All insights

Why are customers asking manufacturers about cyber security?

2 min readBy Brendon Whiting, Founder · 26 May 2026

Because you are part of their supply chain, and their own obligations now extend to their suppliers. Attackers target the least defended link, so larger customers have started asking their smaller suppliers specific questions, and being unable to answer is itself treated as an answer.

The questions have become notably more specific over the past few years. Where a supplier questionnaire once asked whether you had antivirus, it now asks whether multi-factor authentication is enforced across all accounts, how quickly systems are patched, whether backups have been restored and tested, and whether you have been assessed against a recognised framework. Those are answerable from records or not at all, and the difference is visible immediately to whoever is reading.

This lands hardest on manufacturers because of who their customers tend to be. Supplying into larger businesses, government-connected work, or anything defence-adjacent brings supplier security assessment as a matter of course, and it is increasingly scored rather than noted. A manufacturer that cannot answer is not merely embarrassed; it may be excluded, and often without a conversation about why.

The efficient response is an Essential Eight assessment, because most questionnaires map closely onto those eight controls and a dated, control-by-control report answers the bulk of one in a single document. It also gives you something to attach rather than prose. Tindo Solar's brief explicitly paired scaling IT with closing critical cybersecurity gaps, which is the position many growing manufacturers find themselves in once customers start asking. If you want the report that answers the questionnaire, the Scorecard is free, or call 1800 456 567.

Have the answer ready

The free Cyber Security Scorecard gives you a dated, control-by-control report to attach to supplier questionnaires instead of assurances.

Frequently asked questions

Increasingly yes, particularly with larger customers, government-connected work and anything defence-adjacent, where supplier security is now a scored part of assessment rather than a formality. Being unable to answer is treated as an answer, and the businesses that lose out are often the ones that simply had not been asked before.

Specifics rather than assurances: whether multi-factor authentication is enforced, how systems are patched, whether backups are tested, how incidents are handled, and whether you have been assessed against a framework. Most map closely onto the Essential Eight, which is why an assessment answers so much of one at a stroke.

Size is not the filter; supply chain position is. A small manufacturer supplying a large customer is precisely the kind of supplier those programmes are aimed at, because attackers target the least defended link. Being small has stopped being a reason to be excused from the question.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.