Case Study

Scaling supply chain security assurance for Gas Networks Ireland

A Busines professional using a laptop.
  • Case Study
  • 5 minute read
  • July 22, 2026

Gas Networks Ireland needed deeper visibility across supplier cyber risk. PwC helped scale its third-party risk programme from limited annual reviews to more than 50 supplier assessments a year.

Industry

Energy

Our role

DORA compliance

Services

Business Transformation

Leonard McAuliffe

Leonard McAuliffe

Partner, PwC Ireland (Republic of)

Gas Networks Ireland needed to strengthen supply chain security assurance in line with its NIS2 obligations. PwC helped deliver a managed third-party risk assessment service that increased assessment depth, expanded supplier coverage, and gave leadership clearer visibility of risk.

The challenge

As Ireland’s national gas network operator, Gas Networks Ireland (GNI) is classified as an operator of essential services under the NIS2 Directive. That classification brings clear obligations to manage supply chain security risk, including the need to assess the security posture of essential and important suppliers.

Before the engagement, GNI was conducting a limited number of third-party risk assessments each year. This gave the organisation some visibility, but not at the depth or scale needed across its supplier base. The issue was not only operational. It also carried regulatory significance, as GNI needed to demonstrate compliance with the NIS2 requirements relating to supply chain security.

Limited assessment coverage meant GNI had an incomplete view of supplier-level vulnerabilities, incidents, or weaknesses that could affect its critical national operations and services. The organisation needed a more comprehensive and repeatable approach. It wanted to move beyond point-in-time assessment and create an ongoing programme that could identify, track, and remediate third-party risk in a structured way.

Our solution

PwC was engaged to deliver a fully managed third-party risk assessment service for GNI. The service took ownership of the end-to-end assessment lifecycle, from vendor engagement and questionnaire delivery through to evidence review, risk identification, remediation tracking and continuous monitoring.

The managed service was selected through a competitive tendering process. GNI needed to scale its programme quickly and consistently, while maintaining the depth required to support its NIS2 supply chain security obligations. PwC’s approach helped GNI increase capacity and apply a consistent methodology across its supplier base.

The programme was built around four core components:

  1. Detailed supplier assessments: Suppliers are assessed using a comprehensive questionnaire covering 17 security domains, including access control, asset management, compliance, cloud security, third-party risk management, network security, and incident response.
  2. Risk identification and remediation: Findings are documented with risk ratings and treatment plans. They are tracked through to remediation or acceptance in collaboration with GNI’s contract managers and the relevant third parties.
  3. Continuous monitoring: PwC deployed a cybersecurity ratings platform across GNI’s supplier base, providing an additional layer of visibility between assessment cycles.
  4. Phased scaling: The programme is being expanded gradually, with volumes increasing year-on-year to balance coverage, quality, and manageability.

The work began with an initial cohort of suppliers selected by GNI based on their criticality to operations and services. PwC managed the assessment process for each supplier and worked with GNI relationship and contract managers to support engagement where supplier responsiveness required additional follow-up.

The results

The programme has helped GNI move from a limited annual assessment model to a broader, more structured and scalable approach to supply chain security assurance.

The most tangible change is the increase in assessment coverage. GNI has moved from five to six assessments per year with limited depth to a comprehensive programme covering more than 50 suppliers annually across 17 security domains.

Key outcomes include: 

  • Supplier coverage has increased year-on-year.

  • Each supplier is assessed across organisational and project-level controls.

  • Risks are being identified, rated, and tracked through structured treatment plans.

  • Active remediation is underway across the supplier base.

  • Continuous monitoring has been deployed through a cybersecurity ratings platform.

  • GNI now has clearer visibility of supplier security posture between assessment cycles. 

The programme has also supported broader business outcomes. It has strengthened structured engagement with suppliers on security matters, helped GNI’s contract managers drive improved contractual protections and provided leadership with greater confidence that supply chain risks are being actively managed in line with NIS2 obligations.

As the programme matures, GNI has established a baseline understanding of supplier security posture that can support reassessments, onboarding of new suppliers, and measurement of improvement over time.

Lessons learned

The engagement shows that supply chain security assurance needs both scale and discipline. For organisations with large or complex supplier networks, a limited number of annual assessments may not provide enough visibility to meet rising cyber and regulatory expectations.

A consistent methodology was important. Assessing suppliers across the same 17 security domains helped GNI build a more comparable view of risk across the supplier base. Clear risk ratings and treatment plans also helped convert assessment findings into action.

Supplier engagement needed active management. Some third parties were slower to respond or provide evidence, which required regular follow-ups, clarification calls, and support from GNI contract managers. That relationship-led approach helped reinforce the importance of participation without making the process adversarial.

The programme also underlines the value of continuous monitoring. Point-in-time reviews remain important, but ongoing visibility can help organisations identify emerging risks sooner and support more timely conversations with suppliers.

Conclusion

GNI’s managed third-party risk programme has created a more scalable and structured approach to supply chain security assurance. By increasing supplier coverage, deepening assessments, and introducing continuous monitoring, the organisation now has a clearer view of third-party cyber risk and a more consistent way to manage remediation.

The work supports GNI’s NIS2 supply chain security obligations and gives its management body greater visibility of how risks are being identified and addressed. It also provides a repeatable framework that can evolve as the supplier base changes, new suppliers are onboarded, and reassessments are carried out.

For other essential service operators, the lesson is clear: supply chain security is not a one-off exercise. It needs governance, consistency, supplier engagement, and a model that can scale.

“PwC’s third-party risk management service has provided Gas Networks Ireland with a level of depth, structure, and consistency that we could not have achieved in-house at the scale required. The quality of the assessments, combined with regular engagement and review sessions, has materially improved our understanding of supply chain risk and our ability to act on it.”

Alan Grainger,Head of Data at Gas Networks Ireland

We’re here to help you

If your organisation depends on a complex supplier network, third-party cyber risk can quickly become a governance, operational and regulatory issue. PwC can help you assess your current approach, strengthen supplier assurance, and build a scalable programme that supports ongoing risk visibility. To discuss third-party risk management, supply chain security, or NIS2 readiness, contact our team or explore our services.

Managed Services

Run faster, scale smarter, lead stronger.

Cyber Managed Services Centre

Manage cyber risks in an increasingly complex world.

Follow PwC Ireland

Contact us

Leonard McAuliffe

Partner, PwC Ireland (Republic of)

John Fitzgerald

Senior Manager, PwC Ireland (Republic of)

Michelle O’Leary

Manager, PwC Ireland (Republic of)

Hide