
Insolvency professionals handle some of the most sensitive financial data in the UK — from distressed business information to creditor details and personal financial records. This makes your firm an attractive target for cyber criminals.
While many firms focus on internal cybersecurity, recent high-profile incidents reveal a growing threat: supplier vulnerabilities. A single weak link in your technology or data supply chain can expose your entire operation to disruption, data breaches, and reputational harm.
While many firms focus on internal cybersecurity, recent high-profile incidents reveal a growing threat: supplier vulnerabilities. A single weak link in your technology or data supply chain can expose your entire operation to disruption, data breaches, and reputational harm.
Recent Lessons: Jaguar Land Rover and Marks & Spencer
In August 2025, Jaguar Land Rover (JLR) suffered a severe cyber attack that forced it to suspend vehicle production and shut down parts of its IT infrastructure. Factories across Solihull, Halewood and Wolverhampton were temporarily closed, with losses estimated at £50–£70 million per day.
The ripple effect extended through its supply chain, affecting hundreds of dependent businesses. To stabilise operations, the UK Government issued a £1.5 billion loan guarantee to support JLR and protect its suppliers.
Earlier this year, Marks & Spencer (M&S) fell victim to a breach via a third-party IT vendor. Attackers exploited stolen login credentials, causing significant disruption to online orders, “click & collect” services, and payment systems. The financial impact exceeded £300 million, alongside considerable reputational damage.
Both cases demonstrate how even large, well-protected companies can be compromised through a supplier. For insolvency firms, which depend on a network of software, IT, and communications providers, the lesson is clear: your cyber resilience is only as strong as your weakest supplier.
Why Supplier Evaluations Matter for Insolvency Firms
Insolvency practices rely on a range of third-party partners — from case management systems and document platforms to payroll and communications providers. Many have direct access to client data or confidential case files.
Conducting annual supplier evaluations allows you to:
- Protect client and creditor data by confirming that suppliers meet modern security and GDPR standards.
- Prevent operational disruption by checking that systems your firm depends on have effective cyber resilience and recovery measures.
- Meet compliance expectations by documenting due diligence and demonstrating proactive data protection.
- Safeguard reputation and trust by showing clients and regulators that cybersecurity is a core operational priority.
What to Include in Your Annual Review
A structured, risk-based supplier review can be simple yet powerful. Focus on the following key areas:
- Access and Data Controls: Who has access to your systems and what privileges do they hold?
- Cyber Hygiene: Are systems patched regularly? Is multi-factor authentication and encryption in place?
- Incident Response: Does the supplier have a tested plan to detect, contain and report breaches?
- Certification: Look for ISO 27001, Cyber Essentials Plus, or SOC 2 accreditation.
- Business Continuity: Could your firm continue operating if that supplier went offline for 48 hours?
Recording and reviewing this information annually not only strengthens your defences but also evidences compliance if regulators or clients request it.
A Proactive Step Toward Protection Against Cyber Attacks
The JLR and M&S incidents underline a crucial reality: cyber attacks often begin outside your organisation. For insolvency professionals, where client data integrity and business continuity are paramount, annual supplier evaluations are no longer optional.
They are a proactive and cost-effective way to identify vulnerabilities, mitigate risks, and reinforce the trust that underpins every client relationship.
By ensuring your suppliers meet the same high standards you expect internally, you protect not only your firm — but also the confidence of those who rely on you during their most challenging times.
