Back to Articles
Third-Party Risk

Who Funds Your Suppliers? A CISO's View of MI5's CGTRI Warning

By Asaf Levy5 min read

Updated and fact-checked:

Executive Answer

For a critical supplier, I want to know who owns it, who can influence its decisions, and what it can access in the business. MI5's warning about research funding through CGTRI is a reason to revisit those questions. The business recommendations below are my assessment of the lesson for supplier risk management.

What MI5 actually reported

On September 30, 2026, MI5 issued an espionage alert about the China General Technology Research Institute (CGTRI). It said CGTRI funds research in China, including AI and cybersecurity, to improve the Ministry of State Security's technical espionage capabilities.

According to MI5, more than 100 UK-linked academics contributed to projects funded by the MSS through CGTRI. Some may not have known about that funding. The distinction matters: this describes funding of research to which academics contributed, rather than academics knowingly financing intelligence operations.

The alert concerns academic collaboration. It does not establish that a particular commercial supplier is compromised. Applying its lesson to business requires looking at the facts of each relationship.

Why I would bring this into a supplier review

A supplier can explain its encryption, access controls, and incident response process in detail. I still want to understand who can influence the company behind those controls. That could affect decisions about data access, subcontractors, product development, or where a service is delivered.

There is a relevant US reference. In its March 2024 guidance for critical infrastructure leaders, CISA recommends identifying and managing foreign ownership, control, or influence in supplier and partner relationships. I would use that as a due diligence consideration, with the depth of the review matched to the supplier's role.

Foreign investment alone does not establish a threat. An unclear funding structure is a reason to ask more questions. I would look for evidence of influence and consider what the supplier could actually affect before recommending a restriction or a change.

The review I would start with

Start with a small group of suppliers that have privileged access, handle sensitive information, or support a service the business cannot easily lose. For each one, I would ask the person responsible for the relationship to work through these points with procurement and security:

  1. Confirm the company behind the contract. Identify the legal entity, parent company, and controlling owners. Use company records and supporting documents, and record what could not be verified.
  2. Understand relevant funding relationships. Ask whether investors, grants, or strategic partners have rights that could influence operations or access to information. Bring in legal advice where those arrangements need interpretation.
  3. Check the access that exists today. Include support accounts, integrations, shared research, and subcontractors. Compare the access with what the supplier needs to provide the service.
  4. Decide who acts when something changes. Agree how ownership changes, new subcontractors, or credible security alerts reach the business owner. Set a review date and document any limits or follow-up work.

The useful output is a decision with a named owner. That may mean continuing the relationship, reducing access while a question is investigated, or preparing an alternative supplier. The response should follow the evidence and the business impact.

Asaf's Take

For the next management discussion, I would bring one critical supplier and ask the person responsible to explain who is behind it, what access it has, and what remains unclear. A focused review gives management a concrete decision to make. It also shows the team where its supplier records need work.

Questions about supplier due diligence

What did MI5 say about CGTRI?

MI5 said CGTRI funds research that improves the Chinese Ministry of State Security’s technical espionage capabilities. More than 100 UK-linked academics contributed to projects funded through CGTRI. MI5 said some may not have known about that funding.

Does unclear supplier funding prove a security threat?

No. Missing information calls for further due diligence. Assess the available evidence alongside the supplier’s access, its influence over important services, and the consequences if the relationship fails.

Where should a supplier ownership review start?

Start with suppliers that can access sensitive information or disrupt an important service. Confirm the legal entity, ownership and control, relevant funding relationships, access permissions, and who will review changes.

Sources

Discuss your supplier risk priorities

If you want to work through where to start, book a 30-minute introductory call with me. The call is free and carries no obligation; it is a conversation about your needs, not a technical assessment.

Book an introductory call