Zero Trust in the Supply Chain of Critical Infrastructure: When Trust Must Be Verified

18. júna 2026

The weakest point of an organization has long ceased to be its own technology. Increasingly, it is becoming a supplier who has access to systems, data, or ensures the operation of critical services.

With growing digitization, the security of critical infrastructure no longer ends at the borders of a single organization. Its resilience today is also conditioned by the security of partners, suppliers, and the entire digital ecosystem surrounding it. Precisely this change brings a new perspective on trust and pushes the Zero Trust concept to the forefront—an approach based on a simple principle: Never trust, always verify.


What is Zero Trust?


Zero Trust is a modern security approach based on the assumption that no user, device, application, or supplier should be automatically considered trustworthy, regardless of whether they are inside or outside the organization. Its essence is the consistent verification of every identity and every access, providing only necessary permissions, and continuous monitoring and evaluation of risks. At the same time, it is based on the assumption that compromise can occur anywhere in the system, and therefore security cannot be built on automatic trust. Zero Trust, therefore, does not mean distrust toward partners. It represents building trust based on verifiable facts, transparency, and responsible risk management.


The Supply Chain as a New Security Frontier


Modern critical infrastructure is increasingly dependent on cloud services, external data centers, industrial software, remote technology management, third-party services, or integrations through application interfaces (APIs). Cyber attackers are increasingly choosing the supply chain as their entry point. The reason is simple: suppliers often have authorized access to their customers' systems, manage their technologies, or provide critical services.


"Critical infrastructure is only as strong as its weakest supplier. Therefore, it is important to know not only what the supplier provides us, but also how responsibly they approach the security of their systems," says Tibor Straka, President of the Association of Critical Infrastructure of the Slovak Republic.


Every new supplier expands an organization's so-called attack surface. From a security perspective, it is therefore no longer enough to evaluate only the price, technical parameters, or functionality of a solution. Equally important are the questions: What risk does the supplier itself bring? Can they protect sensitive information? Do they have security processes in place? Can they respond to incidents and ensure the continuity of provided services?


The answers to these questions form the supplier's risk profile, which is now becoming one of the decisive factors in selecting partners in the field of critical infrastructure.


What Zero Trust Means in Practice


A supplier is no longer automatically considered a trusted partner. Organizations increasingly require proof of security measures, certifications, and incident management processes.


External partners obtain only the access and permissions necessary to perform their activities, often only for a limited time and to precisely defined systems. An important part of this principle is also continuous risk assessment, where the security status of the supplier is not evaluated only at the conclusion of the contract but is monitored and reassessed throughout the entire cooperation. Trust thus turns into a dynamic process based on constant verification.


European Regulation Confirms the New Trend


The importance of risk management in the supply chain is also confirmed by European rules in the field of cybersecurity. The NIS2 Directive (Network and Information Security Directive 2) introduces stricter requirements for managing cyber risks and emphasizes supply chain security. Organizations operating in critical sectors are required to assess risks associated with external providers and take appropriate measures to manage them.


The DORA regulation (Digital Operational Resilience Act) represents a European framework for digital operational resilience for the financial sector. Its goal is to ensure that financial institutions can withstand, respond to, and recover from cyber incidents and technological failures. Although DORA applies primarily to the financial sector, its principles are gradually becoming an inspiration for other critical infrastructure sectors.



Critical Infrastructure Association of the Slovak Republic systematically promotes the view that the security of critical infrastructure is no longer built only within individual critical entities, but also in the quality of their partnerships and supplier relationships. The Zero Trust concept represents more than just a technological trend. It is not an expression of doubting the supplier, but an expression of responsibility. In today's digital environment, it is becoming a natural part of building secure and resilient critical infrastructure.


31. júla 2026
A commentary by the President of the Critical Infrastructure Association of the Slovak Republic 
31. júla 2026
Komentár prezidenta Asociácie kritickej infraštruktúry Slovenskej republiky
28. júla 2026
In the morning, we open the refrigerator. In a shop, we reach for bread, milk, meat, pasta or fruit. In a cafeteria, a child receives lunch; a hospital patient receives a special diet; and a senior in a social services facility receives a warm meal. Most of us do not think about it. Food simply “is”.
28. júla 2026
Ráno otvoríme chladničku. V obchode siahneme po pečive, mlieku, mäse, cestovinách alebo ovocí. V jedálni dostane obed dieťa, pacient v nemocnici diétnu stravu a senior v zariadení sociálnych služieb teplé jedlo. Väčšina z nás nad tým nepremýšľa. Potraviny jednoducho „sú“.
23. júla 2026
In this series, the Critical Infrastructure Association of the Slovak Republic (AKI SR) is gradually introducing the individual essential services listed in Annex No. 1 of the Critical Infrastructure Act – in other words, those activities without which the economic and social life of the state would quite literally grind to a halt. After the previous instalments, this time we turn to a service that most people have never heard named, yet rely on every second of the day: electricity demand management.
23. júla 2026
Asociácia kritickej infraštruktúry SR v tejto sérii postupne predstavuje jednotlivé základné služby uvedené v prílohe č. 1 zákona o kritickej infraštruktúre – teda tie činnosti, bez ktorých by sa hospodársky a spoločenský život štátu doslova zastavil. Po predchádzajúcich dieloch sa tentoraz pozrieme na službu, ktorú väčšina ľudí nikdy nepočula pomenovať, ale spolieha sa na ňu každú sekundu dňa: riadenie odberu elektriny. 
20. júla 2026
The Critical Infrastructure Association of the Slovak Republic (AKI SR) continues to connect state institutions with domestic technology companies that develop innovative solutions contributing to greater resilience of critical infrastructure. One such example is AKI SR member company Foss Fibre Optics, s.r.o., a Slovak manufacturer of cutting-edge optical technologies used to protect strategic facilities, secure critical communications networks, and monitor infrastructure.
20. júla 2026
Asociácia kritickej infraštruktúry Slovenskej republiky pokračuje v prepájaní štátnych inštitúcií s domácimi technologickými spoločnosťami, ktoré vyvíjajú inovatívne riešenia prispievajúce k zvyšovaniu odolnosti kritickej infraštruktúry. Jedným z príkladov je členská spoločnosť AKI SR – Foss Fibre Optics, s.r.o, slovenský výrobca špičkových optických technológií, ktorých využitie nachádza uplatnenie pri ochrane strategických objektov, zabezpečení kritických komunikačných sietí a monitorovaní infraštruktúry.
17. júla 2026
Decent Cybersecurity s. r. o., a member company of the Critical Infrastructure Association of the Slovak Republic, has been selected among the ten innovators chosen for the Decision Superiority for NATO Warfighters challenge, launched by the Defence Innovation Accelerator for the North Atlantic (NATO DIANA) in close collaboration with Allied Command Operations (ACO). The selection was announced on 13 July 2026, and each of the chosen entities receives funding for the integration and demonstration of its solution directly with the Alliance's end users. 
17. júla 2026
Spoločnosť Decent Cybersecurity s. r. o., členská firma Asociácie kritickej infraštruktúry Slovenskej republiky, sa prebojovala medzi desiatku inovátorov vybraných do výzvy Decision Superiority for NATO Warfighters, ktorú vyhlásil Defence Innovation Accelerator for the North Atlantic (NATO DIANA) v úzkej spolupráci s Allied Command Operations (ACO). Výber bol oznámený 13. júla 2026 a každý z vybraných subjektov získava financovanie na integráciu a demonštráciu svojho riešenia priamo s koncovými používateľmi Aliancie.