Securing the chain: innovation, accountability and resilience in supply chain security – event round-up

The event also marked the official launch of techUK's Supply Chain Security in Practice playbook, a practical, member-led guide drawing on real-world case studies from across defence, retail and critical national infrastructure.
The session opened with a presentation from Lorna Kirkby, Head of Software Security Policy at DSIT, and David Griffiths, CEO of Hexiosec, on the Software Security Code of Practice. Built around principles covering secure design, build environment security and vulnerability management, the code provides suppliers with a structured way to demonstrate how they build and maintain secure software, while giving buyers a common language to set and communicate security expectations across their supply chains. It comes with a self-assessment that organisations can complete and share with customers as evidence of their practices, as well as supporting implementation guidance.
The panel discussion explored why, despite the range of frameworks and guidance already available, supply chain security requirements are not yet being consistently communicated and acted upon across the economy. A key theme that emerged was the need to engage non-cyber audiences, including boards, procurement teams and commercial functions, in understanding and owning supply chain risk alongside security teams.
Panelists also addressed the shift from reactive to proactive risk management, highlighting the importance of continuous monitoring and supply chain mapping. Because supply chains change constantly, even when business operations appear stable, a single point-in-time assessment gives organisations only a partial view of their exposure. Cross-sector information sharing was presented as a practical way to build a more complete picture, with sectors such as central government already making progress in this area.
On the regulatory landscape, the panel outlined how the Cyber Security and Resilience Bill and the Government Cyber Action Plan are working to embed accountability at a senior level across regulated sectors and government. The discussion also covered how organisations can use existing tools, including standards, certifications and codes of practice, to set clear security expectations in supplier contracts, particularly where regulation does not yet reach.
For smaller organisations, panelists highlighted the practical resources already available, including the NCSC's Early Warning System, Cyber Essentials certification, the Cyber Advisor Scheme and the British Business Bank's funding finder tool, all of which provide accessible starting points for organisations looking to strengthen their supply chain security posture.



