exposure when a cyberattack occurs.
Against this backdrop, the discussion considers the evolving regulatory and enforcement landscape in the UK and the EU and identifies how businesses can use their contracts, alongside other risk management measures, to manage their exposure.
The growing threat
The discussion kicks off with a look at the current threat landscape, drawing on several high-profile examples to illustrate the scale of the issue.
Our panel considers this against the regulatory environment, noting that supply chain cybersecurity is an area of increasing focus for regulators across the EU and the UK. The discussion highlights a consistent theme: liability cannot be outsourced. Enforcement action across the EU demonstrates a focus on failures to audit, monitor, and enforce contractual rights. Robust contracts are essential, but businesses that fail to move beyond compliance on paper towards embedded risk management frameworks will face regulatory scrutiny – and potential significant liability – when impacted by an attack on a counterparty.
Meeting the challenge
Our panel then considers how businesses should approach supply chain cyber risk, starting with a risk-based analysis of their supply chain to identify critical dependencies and inform procurement strategy.
The discussion covers the impact on supply contracts of EU legislation like the updated Network and Information Systems Directive (NIS2) and the Digital Operational Resilience Act (DORA), and it highlights the importance of actively managing and enforcing the contract. Simply accepting contractual assurances at face value is increasingly risky from a legal and regulatory perspective.
Regulators will assess whether technical and organisational measures are appropriate by reference to industry norms and the known threat landscape, so it is important for businesses to stay up to date with the evolving landscape and regulatory guidance.
Beyond the contract
The podcast rounds off with a discussion of the practical measures that should sit alongside contractual protections, highlighting that contracts can allocate risk but cannot manufacture resilience. The panel offers a number of helpful takeaways that support businesses in taking a holistic approach to managing cyber risk across their supply chains.
You can listen to the podcast and find out more about the other podcasts in the series here.
Further reading
- EU: NIS2 Update - EU Moves to Harmonise Cyber Controls, Refine Scope, and Add New In-Scope Entities
- Germany: Monitoring and auditing obligations of controllers with respect to their processors
- Cyber Resilience Act: What you need to know and what you need to be doing
- Seconds matter: Understanding DORA’s real-time response requirements
Since the podcast was recorded, the UK’s National Cyber Security Centre issued an advisory in relation to software supply chain attacks, warning that attackers are compromising software ecosystems to widely spread malware and that organisations must review and maintain a clear inventory of all software dependencies to reduce the risks: Software supply chain attacks: check your dependencies | National Cyber Security Centre



