Skip to main content

On-demand webinar coming soon...

On-demand webinar coming soon...

Supply Chain and Third-party Risk: What UK Organisations Need to Do Now

Wednesday, October 21, 2026 | 10:00 AM GMT

Cyber resilience isn't a new topic. Most organisations understand the risks, have invested in controls and are familiar with the regulatory landscape.

The challenge now is turning those requirements into practical, scalable processes that can withstand growing scrutiny from boards, regulators and customers alike. Supplier ecosystems have long been a significant source of resilience risk. The rapid adoption of AI is adding another layer of complexity, making visibility, accountability and oversight across increasingly connected supplier ecosystems even more important.

The pressure is only increasing. The UK Government's latest Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber breach or attack in the last year, rising to 65% of medium-sized organisations and 69% of large organisations. Yet only 31% of businesses place responsibility for cyber security at board level, highlighting the gap many organisations are still working to close between growing risk and effective governance. 

Supply chain management remains one of the weakest areas of organisational cyber resilience. Research shows that only around three in ten medium and large UK organisations carried out a formal assessment of supplier cyber security in the last year, despite growing concern around third-party access, supplier risk and operational dependency.

Photo of abstract architecture behind a green overlay with a play button


Please fill in all required fields

Details:

green dash

Recent incidents across public services, manufacturing and retail show how quickly these risks can translate into operational disruption. A ransomware attack on a supplier to NHS hospitals in London significantly reduced pathology testing capacity and led to delays to more than 11,000 outpatient and elective procedure appointments. The incident demonstrating how disruption within one provider can affect essential services across a wider ecosystem.

At the same time, the Government is strengthening the UK's cyber resilience framework. The Cyber Security and Resilience (Network and Information Systems) Bill is intended to reinforce the security of essential and digital services, with greater emphasis on incident readiness, operational resilience and supply chain risk.

What does this mean for you?

For many organisations, the challenge is no longer understanding the regulations. It's knowing how to translate these expectations and operationalise them.

  • How do you demonstrate accountability to boards and regulators?
  • How do you gain greater visibility across a growing supplier ecosystem?
  • How do you build processes that are scalable, repeatable and capable of standing up to increasing scrutiny?
  • What good look like in practice?

Join OneTrust and Deloitte for a practical discussion on how organisations are approaching these challenges today and the steps they are taking to strengthen cyber resilience across their operations and supply chains.

During this webinar, we'll cover:

  • The UK cyber resilience landscape in 2026 — what's changed, how expectations are evolving and where organisations are focusing their efforts.
  • What good looks like in practice when it comes to governance, accountability, board reporting and audit readiness.
  • Common challenges organisations face when managing supplier and third-party risk — and where they typically fall short.
  • How teams are operationalising cyber resilience at scale across both their own operations and supplier ecosystems

Speakers

Mohammed Chraim

Senior Risk Analyst
OneTrust

Oscardex Ezeigwe

Cyber Risk Advisory Manager
Deloitte

Shanaia Saju

Technology & Transformation Manager
Deloitte