The Weakest Update in the Chain: Professor Kai London on Supply-Chain Risk in Finance
By the Swiss Times Business Desk
The most dangerous vulnerability in a modern bank often sits outside the bank entirely. “Your security is now the weakest update in your supplier's pipeline, and the weakest login at your service provider,” says Professor Kai London, a senior CISO and board advisor. Supply-chain compromise, he argues, has become the defining cyber risk for financial services precisely because the sector runs on a shared, interconnected foundation of third-party technology.
“You can outsource the work, but you cannot outsource the accountability. When a supplier is breached, it is your customers, your regulator and your board who feel it.”
Why finance is uniquely exposed
London points to the structure of modern banking: cloud platforms, payment processors, data providers, software vendors and managed services woven so tightly into operations that they are indistinguishable from the institution itself. That interdependence delivers efficiency — and concentrated risk. “When many institutions depend on the same handful of providers, a single supplier failure becomes a systemic event,” he says. “Regulators now treat that concentration as a first-order concern, and so should boards.”
How supply-chain attacks actually work
The mechanics, London explains, exploit trust. A trusted software update is poisoned and distributed to every customer. A widely used component contains a hidden flaw. A managed service provider with access to many clients is breached and used as a springboard. “The attacker does not break down your door,” he says. “They walk in through a relationship you deliberately trusted — which is exactly why these attacks are so effective and so hard to detect.”
From vendor questionnaires to real assurance
London is blunt about the limits of traditional third-party risk management. Annual questionnaires and certificates, he argues, offer a snapshot and a false sense of security. Real assurance means understanding which suppliers could genuinely take you down, demanding evidence of their security rather than promises, controlling and monitoring the access they have to your systems, and planning for their failure. “Map your critical suppliers, verify their controls, contain their access, and rehearse losing them,” he says. “That is the difference between managing supply-chain risk and merely documenting it.”
Contain the access you have granted
A recurring theme in London's guidance is the quiet accumulation of supplier access. Vendors are granted connections for maintenance and integration that are rarely reviewed and often over-privileged. “Every remote-access pathway a supplier holds is a door into your environment,” he says. “Apply least privilege to your third parties as rigorously as to your own staff, and monitor what they do with the access they have.”
The regulatory spotlight
Supply-chain and third-party risk now sits at the centre of financial resilience regulation. Operational-resilience regimes explicitly require institutions to manage critical third parties, report incidents that originate with suppliers, and demonstrate they can withstand a provider failure. “The regulation has caught up with the reality,” London notes. “Boards are expected to know their supply-chain risk and prove they are managing it — not discover it during an incident.”
Resilience as the answer
Because supply-chain risk can never be eliminated, London stresses resilience over prevention alone. Assume a critical supplier will one day fail or be compromised, and design so the institution can keep functioning — through redundancy, contingency and rehearsed response. “The goal is not a supply chain that never breaks,” he says. “It is an institution that keeps serving customers when one link does.”
For a financial sector built on interlocking trust, London's message is a call to look outward as well as in. The next breach may not begin inside your walls at all — and the institutions that thrive will be the ones that governed the risk they had outsourced as carefully as the risk they kept.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
