Course overview
An organization is only as secure as its weakest supplier. Attackers increasingly breach their targets by compromising a vendor, a software update, or a service provider, turning trusted relationships into attack paths. This course shows how to secure the supply chain and manage the third-party risk that traditional, inward-looking security misses.
Participants examine the supply-chain threat landscape, vendor and third-party risk management, and the frameworks and standards that structure it, including the NIST Cybersecurity Framework, ISO/IEC 27036, and CMMC. The course then covers governance, contractual protections, and building resilient supplier ecosystems, using documented supply-chain attacks throughout.
Why this matters
Major breaches have shown how a single compromised supplier can cascade across thousands of organizations. As businesses depend on ever more vendors and cloud services, third-party risk has become one of the hardest security problems. Professionals who can assess and manage it protect the whole ecosystem, work that builds on the governance in the Cybersecurity Governance and Risk Compliance course.
What you will be able to do afterwards
By the end of the course, participants will be able to:
- Explain the supply-chain cybersecurity threat landscape.
- Assess and monitor vendor and third-party risk.
- Apply frameworks such as the NIST CSF, ISO/IEC 27036, and CMMC.
- Use governance and contracts to enforce supplier security.
- Build resilient, collaborative supplier ecosystems.
Course outline
Unit 1: Supply chain cybersecurity landscape
The unit sets out the threat through suppliers.
- Threats to global and digital supply chains.
- Nation-state and criminal exploitation of vendors.
- Case studies of supply-chain cyberattacks.
- The importance of supply-chain resilience.
Unit 2: Vendor and third-party risk management
Participants examine assessing suppliers.
- Identifying and assessing vendor risk.
- Due diligence in procurement processes.
- Continuous vendor monitoring.
- A worked third-party risk assessment.
Unit 3: Frameworks and standards for supply chain security
The unit covers the recognized frameworks.
- The NIST Cybersecurity Framework for supply chains.
- ISO/IEC 27036 and related standards.
- Cybersecurity Maturity Model Certification (CMMC).
- A worked example applying frameworks to vendor oversight.
Unit 4: Governance, compliance, and contractual protections
Participants study enforcing supplier security.
- Building governance models for supply-chain security.
- Regulatory and compliance requirements.
- Contract clauses for cybersecurity and liability.
- A case study of securing vendor contracts.
Unit 5: Building resilient supply chain ecosystems
The closing unit connects security to resilience.
- Collaboration across suppliers and stakeholders.
- Incident response in supply-chain disruptions.
- Future risks: IoT, AI, and geopolitical factors.
- A roadmap for sustainable supply-chain resilience.
How the course is delivered
The course combines structured teaching with documented supply-chain attacks, worked examples, and guided analysis of vendor risk and frameworks. Participants reason through securing the supply chain using realistic material, so the methods transfer to their own vendor relationships. The course is educational and does not provide a live lab or a security certification.
Who should attend
The course suits security, risk, and procurement professionals, vendor and third-party risk managers, compliance staff, and managers responsible for supplier oversight. A basic grounding in security or procurement is helpful.
About EuroQuest International Training
EuroQuest International Training is an international training provider founded in 2015, with a catalog of more than 1,000 courses delivered to over 15,000 participants. Headquartered in Bratislava, EuroQuest runs courses across a network of European and regional training hubs and focuses on practical, current, and professionally relevant content.
Frequently asked questions
Which frameworks does the course cover?
It draws on the NIST Cybersecurity Framework for supply chains, ISO/IEC 27036, and the Cybersecurity Maturity Model Certification (CMMC), as educational subject matter, and shows how to apply them to vendor oversight.
Is this course for security or for procurement people?
Both. Third-party risk sits where security and procurement meet, so the course serves security and risk professionals alongside procurement and vendor-management staff, giving each the other's perspective.
Does the course include a live lab?
No. It builds understanding through documented attacks and guided analysis rather than a live lab. It is educational and prepares you to manage supply-chain and third-party risk, not a certification.
Related courses
- Supply Chain Security and Risk Mitigation
- Cyber Threat Modeling and Risk Assessment
- IoT Security and Emerging Technology Risks
- Building a Cybersecurity Strategy for Enterprises
Register for this course
To reserve a place or request an in-house session for your team, contact EuroQuest International Training and our team will help you confirm dates and details.
All Course Dates & Locations
28 dates · 12 cities · Oct 2026 – Jun 2027