Zero Trust in the Supply Chain of Critical Infrastructure: When Trust Must Be Verified

18. júna 2026

The weakest point of an organization has long ceased to be its own technology. Increasingly, it is becoming a supplier who has access to systems, data, or ensures the operation of critical services.

With growing digitization, the security of critical infrastructure no longer ends at the borders of a single organization. Its resilience today is also conditioned by the security of partners, suppliers, and the entire digital ecosystem surrounding it. Precisely this change brings a new perspective on trust and pushes the Zero Trust concept to the forefront—an approach based on a simple principle: Never trust, always verify.


What is Zero Trust?


Zero Trust is a modern security approach based on the assumption that no user, device, application, or supplier should be automatically considered trustworthy, regardless of whether they are inside or outside the organization. Its essence is the consistent verification of every identity and every access, providing only necessary permissions, and continuous monitoring and evaluation of risks. At the same time, it is based on the assumption that compromise can occur anywhere in the system, and therefore security cannot be built on automatic trust. Zero Trust, therefore, does not mean distrust toward partners. It represents building trust based on verifiable facts, transparency, and responsible risk management.


The Supply Chain as a New Security Frontier


Modern critical infrastructure is increasingly dependent on cloud services, external data centers, industrial software, remote technology management, third-party services, or integrations through application interfaces (APIs). Cyber attackers are increasingly choosing the supply chain as their entry point. The reason is simple: suppliers often have authorized access to their customers' systems, manage their technologies, or provide critical services.


"Critical infrastructure is only as strong as its weakest supplier. Therefore, it is important to know not only what the supplier provides us, but also how responsibly they approach the security of their systems," says Tibor Straka, President of the Association of Critical Infrastructure of the Slovak Republic.


Every new supplier expands an organization's so-called attack surface. From a security perspective, it is therefore no longer enough to evaluate only the price, technical parameters, or functionality of a solution. Equally important are the questions: What risk does the supplier itself bring? Can they protect sensitive information? Do they have security processes in place? Can they respond to incidents and ensure the continuity of provided services?


The answers to these questions form the supplier's risk profile, which is now becoming one of the decisive factors in selecting partners in the field of critical infrastructure.


What Zero Trust Means in Practice


A supplier is no longer automatically considered a trusted partner. Organizations increasingly require proof of security measures, certifications, and incident management processes.


External partners obtain only the access and permissions necessary to perform their activities, often only for a limited time and to precisely defined systems. An important part of this principle is also continuous risk assessment, where the security status of the supplier is not evaluated only at the conclusion of the contract but is monitored and reassessed throughout the entire cooperation. Trust thus turns into a dynamic process based on constant verification.


European Regulation Confirms the New Trend


The importance of risk management in the supply chain is also confirmed by European rules in the field of cybersecurity. The NIS2 Directive (Network and Information Security Directive 2) introduces stricter requirements for managing cyber risks and emphasizes supply chain security. Organizations operating in critical sectors are required to assess risks associated with external providers and take appropriate measures to manage them.


The DORA regulation (Digital Operational Resilience Act) represents a European framework for digital operational resilience for the financial sector. Its goal is to ensure that financial institutions can withstand, respond to, and recover from cyber incidents and technological failures. Although DORA applies primarily to the financial sector, its principles are gradually becoming an inspiration for other critical infrastructure sectors.



Critical Infrastructure Association of the Slovak Republic systematically promotes the view that the security of critical infrastructure is no longer built only within individual critical entities, but also in the quality of their partnerships and supplier relationships. The Zero Trust concept represents more than just a technological trend. It is not an expression of doubting the supplier, but an expression of responsibility. In today's digital environment, it is becoming a natural part of building secure and resilient critical infrastructure.


18. júna 2026
Najslabším miestom organizácie už dávno nemusí byť jej vlastná technológia. Čoraz častejšie sa ním stáva dodávateľ, ktorý má prístup k systémom, údajom alebo zabezpečuje prevádzku kritických služieb.
15. júna 2026
The Critical Infrastructure Association of the Slovak Republic continues its presentation of individual critical infrastructure sectors. This time, the focus is on an area that forms the digital backbone of modern society and ensures the continuous flow of information, data, and electronic services – the Digital Infrastructure sector.
15. júna 2026
Asociácia kritickej infraštruktúry Slovenskej republiky pokračuje v predstavovaní jednotlivých sektorov kritickej infraštruktúry. Tentoraz sa zameriavame na oblasť, ktorá tvorí digitálnu kostru modernej spoločnosti a zabezpečuje nepretržitý tok informácií, dát a elektronických služieb – sektor Digitálna infraštruktúra.
12. júna 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of articles introducing the essential services defined by Act No. 367/2025 Coll. on Critical Infrastructure. Following our previous articles on electricity supply and the operation, maintenance and development of the electricity distribution system, we now turn our attention to the service that ensures the safe and reliable transmission of electricity across the entire territory of the Slovak Republic – the operation, maintenance and development of the electricity transmission system.
12. júna 2026
Asociácia kritickej infraštruktúry Slovenskej republiky pokračuje v sérii článkov, v ktorej postupne predstavujeme základné služby definované zákonom č. 367/2025 Z. z. o kritickej infraštruktúre. Po predstavení dodávky elektriny a prevádzky, údržby a rozvoja elektrizačnej distribučnej sústavy sa tentokrát pozrieme na službu, ktorá zabezpečuje bezpečný a spoľahlivý prenos elektrickej energie naprieč celým územím Slovenskej republiky – prevádzku, údržbu a rozvoj elektrizačnej prenosovej sústavy.
10. júna 2026
Imagine a situation where equipment that ensures the supply of electricity, the production of drinking water, or the operation of a hospital fails. The failure itself may not be the biggest problem. A much greater challenge can be discovering that the replacement part is manufactured on the other side of the world and its delivery will take several months. It is in situations like these that the true importance of resilient supply chains becomes clear.
10. júna 2026
Predstavme si situáciu, že dôjde k poruche zariadenia zabezpečujúceho dodávku elektriny, výrobu pitnej vody alebo fungovanie nemocnice. Samotná porucha nemusí znamenať najväčší problém. Oveľa väčšou výzvou môže byť zistenie, že náhradný diel sa vyrába na druhom konci sveta a jeho dodanie potrvá niekoľko mesiacov. Práve v takýchto situáciách sa ukazuje skutočný význam odolnosti dodávateľských reťazcov.
8. júna 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of professional articles dedicated to the individual sectors of critical infrastructure under Act No. 367/2024 Coll. on Critical Infrastructure. The aim of this series is to present to both the professional and general public the significance of individual critical sectors, their position within the state security system, essential services, risks, and the obligations of critical infrastructure entities.
8. júna 2026
Asociácia kritickej infraštruktúry Slovenskej republiky pokračuje v sérii odborných článkov venovaných jednotlivým sektorom kritickej infraštruktúry podľa zákona č. 367/2025 Z. z. o kritickej infraštruktúre. Cieľom tejto série je priblížiť odbornej aj laickej verejnosti význam jednotlivých kritických sektorov, ich postavenie v systéme bezpečnosti štátu, základné služby, riziká a povinnosti subjektov kritickej infraštruktúry.
5. júna 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of articles introducing the essential services defined by Act No. 367/2025 Coll. on Critical Infrastructure. Following the topic of electricity supply, we now focus on the service that acts as its "backbone": the operation, maintenance, and development of the electricity distribution system.