
When assessing supply chain sustainability, businesses focus on emissions and ethical sourcing. However, there is an often-overlooked risk that deserves equal attention: communication security.
UK businesses with unsecured communication channels risk exposing sensitive ESG data. Hackers could infiltrate unsecured communications and access emission figures, audit findings, certifications, and other documentation.
Why Communication Security Matters to ESG
Communication security matters because ESG programmes rely on data. For example, procurement teams need data from suppliers to assess environmental practices. Sustainability teams rely on emissions data, while governance teams need policy and control information.
These teams exchange information through emails and messaging platforms. Teams sometimes send open documents through unsecured, remote connections. Hackers can intercept these communications and gain access to confidential information. They may also use compromised accounts to impersonate employees and other professionals. Bad actors may then expose, steal, and alter sensitive company data.
A communications cyber incident would not only compromise confidential information. It would also compromise the credibility of the company’s wider ESG approach. Without protected channels, companies cannot reliably verify supplier compliance.
Cyberattacks are hitting UK manufacturers at an increasing rate. A recent report by MakeUK found that in the last 12 months, 30% of manufacturers had experienced a cyber incident. It is, therefore, more important than ever to secure supply chain communications.
Making Security Part of Procurement Control
The 2025 Cyber Security Breaches Survey found that most businesses in the UK do not take supply chain security seriously. Only 14% of businesses said they reviewed risks posed by their immediate suppliers. Only 7% of businesses reviewed the risks posed by the wider supply chain. These figures do not relate to communication specifically. However, they convey the attitude of the majority of businesses towards supply chain security.
Businesses can adopt a few practical measures to prevent security incidents.
Encrypted Communication Channels
Businesses should always transfer sensitive supplier information through protected channels. They should not use unsecured networks or informal messaging apps. Encrypted communication channels ensure that unauthorised parties cannot steal transmitted information.
Strong Access Controls
Businesses should lock systems and information with strong passwords and multi-factor authentication checks. Businesses should only grant access to employees and external partners who require it. Companies should review permissions regularly and remove former employees and partners as necessary.
Secure Remote Connections
Both procurement and sustainability teams need to work remotely at times. Employees risk company data when they connect to unsecured networks to complete tasks. All employees and associates should use a VPN (Virtual Private Network) when connected to public Wi-Fi. Tools that are widely considered the best VPN establish a ‘virtual tunnel’ of data encryption. The VPN routes traffic through a remote server, which makes it harder for third parties to intercept the data.
Audit Trail Protections
Businesses can protect audit trails by maintaining clear ownership of each document. They should keep records of all changes made to the documents, including information on who made the changes and when. An employee’s role should determine the permissions they receive. Only approved individuals should be able to edit, approve, or delete sensitive procurement and ESG records.
Supplier Security Requirements
Companies should make communication security an explicit requirement when selecting and managing suppliers. A trustworthy supplier should use VPNs and MFA to keep documentation secure. They should also have procedures set out for what to do when a security incident occurs. Businesses should explicitly state these requirements in supplier contracts.
Employee Security Awareness
Strong technical controls are useless if employees aren’t trained on how to use them. All procurement and sustainability teams should receive ongoing cybersecurity awareness training. Businesses should train employees on how to spot phishing attempts and suspicious requests. Managers should regularly remind employees which platforms they can use to share sensitive procurement information.
Supply Chain Communication Must Be Secure
Sustainable supply chain management is more than responsible sourcing and environmental targets. It also depends on the accuracy and confidentiality of data shared throughout the supply chain.
Supply chains are regularly targeted by cybercriminals. Businesses should treat communication security as an essential part of ESG risk management. UK businesses can reduce their exposure by using encrypted communication channels.












