Building a resilient supply chain

Ensuring the resilience of your supply chain is critical in today’s volatile business environment. Dan Norman, ISF Regional Director, EMEA, explores the steps that are needed to monitor the risks associated with your supply chains.

In today’s interconnected global economy, supply chains are more complex and vulnerable than ever before. Disruptions to the supply chain can have a devastating impact on businesses, from production delays and financial losses to reputational damage. Ensuring the resilience of your supply chain is critical in today’s volatile business environment. One of the most crucial aspects of building a robust supply chain is effectively assessing and mitigating the risks associated with your suppliers. This involves a comprehensive evaluation of potential threats, including cybersecurity vulnerabilities, geopolitical risks, and social and environmental concerns.

It is impossible to operate a business without having a supply chain. In the increasingly globalised environment, suppliers help to keep daily operations moving in every organisation. But this also introduces cyber risk: supplier vulnerabilities are an increasingly common cause of compromise. Keeping a watchful eye on the security status of suppliers – always knowing the risk they present – is an important part of building resilience and maintaining operations.

Navigating the tangled web

Supply chains are often huge and complex – better described as a tangled web than a chain. In addition to their own customers, large organisations have multiple thousands of suppliers, who in turn have their own suppliers, and so forth. Moreover, the growth of services and technologies such as cloud computing and the Internet of Things (IoT) means that organisations have more suppliers connected directly to their systems and information than ever before. High profile incidents such as the spread of the NotPetya malware in 2017 demonstrate the devastating impact that can be caused by supplier vulnerabilities.

Regulations such as NIS2, DORA and PDPL have put a significant focus on managing cyber risk across an organisation’s supply chain; and unfortunately, every organisation is on a different level in their maturity journey. There is an incredible amount to consider when building a robust supply chain risk management capability: how do we integrate security requirements into existing and future contracts? How do we classify our suppliers in terms of criticality to the business, or potential impact to us if they are compromised due to a cyber attack? How do we risk-assess our suppliers? How do we continuously monitor them to provide assurance to the business that they are secure? Do we have the right tools in place to accelerate the entire process of effective supply chain cyber risk management? And the list goes on.

Security assessments

The large number of suppliers that organisations work with makes it challenging to regularly assess each one individually. Security assessments are often static snapshots that are rarely updated and do not reflect how quickly the information risk landscape changes, as new threats emerge and existing ones evolve. Without a continuous view of supplier security, businesses cannot fully understand the risks they face.

Continuous supply chain assurance means being able to present owners and decision makers with up-to-date information and evidence on the security of suppliers. It requires an understanding of which suppliers present the greatest risk, on which to focus monitoring; flexibility to use a range of different tools and techniques to more regularly assess supplier security; the adoption of automation to enable continuous reporting.

For many companies, moving to a pattern of continuously monitoring supplier security is likely to be a significant challenge. It will require a shift in focus from infrequent point-in-time assessments to more regular data capture throughout the relationship with any given supplier. There are no one-size-fits-all solutions on how to continuously monitor supplier security and every acquirer should adopt a way of working that meets their own requirements. However, there are a variety of tools and techniques that any acquirer may choose to make use of:

Open Source Intelligence (OSINT) – information that can give an indication of a supplier’s security posture.

Security ratings – services that automate the collection and analysis of OSINT to provide a data-driven assessment of an organisation’s technical security performance.

Information sharing mechanisms – a mixture of techniques for suppliers to share information directly with acquirers, and industry groups that enable acquirers to share information with each other in relation to common suppliers.

Supplier security self-assessments – questionnaire-based assessments used by acquirers, asking suppliers to assess their own security arrangements.

Security certifications – certification of systems and security controls against recognised national, international or industry-specific regulatory standards.

On-site security assessments/audits – assessments of a supplier’s security arrangements conducted by an acquirer’s employees or experts from an accredited third party, who have authorised access to the supplier’s premises.

Now, the reality is, an organisation will likely have thousands of suppliers, and assessing each supplier robustly using all of the above techniques is unrealistic and unmanageable. Suppliers must be classified into tiers of criticality and a monitoring capability must be integrated into a repeatable process, and refined over time. Many businesses may choose to outsource all of their supplier risk assessments to vendors that promise 100% coverage of a supplier’s vulnerabilities from OSINT, but this may not help in the long-run. A blended, pragmatic approach that considers a range of sources of information will provide sustainable and meaningful information to security leaders.

No Comments

Sorry, the comment form is closed at this time.

1