Supply Chain


The Mid-Market as Both Supplier and Buyer

The Mid-Market's Hidden Role in Supply Chain Risk

Every company in this report is a supplier to someone larger and a customer of someone smaller. Those two roles are usually treated as separate problems, handled by separate teams under separate budgets. In a mid-market company they are rarely handled by anyone at all, and they are the same problem seen from two directions.

You Are Somebody Else's Third Party

The sectors that dominate the victim data, manufacturing, professional and technical services, construction, wholesale, share one trait: Their customers are mostly other businesses. When one of these companies is attacked, the incident is recorded against its own name, but the damage does not stop there.

A compromised parts supplier halts its customer's production line. A breached IT services firm exposes its clients' data and opens a route into their systems.

This is why a mid-market company selling to larger organizations answers more security questions every year. The obligation belongs to the customer, and it is written into regulation on both sides of the Atlantic.

The European Union

The European Union has already put this reasoning into law.

The NIS2 Directive states it plainly. Recital 56 states that small and medium-sized enterprises are increasingly the target of supply chain attacks because of their less mature cybersecurity measures and limited resources, and that such attacks can cascade to the larger entities they supply. Article 21 turns that reasoning into a duty: In-scope entities must manage the security of the relationships between themselves and their direct suppliers. The directive reaches mid-market companies directly, not only their enterprise customers. Its size-cap rule pulls in entities that meet the medium-sized threshold defined in Commission Recommendation 2003/361/EC and operate in a covered sector, which places much of this report's population inside the directive's own scope.

The United States

In the United States there is no single equivalent, and the duty arrives through sector and state rules instead.

New York's financial regulation, 23 NYCRR 500, requires covered firms to maintain written policies for the oversight and due diligence of their third-party service providers, and it does not exempt small firms from that particular obligation. In healthcare, HIPAA holds a covered entity responsible for a business associate's breach where the entity knew, or by exercising reasonable diligence should have known, of a pattern that violated the agreement between them. A mid-market vendor with no regulation of its own still answers to a customer that has one.

The Rules That Apply, Regardless of Size

Jurisdiction
Rule
What It Requires
European Union
NIS2 Directive, Article 21
Manage the security of relationships with direct suppliers; reaches mid-market companies directly via the size-cap rule in Commission Recommendation 2003/361/EC
U.S., Financial
23 NYCRR 500
Maintain written policies for oversight and due diligence of third-party service providers; no exemption for small firms
U.S., Healthcare
HIPAA
Holds a covered entity responsible for a business associate's breach if it knew, or reasonably should have known, of a violating pattern

The evidence those customers want is the same exposure the previous section measured, and much of it they can already see from the outside. A questionnaire asks a company to describe a posture that an external scan has often already revealed. The distance between what a vendor reports and what its exposure actually shows is itself a finding, and it is one the customer can produce at any time.

You Have Third Parties of Your Own

A mid-market company can carry hundreds of vendors, and it typically has no dedicated team to watch them. Industry surveys of vendor-risk programs find teams of two or fewer people responsible for portfolios that run well past three hundred suppliers, a ratio that makes continuous oversight impossible by hand.

The Team Is Two, The Vendor List Is 300+

or fewer

the typical team size managing vendor-risk portfolios

the typical number of suppliers in that portfolio

The gap starts before monitoring does, at the inventory itself. Vendors enter through department-level software purchases, free-tier tools with data access, and components embedded in other software, and many are never recorded. As a result, mid-market vendor inventories are routinely shorter than the real list of suppliers.

A company cannot watch what it has not counted.

What fills the gap is compliance treated as a substitute for security. Techaisle's research across mid-market firms found that 34% have no security protocol in place and 35% operate without a formal risk framework.

Compliance Isn't Security

mid-market firms with no security protocol in place

mid-market firms with no formal risk framework

(Source: Techaisle)

For companies in that position, third-party risk management often reduces to the cheapest defensible option: Buy a questionnaire tool, send the forms, file the responses, and treat the collected paper as evidence that risk is managed.

It is not. The Cloud Security Alliance describes the structural problem plainly: A questionnaire captures a single point in time, its answers are self-reported and hard to verify, and responses that pass on the day they are issued may no longer hold months later. A questionnaire tells a company what a vendor was willing to attest to once. It does not show what that vendor exposes now, and exposure is what an attacker moving through a supply chain actually uses.

That exposure is measurable, and the previous section already measured it. The suppliers of a mid-market company carry unpatched systems, known exploited vulnerabilities, and circulating credentials at the same rates as the wider population, because they are the wider population. Seeing it does not take a larger team. It takes the same external view the company's own customers already use, turned toward its suppliers and kept current, rather than a form filed once a year.

Next: Six ways to close the gap.

Enterprise-grade monitoring, sized for the team and budget you actually have.

PREVIOUS
NEXT