IT Procurement

Why IT Procurement Is a Security Decision, Not Just a Purchasing One

N
By Nicola
September 2026Category: IT Procurement
Key Takeaway

IT procurement has long been treated as a cost and logistics exercise, judged on price, availability and delivery. That framing no longer holds. Every device, licence and supplier a business brings in becomes part of its security perimeter, and much of the risk it carries is inherited at the point of purchase, long before anything is switched on.

Regulation has reinforced the point, with the EU's NIS2 Directive and the UK's Cyber Security and Resilience Bill placing formal duties on organisations to manage supplier risk. For businesses without the internal capacity to run procurement this way, structured IT sourcing provides the supplier reach and lifecycle control to do it properly.

Four business professionals reviewing a tablet in a server room with networking equipment and company branding visible

Picture the way most technology gets bought. A team needs new laptops. A project runs short of server capacity. A software renewal drops onto someone's desk. Whoever handles purchasing finds a supplier, agrees a price and places the order. The kit turns up, someone sets it up and the task is ticked off. On speed and cost, the process did its job.

Trouble is, speed and cost were never the only things on the table. That same order settled a string of security questions in passing: which supplier to trust, where the hardware was really made and handled, whose firmware would end up running inside the network, whether the software came down a legitimate channel. Nobody sat and weighed those questions. They got answered by default, by people whose job was to land the right item at the right price. And the space between what procurement decides and what procurement gets judged on is where a lot of avoidable risk hides.

What follows is a look at why buying technology has become a security job, the risks that travel down the supply chain and what it takes to source around security rather than price alone.

Why Buying Technology Is Now a Security Question

Procurement carries security weight now because the security perimeter has moved. Protection used to sit at the edge of the network. Whatever ran inside the firewall was trusted, and the job of security was to keep threats on the outside. Most serious environments have abandoned that model. They now run some form of Zero Trust, where nothing is trusted by default and every device, user and connection has to earn its place.

Once you look at it that way, a new purchase stops being a neutral object. It joins the network carrying its own history. A laptop runs firmware that a manufacturer wrote and updates, built from components that passed through a chain of suppliers, and it reached your loading bay by a route that may have crossed several sets of hands. A software licence brings the security habits of whoever sold it, along with the integrity of the media it was installed from. Buy any of these, and you inherit the security of everyone who handled it along the way.

So the cheapest or fastest supplier is not automatically the safest one. A laptop bought for a few pounds less from a reseller nobody has vetted can create problems that cost far more to untangle later, if anyone spots them at all. The buying decision and the security decision happen at the same moment. Split them apart and you leave a gap that someone else will find.


The Risks That Ride In on a Purchase Order

None of these risks is exotic. They happen when technology gets bought without security in mind, and they fall into a few groups.

Compromised or unverified hardware

You cannot see hardware risk when the box turns up. Firmware, the low-level code that runs a device before the operating system even loads, might be out of date, badly configured or, in the worst cases, tampered with. Kit bought outside official channels can turn out to be refurbished stock sold as new, counterfeit gear or units that have passed through hands nobody can account for. Once something with a murky history is sitting in the estate, checking whether it is clean is hard and often impossible. The only check that works is knowing where a device came from before it turns up.

Software and licensing exposure

Software bought through unofficial routes runs into much the same trouble. Installation files from a source you cannot vouch for may hide modified or bundled components. Licences picked up through grey-market channels can be invalid, already used elsewhere or simply unsupported, which cuts the business off from security patches at the very moment it needs them. Attackers constantly target unpatched software, so a licence chosen on price alone can take a system off the update path that keeps it safe.

The supplier's own security

Buy from a supplier and you take on a slice of how well that supplier protects itself. A reseller or distributor with weak internal controls, careless customer data handling or a breach of its own becomes an entry point for anyone targeting its customers. Many attacks now arrive through the supply chain rather than the front door, because a trusted supplier becomes an easy stepping stone.

