Zero Trust in the Supply Chain of Critical Infrastructure: When Trust Must Be Verified

18. júna 2026

The weakest point of an organization has long ceased to be its own technology. Increasingly, it is becoming a supplier who has access to systems, data, or ensures the operation of critical services.

With growing digitization, the security of critical infrastructure no longer ends at the borders of a single organization. Its resilience today is also conditioned by the security of partners, suppliers, and the entire digital ecosystem surrounding it. Precisely this change brings a new perspective on trust and pushes the Zero Trust concept to the forefront—an approach based on a simple principle: Never trust, always verify.


What is Zero Trust?


Zero Trust is a modern security approach based on the assumption that no user, device, application, or supplier should be automatically considered trustworthy, regardless of whether they are inside or outside the organization. Its essence is the consistent verification of every identity and every access, providing only necessary permissions, and continuous monitoring and evaluation of risks. At the same time, it is based on the assumption that compromise can occur anywhere in the system, and therefore security cannot be built on automatic trust. Zero Trust, therefore, does not mean distrust toward partners. It represents building trust based on verifiable facts, transparency, and responsible risk management.


The Supply Chain as a New Security Frontier


Modern critical infrastructure is increasingly dependent on cloud services, external data centers, industrial software, remote technology management, third-party services, or integrations through application interfaces (APIs). Cyber attackers are increasingly choosing the supply chain as their entry point. The reason is simple: suppliers often have authorized access to their customers' systems, manage their technologies, or provide critical services.


"Critical infrastructure is only as strong as its weakest supplier. Therefore, it is important to know not only what the supplier provides us, but also how responsibly they approach the security of their systems," says Tibor Straka, President of the Association of Critical Infrastructure of the Slovak Republic.


Every new supplier expands an organization's so-called attack surface. From a security perspective, it is therefore no longer enough to evaluate only the price, technical parameters, or functionality of a solution. Equally important are the questions: What risk does the supplier itself bring? Can they protect sensitive information? Do they have security processes in place? Can they respond to incidents and ensure the continuity of provided services?


The answers to these questions form the supplier's risk profile, which is now becoming one of the decisive factors in selecting partners in the field of critical infrastructure.


What Zero Trust Means in Practice


A supplier is no longer automatically considered a trusted partner. Organizations increasingly require proof of security measures, certifications, and incident management processes.


External partners obtain only the access and permissions necessary to perform their activities, often only for a limited time and to precisely defined systems. An important part of this principle is also continuous risk assessment, where the security status of the supplier is not evaluated only at the conclusion of the contract but is monitored and reassessed throughout the entire cooperation. Trust thus turns into a dynamic process based on constant verification.


European Regulation Confirms the New Trend


The importance of risk management in the supply chain is also confirmed by European rules in the field of cybersecurity. The NIS2 Directive (Network and Information Security Directive 2) introduces stricter requirements for managing cyber risks and emphasizes supply chain security. Organizations operating in critical sectors are required to assess risks associated with external providers and take appropriate measures to manage them.


The DORA regulation (Digital Operational Resilience Act) represents a European framework for digital operational resilience for the financial sector. Its goal is to ensure that financial institutions can withstand, respond to, and recover from cyber incidents and technological failures. Although DORA applies primarily to the financial sector, its principles are gradually becoming an inspiration for other critical infrastructure sectors.



Critical Infrastructure Association of the Slovak Republic systematically promotes the view that the security of critical infrastructure is no longer built only within individual critical entities, but also in the quality of their partnerships and supplier relationships. The Zero Trust concept represents more than just a technological trend. It is not an expression of doubting the supplier, but an expression of responsibility. In today's digital environment, it is becoming a natural part of building secure and resilient critical infrastructure.


14. septembra 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of articles focusing on basic services under Act No. 367/2024 Coll. on Critical Infrastructure. This time, we look at a basic service that remains largely invisible to the public, yet its disruption can have an immediate impact on transport, industry and the wider economy – the operation of pipelines for the transportation of crude oil and fuels.
14. septembra 2026
Asociácia kritickej infraštruktúry SR pokračuje v sérii článkov venovaných základným službám podľa zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Tentoraz sa venujeme základnej službe, ktorá zostáva pre verejnosť väčšinou neviditeľná, no jej výpadok môže mať veľmi rýchly vplyv na dopravu, priemysel aj fungovanie ekonomiky: prevádzkovaniu potrubí na prepravu ropy a pohonných látok.
8. septembra 2026
Several incidents in the space of a single week. And in one case, 4.2 GW of generation capacity was temporarily taken offline. Germany is dealing with a series of attacks on its electricity grid that highlights one important point: the target does not necessarily have to be the power plant itself.
8. septembra 2026
Niekoľko incidentov v priebehu jediného týždňa. A v jednom prípade dočasne vyradená výrobná kapacita 4,2 GW. Nemecko rieši sériu útokov na elektrickú sieť, ktorá ukazuje dôležitú vec: terčom nemusí byť samotná elektráreň.
5. septembra 2026
District heating and cooling are an important part of the energy infrastructure of cities and municipalities. Their role is not limited to providing thermal comfort; they create stable conditions for the functioning of households, public institutions, industry and other facilities. As energy systems become increasingly technologically complex, the importance of their reliability, preparedness and ability to respond to operational disruptions is also growing.
5. septembra 2026
Diaľkové vykurovanie a chladenie predstavujú významnú súčasť energetickej infraštruktúry miest a obcí. Ich úlohou nie je len zabezpečiť tepelný komfort, ale vytvárať stabilné podmienky pre fungovanie domácností, verejných inštitúcií, priemyslu a ďalších prevádzok. S rastúcou technologickou komplexnosťou energetických systémov zároveň rastie aj význam ich spoľahlivosti, pripravenosti a schopnosti reagovať na narušenie prevádzky.
2. septembra 2026
On Monday, 31 August 2026, a working meeting took place at the Ministry of Interior of the Slovak Republic with State Secretary of the Ministry of Interior Patrik Krauspe, Director General of the Crisis Management Section Jaroslav Kmeť, Naďa Trelová Sonogová from the Department of International Cooperation of the Ministry of Interior, and representatives of the Critical Infrastructure Association of the Slovak Republic (AKI SR).
2. septembra 2026
Na Ministerstve vnútra Slovenskej republiky sa v pondelok 31. augusta 2026 uskutočnilo pracovné rokovanie štátneho tajomníka MV SR Patrika Krauspeho, generálneho riaditeľa sekcie krízového riadenia MV SR Jaroslava Kmeťa, Nade Trelovej Sonogovej z odboru medzinárodnej spolupráce MV SR a predstaviteľov Asociácie kritickej infraštruktúry Slovenskej republiky (AKI SR).
28. augusta 2026
The Government of the Slovak Republic has approved a draft act on the cybersecurity of products with digital elements, also referred to as the cyber resilience act. This is a further step in the legislative process; the bill will subsequently be debated in the National Council of the Slovak Republic.
28. augusta 2026
Vláda Slovenskej republiky schválila návrh zákona o kybernetickej bezpečnosti produktov s digitálnymi prvkami, označovaný aj ako zákon o kybernetickej odolnosti. Ide o ďalší krok v legislatívnom procese, návrh zákona bude následne predmetom prerokovania v Národnej rade Slovenskej republiky.