Why are customers asking manufacturers about cyber security?
Because you are part of their supply chain, and their own obligations now extend to their suppliers. Attackers target the least defended link, so larger customers have started asking their smaller suppliers specific questions, and being unable to answer is itself treated as an answer.
The questions have become notably more specific over the past few years. Where a supplier questionnaire once asked whether you had antivirus, it now asks whether multi-factor authentication is enforced across all accounts, how quickly systems are patched, whether backups have been restored and tested, and whether you have been assessed against a recognised framework. Those are answerable from records or not at all, and the difference is visible immediately to whoever is reading.
This lands hardest on manufacturers because of who their customers tend to be. Supplying into larger businesses, government-connected work, or anything defence-adjacent brings supplier security assessment as a matter of course, and it is increasingly scored rather than noted. A manufacturer that cannot answer is not merely embarrassed; it may be excluded, and often without a conversation about why.
The efficient response is an Essential Eight assessment, because most questionnaires map closely onto those eight controls and a dated, control-by-control report answers the bulk of one in a single document. It also gives you something to attach rather than prose. Tindo Solar's brief explicitly paired scaling IT with closing critical cybersecurity gaps, which is the position many growing manufacturers find themselves in once customers start asking. If you want the report that answers the questionnaire, the Scorecard is free, or call 1800 456 567.
Have the answer ready
The free Cyber Security Scorecard gives you a dated, control-by-control report to attach to supplier questionnaires instead of assurances.
Other questions we are asked about this, answered the same way.
- 5 min
What is an Essential Eight assessment, and what actually happens during one?
What gets measured, what evidence gets examined, and what the report should hand you. A walkthrough for the business being assessed.
Read the article - 2 min
Does a financial advice firm need the Essential Eight?
Not by law, and it produces exactly the evidence licensees and insurers now ask for, which makes it the efficient path.
Read the article - 6 min
What should an advice firm be able to tell its licensee about cyber security?
Specific, dated answers rather than assurances. A maturity report answers most licensee questionnaires in one document.
Read the article
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business