Grey-market and shortage-driven buying

Shortages and rushed refresh projects sharply increase the risk. When a device is scarce and the deadline will not move, buying from whoever has stock starts to look reasonable. That is usually when unverified suppliers and grey-market channels slip in, and when the normal checks get waved through. If you want to predict a bad sourcing decision, look for a tight delivery deadline.


What Unverified Devices Do to a Zero Trust Programme

Most enterprises are moving towards Zero Trust, and it makes sense. The idea, that no device or user gets trusted automatically and everything has to be verified again and again, fits a world where the network edge barely exists anymore. There is a catch, though. Zero Trust only works if you can establish trust on purpose, and that gets much harder when you cannot say where a device came from.

A device whose firmware you cannot vouch for weakens the whole model before it is even enrolled. Zero Trust wants you to verify each device's identity and integrity, apply policy to it and watch how it behaves. All of that rests on a known starting point. When nobody can confirm where a device came from, who handled it or whether its firmware is genuine and current, the trust decision made at enrolment is really a guess. You end up wrapping strict controls around a base that was never checked in the first place.

That is where procurement meets security architecture. Every control you stack on a device, from identity checks to segmentation to constant monitoring, holds up better when the device reached you by a known and approved route. Sourcing decides whether that base is sound. A cyber security approach that expects verified endpoints but waves unverified ones in through purchasing is pulling in two directions at once.


How Scattered Supplier Relationships Open Lifecycle and Compliance Gaps

One supplier, well managed, is easy enough to keep on top of. Trouble starts once a business is buying from a dozen suppliers with nothing joining them up, which is where most organisations end up given enough time. Different teams use different vendors, anything urgent goes to whoever can deliver first and no single record covers the whole estate. Two kinds of gaps open up as a result.

The first is about lifecycle. Spread purchasing across enough suppliers and you lose track of what you own, when you bought it, what warranty or support sits behind it and when it is due for replacement. Devices hit end of life with no plan in place. Licences roll over automatically or lapse without anyone noticing. Old kit gets thrown out without anyone wiping the data, because no process was ever attached to it. Every one of these costs money and creates security risk, and they build up out of sight until something drags them into the open.

The second is about compliance. More and more, businesses have to show where their equipment came from, that they checked their suppliers and that they track and manage what they own. A scattered supplier base makes that a struggle to prove. When an auditor, a big customer or a regulator asks to see your supply chain controls, buying reactively from an ever-changing list of vendors leaves you with very little to hand over.

Sourcing and day-to-day service delivery are really the same job seen from two ends. Buy with the lifecycle in mind and the asset records, refresh plans and support routines all fall into place. That is why sourcing works best when it feeds into the wider managed services that keep the estate running, instead of sitting off to one side as a run of separate purchases.


Supply Chain Security Is Now Written Into Law

For a long time this was just sensible practice. Now it is turning into law. Regulators in the EU and the UK have caught up with the fact that supply chains are a favourite way into an organisation, and buyers are being asked to prove they are handling the risk.

The European position under NIS2

The EU's NIS2 Directive, now being written into national law across member states, makes supply chain security a required part of cyber risk management. Organisations in scope must assess the security of their dealings with direct suppliers and service providers, weigh each one's specific weaknesses, and build supplier security into their own risk work. Put plainly, choosing a supplier is a security decision, and you are expected to show your reasoning. UK firms that sell into the EU or supply EU customers feel this too, since it arrives through their contracts and the assurance questions their customers now ask.

The UK Cyber Security and Resilience Bill

The UK is heading the same way with its Cyber Security and Resilience Bill, which overhauls and widens the existing Network and Information Systems Regulations. It brings more organisations into scope, puts managed service providers under direct regulation for the first time and lets regulators name critical suppliers whose failure would hit essential services. Supply chain risk runs right through it: regulated organisations will have to manage the security of the suppliers they lean on. It worked its way through Parliament during 2026 and stands as the biggest shake-up of UK cyber rules since 2018.

