Your Supply Chain Has a People Problem

The UK Cyber Security and Resilience Bill will regulate critical suppliers directly. Most are not ready – and the talent gap in the supply chain is the reason why.

Governance & Leadership
Risk & Resilience
Hiring Strategy
July 27, 2026
5
minutes
← Back to Insights

Everyone is talking about supply chain security. Almost nobody is talking about the right part of it.

The UK Cyber Security and Resilience Bill, which is heading for Royal Assent later this year, does something NIS2 doesn’t. It directly regulates critical suppliers. Not just the CNI operators themselves, but the companies those operators depend on. The managed service providers, the systems integrators, the OT vendors, the cloud platforms, the outsourced SOC providers.

That’s a significant shift. And the conversation around it has been almost entirely about technology and assurance frameworks. Do your suppliers meet Cyber Essentials Plus? Have they got ISO 27001? Can they evidence their patching cadence?

Those are the right questions. But they miss a more fundamental one: do your suppliers have the people to do what you’re about to require of them?

The talent gap doesn’t stop at your front door

Here’s what we see from the recruitment side. A large CNI operator decides to take supply chain security seriously. They build out their own third-party risk function. They hire a supplier assurance lead, maybe a small team. They start flowing requirements down to their Tier 1 suppliers.

And then those suppliers try to hire the people needed to meet those requirements. The same GRC professionals, the same security engineers, the same compliance analysts that the operator just spent six months hiring from an already thin market.

The talent pool doesn’t double because the regulatory scope doubled. It stays roughly the same size while demand across the chain increases. The operator gets their people because they can pay more and offer more interesting work. The supplier, often a smaller company with tighter margins, gets what’s left.

This isn’t a theoretical concern. We’re already seeing it. Managed security service providers telling us they can’t recruit fast enough to service new compliance-driven contracts. OT integrators winning work they then struggle to deliver because the security expertise the contract assumed doesn’t exist internally. IT service companies adding “cyber” to job titles without adding the corresponding capability.

The assurance gap

What makes this particularly tricky is that the current assurance model doesn’t really test for it.

A supplier can hold ISO 27001 certification with a lean team, because the standard assesses management systems, not headcount. Cyber Essentials Plus tests technical controls, not whether there’s a qualified person maintaining them day to day. A SOC 2 Type II report tells you that controls operated effectively during the audit period. It doesn’t tell you that the person who operated them left two months later and hasn’t been replaced.

So a CNI operator can do everything right on paper – flowing requirements down, checking certifications, reviewing evidence packs – and still be exposed because the supplier’s security function is one resignation away from collapse.

We’ve seen this play out. A supplier passes an annual audit, a key person leaves, and for three months the controls that were evidenced during the audit are running on autopilot. Nobody at the operator end knows until something goes wrong.

What the Bill will change

The Cyber Security and Resilience Bill gives regulators new powers to set security requirements for designated critical suppliers. The detail will come through secondary legislation, but the direction is clear: suppliers to CNI will face direct regulatory obligations, not just contractual ones.

That changes the calculation for suppliers. Until now, security investment was a cost of doing business with demanding clients. Soon it becomes a compliance obligation with its own penalty regime. The suppliers that took a minimal approach – lean teams, borrowed expertise, compliance-by-checkbox – will need to build actual capability.

Which means they’ll need to hire. In the same market. For the same people.

The question nobody is asking in procurement

When a CNI operator evaluates a supplier’s security posture, the conversation tends to focus on documentation, certifications, and technical controls. Rarely does anyone ask: who is your security team? How many are there? How long have they been with you? What’s your attrition rate in that function?

Those questions feel intrusive. They’re also the ones that would tell you whether the supplier can actually sustain the security posture they’ve evidenced.

A supplier with three security staff, one of whom joined last month, is in a fundamentally different position from one with ten who’ve been there for years. The certifications might look identical. The resilience is not remotely comparable.

If the Bill is going to make supply chain security a regulatory reality, the assurance model needs to catch up. Technology controls matter. Process documentation matters. But the people who operate those controls and maintain those processes matter more, and right now almost nobody is assessing whether they exist, whether they’re qualified, and whether they’ll still be there next quarter.

The supply chain security conversation needs a workforce chapter. It doesn’t have one yet.

LC
Laurence Connor
Operations Director, Foundations Search
Share this article

Trusted by security leaders at

Datacor logoNomios logoBritish Airways logoForvis Mazars logoEquinix logoJamf logo

Talk To Our Founder

Book a Call

Gyles Whitnall

"I can't recommend Gyles and the team at Foundations enough. We struggled to find a suitable candidate for 5 months, Foundations found 3 perfect candidates in 24 hours."

Manager of EMEA & APAC Network Engineering, Equinix