You can secure your own IT impeccably and still stand still for days—because it wasn’t your own IT. When a shared IT service provider, a data center, or a software supplier is hit, everyone who relies on them hangs on that thread. For many public authorities and companies, that is the more likely path to an outage than a direct attack: your own perimeter holds, but the service behind it is gone.
This is no longer a fringe topic—it is regulated. NIS-2 and DORA turn the vague notion of “supply-chain risk” into concrete obligations.
Why the Detour Is Attractive
Attackers do the economics. A provider serving 50 municipalities or law firms is a lever: one break-in, many victims. The very concentration that makes shared operations affordable becomes the target. And the route through a trusted supplier—a tampered update, a compromised remote-maintenance access—bypasses many defenses, because it comes from the inside, from a source that is trusted.
What NIS-2 and DORA Concretely Require
Both frameworks explicitly shift responsibility onto the chain:
- Assess suppliers. Affected companies must know and evaluate the risks of their IT service providers—not once, but continuously.
- Harden contracts. For financial firms, DORA (the EU Digital Operational Resilience Act) requires concrete contractual clauses with ICT service providers: security level, audit rights, notification duties, orderly exit scenarios. NIS-2 (the EU cybersecurity directive) demands comparable diligence more broadly.
- Provide evidence. “We trust our provider” is not enough. What is required is demonstrable information: how do they secure, how do they report, how quickly do they respond in a real incident?
The uncomfortable flip side: anyone who is a service provider themselves must be able to supply this evidence—and will, in future, be selected on that basis.
What This Means in Practice
The review begins with uncomfortable questions to every critical provider: Where does our data sit? Who has remote access, and how is it secured? How will we be informed in the event of an incident, and within what deadline? Is there tested recovery—not just a backup? And: what happens if we want to switch? Anyone who does not get these answers has not understood their risk, only outsourced it.
How We Help
As an owner-run IT systems house, we stand on both sides of this chain. For our clients, we support the assessment and hardening of their service providers and deliver the evidence that NIS-2 and DORA require—ongoing evidence maintenance, notification processes, incident readiness. And as a service provider, we disclose the same evidence ourselves: documented operations, defined notification paths, tested recoveries, an environment that is transferable at any time. All of it at a predictable flat monthly rate as part of our compliance support and Managed Services. Trust in the supply chain is good—demonstrable trust is what the legislator now requires.