Why this reaches businesses that are not directly regulated

Plenty of businesses will look at who these rules cover, decide they are not on the list and move on. They may well be right that they are not directly regulated, but that will not keep the requirements away. Duties land on the regulated organisations first, then work their way down the chain. A regulated customer that has to manage its own supplier risk will push security requirements onto its suppliers through contracts, questionnaires and minimum standards. Insurers are asking harder questions about supply chain controls before they will offer cover. So the expectations reach firms of every size, named in the legislation or not. Being able to show where your equipment came from and why you chose a given supplier is fast becoming part of winning work, not something only the big players need to worry about.


What Security-Aware Sourcing Looks Like in Practice

Agreeing that procurement is a security decision takes a minute. Turning that into a way of buying takes a bit of work, and it is where the payoff sits. None of it means treating every order like a criminal inquiry. It means a handful of sensible controls, set up once, so that security comes as standard instead of by luck.

Buy through approved vendors and verified channels

Secure sourcing starts with knowing, and trusting, the road a product travels to reach you. In practice that means going through established distributor and manufacturer relationships, not whoever is cheapest or quickest that particular week. A network built on direct manufacturer partnerships and vetted distributors clears up most of the doubt about where something came from before it can bite. It also holds up during shortages, when the pull towards unverified channels is strongest. Contrac leans on relationships with more than 300 distributors and partnerships with the likes of Microsoft, Dell and Cisco partly for this reason: to give clients a supply route they can actually trust.

Put security requirements in the specification

Security belongs in the spec, not in a check somewhere after the fact. Write the requirements in up front, things like supported and current products, genuine licensing and sensible configuration, so the unsupported or non-compliant options fall away before anyone gives them a look. Once those criteria are baked in, the buying decision leans towards kit that will last rather than whatever just covers the immediate need.

Keep sight of the whole asset lifecycle

The job doesn't end when the courier leaves. It runs the length of the asset's life, from the first time someone writes down a requirement to the day the kit is retired properly. In between, that means keeping asset records straight, watching warranty and support dates, planning replacements before things break and making sure old devices are wiped and disposed of correctly. Do this and a pile of separate purchases becomes an estate you can manage, and one you can answer questions about without a scramble.

Give someone a single point of accountability

Spread your suppliers wide enough and nobody owns the whole picture. Pull sourcing under one accountable partner, or at the very least one coordinating point, and the cracks between vendors start to close. Your own team carries less admin, no supplier can point the finger at another when something breaks and there is finally one place where supply chain security gets governed. That single point of ownership is what structured IT sourcing is built to give you.


Cheap Hardware Has a Habit of Getting Expensive

Every purchase is also a quiet vote on whose security you are willing to lean on and how much risk you will carry. Ignore that side of it and the risk stacks up out of sight, surfacing later as an incident, a failed audit or a contract you lost. Handle it deliberately, weighing where things come from and who supplies them, and procurement becomes one of the cheapest and least disruptive ways you have to cut risk across the estate.

None of this calls for a revolution. Treat sourcing as the security job it now is, put a few sensible controls in place and stick to supply routes you can trust and prove. Businesses without the supplier reach or spare hands to do this on their own can hand it to a sourcing partner, who closes the gap without adding cost or complexity and turns procurement from a hidden risk into something you control.

If your organisation is buying technology without a clear view of where it comes from or how its suppliers are run, it is worth looking hard at how those calls get made before the next refresh comes round. The team at Contrac IT Support offers enterprise IT sourcing and security guidance to UK businesses that want procurement working for their security rather than against it.

FAQ

Frequently Asked Questions

N

Written by Nicola, Editorial Team at Contrac.

Share this article:
Next Steps

Make Procurement Work for Your Security

If your organisation is buying technology without a clear view of where it comes from or how its suppliers are run, the Contrac IT sourcing team can help. Talk to us about security-aware sourcing and what a structured, vetted supply chain could look like for your business.

Discover Contrac IT Sourcing