Skip to main content
CYB-0150PractitionerCurrent Intake
X-CWSC-P

Supply Chain and Third-Party Cyber Threat Management

3-Day Instructor-Led Programme

A practitioner programme covering the detection, assessment, and management of nation-state supply chain threats targeting software, hardware, and trusted vendor access channels. Develop the skills to build a vendor security assessment programme, generate and analyse Software Bills of Materials, apply NIS2 supply chain obligations, and respond to a supply chain compromise without disrupting operations.

Duration

3 Days

Price

$3,492

Supply Chain and Third-Party Cyber Threat Management
Duration
3 Days
Complete in 3 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

State-aligned actors pre-position inside software supply chains during periods of relative geopolitical calm, waiting for the strategic moment to activate embedded capabilities. SolarWinds, XZ Utils, and dozens of smaller incidents have demonstrated that trusted software and legitimate vendor access are now primary attack vectors for nation-state actors. Healthcare, manufacturing, defence supply chains, and financial services face the highest exposure.

Over three mentor-led days, participants assess and score third-party cyber risk in a nation-state threat context, identify supply chain implant indicators in software and hardware, design a vendor security assessment programme aligned to NIS2 and NCSC CAF, apply software composition analysis tooling to identify supply chain vulnerabilities, generate and interpret Software Bills of Materials, and develop response procedures for supply chain compromise situations.

The programme concludes with a capstone supply chain compromise investigation: participants receive a simulated compromise scenario, identify the scope, execute containment without disrupting operations, and produce a NIS2-compliant regulatory notification. This course is aligned with NIS2 ICT third-party risk obligations, NCSC supply chain guidance, SBOM standards including SPDX and CycloneDX, and software composition analysis industry practice.

Hands-On Learning

Software composition analysis tool practical, SBOM generation and analysis exercise, vendor risk scoring workshop, and a full supply chain compromise investigation and regulatory notification capstone

Mentor-Led Sessions

Practitioner-led analysis of SolarWinds and XZ Utils attack anatomy, NIS2 supply chain compliance mapping, and vendor security questionnaire design with live commentary on current supply chain threat intelligence

Career-Ready Skills

Third-party risk assessment methodology, SBOM generation and analysis, NIS2 supply chain compliance, software composition analysis, and supply chain compromise investigation and response.

Learning Outcomes

Assess and score third-party cyber risk in the context of nation-state supply chain targeting methodologies.

Identify supply chain implant indicators in software, hardware, and vendor access telemetry.

Design a vendor security assessment programme aligned to NIS2 and NCSC CAF requirements.

Generate and analyse a Software Bill of Materials for an application or dependency set.

Integrate software composition analysis into CI/CD pipelines for continuous supply chain security.

Respond to a supply chain compromise: scope identification, containment, and regulatory notification production.

Implement NIS2 ICT third-party risk obligations within a practical vendor security programme.

Prerequisites

1

Professional experience in procurement, vendor management, software security, or third-party risk management.

2

Basic understanding of software development lifecycle concepts and network security fundamentals.

3

Familiarity with regulatory compliance concepts in a technology or business risk management context.

Detailed Syllabus

Step-by-step learning journey from basics to professional practice

Topics Covered

  • Pre-reading: NCSC supply chain guidance and NIS2 ICT third-party risk management requirements
  • Introduction to software composition analysis concepts and SBOM format standards
  • Accessing course resources, SCA lab environment, and supply chain threat intelligence datasets
  • Course objectives, supply chain security knowledge baseline assessment, and pathway alignment

Skills You'll Gain

Master these in-demand skills through hands-on practice

Third-party risk scoring and tieringSBOM generation and analysisSoftware composition analysisNIS2 supply chain complianceVendor security questionnaire designSupply chain compromise investigationNIS2 regulatory notification productionSCA CI/CD pipeline integrationVendor audit methodologyHardware and firmware integrity assessment

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Third-Party Risk ManagerProcurement Security LeadSoftware Security EngineerSupply Chain Security SpecialistIT DirectorCISO
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

3 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$3,492+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Supply Chain and Third-Party Cyber Threat Management learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Awarding Organisation
Xcademia
Credential Awarded
Certificate of Completion

Important Information

You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.

Credential

Certificate of Completion

On successful completion of Supply Chain and Third-Party Cyber Threat Management, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.

Frequently Asked Questions

Everything you need to know about this course

Procurement leads, third-party risk managers, vendor security teams, software security engineers, and IT directors responsible for supply chain security and ICT vendor risk management.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options