Industry
Energy
Our role
DORA compliance
Services
Business Transformation
Gas Networks Ireland needed to strengthen supply chain security assurance in line with its NIS2 obligations. PwC helped deliver a managed third-party risk assessment service that increased assessment depth, expanded supplier coverage, and gave leadership clearer visibility of risk.
As Ireland’s national gas network operator, Gas Networks Ireland (GNI) is classified as an operator of essential services under the NIS2 Directive. That classification brings clear obligations to manage supply chain security risk, including the need to assess the security posture of essential and important suppliers.
Before the engagement, GNI was conducting a limited number of third-party risk assessments each year. This gave the organisation some visibility, but not at the depth or scale needed across its supplier base. The issue was not only operational. It also carried regulatory significance, as GNI needed to demonstrate compliance with the NIS2 requirements relating to supply chain security.
Limited assessment coverage meant GNI had an incomplete view of supplier-level vulnerabilities, incidents, or weaknesses that could affect its critical national operations and services. The organisation needed a more comprehensive and repeatable approach. It wanted to move beyond point-in-time assessment and create an ongoing programme that could identify, track, and remediate third-party risk in a structured way.
PwC was engaged to deliver a fully managed third-party risk assessment service for GNI. The service took ownership of the end-to-end assessment lifecycle, from vendor engagement and questionnaire delivery through to evidence review, risk identification, remediation tracking and continuous monitoring.
The managed service was selected through a competitive tendering process. GNI needed to scale its programme quickly and consistently, while maintaining the depth required to support its NIS2 supply chain security obligations. PwC’s approach helped GNI increase capacity and apply a consistent methodology across its supplier base.
The programme was built around four core components:
The work began with an initial cohort of suppliers selected by GNI based on their criticality to operations and services. PwC managed the assessment process for each supplier and worked with GNI relationship and contract managers to support engagement where supplier responsiveness required additional follow-up.
The programme has helped GNI move from a limited annual assessment model to a broader, more structured and scalable approach to supply chain security assurance.
The most tangible change is the increase in assessment coverage. GNI has moved from five to six assessments per year with limited depth to a comprehensive programme covering more than 50 suppliers annually across 17 security domains.
Key outcomes include:
Supplier coverage has increased year-on-year.
Each supplier is assessed across organisational and project-level controls.
Risks are being identified, rated, and tracked through structured treatment plans.
Active remediation is underway across the supplier base.
Continuous monitoring has been deployed through a cybersecurity ratings platform.
GNI now has clearer visibility of supplier security posture between assessment cycles.
The programme has also supported broader business outcomes. It has strengthened structured engagement with suppliers on security matters, helped GNI’s contract managers drive improved contractual protections and provided leadership with greater confidence that supply chain risks are being actively managed in line with NIS2 obligations.
As the programme matures, GNI has established a baseline understanding of supplier security posture that can support reassessments, onboarding of new suppliers, and measurement of improvement over time.
The engagement shows that supply chain security assurance needs both scale and discipline. For organisations with large or complex supplier networks, a limited number of annual assessments may not provide enough visibility to meet rising cyber and regulatory expectations.
A consistent methodology was important. Assessing suppliers across the same 17 security domains helped GNI build a more comparable view of risk across the supplier base. Clear risk ratings and treatment plans also helped convert assessment findings into action.
Supplier engagement needed active management. Some third parties were slower to respond or provide evidence, which required regular follow-ups, clarification calls, and support from GNI contract managers. That relationship-led approach helped reinforce the importance of participation without making the process adversarial.
The programme also underlines the value of continuous monitoring. Point-in-time reviews remain important, but ongoing visibility can help organisations identify emerging risks sooner and support more timely conversations with suppliers.
GNI’s managed third-party risk programme has created a more scalable and structured approach to supply chain security assurance. By increasing supplier coverage, deepening assessments, and introducing continuous monitoring, the organisation now has a clearer view of third-party cyber risk and a more consistent way to manage remediation.
The work supports GNI’s NIS2 supply chain security obligations and gives its management body greater visibility of how risks are being identified and addressed. It also provides a repeatable framework that can evolve as the supplier base changes, new suppliers are onboarded, and reassessments are carried out.
For other essential service operators, the lesson is clear: supply chain security is not a one-off exercise. It needs governance, consistency, supplier engagement, and a model that can scale.
“PwC’s third-party risk management service has provided Gas Networks Ireland with a level of depth, structure, and consistency that we could not have achieved in-house at the scale required. The quality of the assessments, combined with regular engagement and review sessions, has materially improved our understanding of supply chain risk and our ability to act on it.”
Alan Grainger,Head of Data at Gas Networks IrelandIf your organisation depends on a complex supplier network, third-party cyber risk can quickly become a governance, operational and regulatory issue. PwC can help you assess your current approach, strengthen supplier assurance, and build a scalable programme that supports ongoing risk visibility. To discuss third-party risk management, supply chain security, or NIS2 readiness, contact our team or explore our services.
Run faster, scale smarter, lead stronger.
Manage cyber risks in an increasingly complex world.
Menu