SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

Your risk is only as low as your weakest supplier's security.

A significant share of enterprise attacks aim not at the target but at a third party with access to it. Sanal Çekirdek addresses supplier risk in three layers: contract, access and continuous monitoring.

Sending a questionnaire is not a control. The control is how narrow and how observable the supplier's access actually is.

Supplier inventory and criticality

The list comes first: which supplier reaches which data, which system, with which privileges. Criticality follows the class of data reached and the business impact of an outage — not the size of the supplier.

  • Subcontractors belong in the inventory too
  • Criticality is set by data class and business impact
  • A supplier whose access ends leaves the inventory
  • The inventory is wired into the procurement process

Contract and obligations

A contract is where the arguments that would follow an incident are settled in advance: breach notification timing, audit rights, use of subcontractors, what happens to data at the end. Under Turkish data protection law a processor agreement is separately required.

  • Breach notification timing is written as a number
  • Use of subcontractors requires permission
  • Return and destruction of data at contract end is defined
  • Audit rights are drafted so they can actually be exercised

Access design

The most effective control is that a supplier cannot reach anything it does not need. Access is opened for a task and expires, sessions are recorded, and no standing privileged account is issued.

  • Access opens on a work request and closes on expiry
  • Session records allow the work to be reviewed later
  • No standing privileged accounts are issued
  • Network reach is limited to the required destinations

Awareness and behavior

Awareness training is measured by behavior change, not by attendance. Simulation results, reporting rates and repeated mistakes are tracked together; the aim is less risky behavior, not punishment.

  • The measure is reporting and error rate, not attendance
  • Simulation difficulty increases in stages
  • Results are reported at group level, not per person
  • A repeated mistake signals a process problem, not a training gap

How we work

  1. Build the supplier and access inventory
  2. Set criticality by data class
  3. Put contractual obligations in writing
  4. Make access time-bound and observable
  5. Track awareness through behavioral measures

How success is measured

  • The data class each supplier reaches is known
  • Suppliers hold no permanent privileged account
  • Breach notification duties appear in the contracts
  • Reporting rates in simulations keep rising

Frequently asked questions

Is a supplier questionnaire enough?

Not on its own. A questionnaire is a declaration; the control is how narrow, time-bound and observable the access is. For critical suppliers it should be backed by technical verification.

Should small suppliers be in scope?

Criticality follows access, not size. A small software provider with reach into a production database can carry more risk than a large one.

Does awareness training actually work?

It does when measured correctly. Attendance says nothing; a rising rate of reported suspicious email and a falling rate of repeated mistakes are meaningful indicators.

To see which data each of your suppliers can reach, let's begin with the inventory work.

Build your supplier inventory