Managing Supply Chain Cyber Risk

In highly connected industrial ecosystems, managing the supply chain landscape requires adapting traditional approaches to cyber risk.

A hyper-connected world helps companies increase transparency to mitigate the physical disruption of goods. But it also opens them up to a potential digital weakness that poses another kind of disruption โ cyber risk.
Lessons from the recent pandemic have accelerated digital adoption. This is now changing the security paradigm in the short to medium term. In particular, the adoption of new technologies to help drive efficiencies across the industrial sector is leading to more complicated IT ecosystems that are, in some cases, heavily integrated with partners, alliances and suppliers. This grey area of potential risk falls outside the traditional good practice guidelines leaders have come to know well. Manufacturers, distributors, and other industrial organizations must now adapt their methods and approaches to identify and manage this new cyber risk vector.
The Impact of an Interconnected World
As traditional corporate boundaries become increasingly blurred, expanding deep into the supplier landscape, trying to track who does what, and when, with data is a growing challenge. Organizations are now faced with an increased exposure presenting many unknown risks, potentially impacting daily operations.
This is a problem for the total supply chain. If one operation is hacked, all are at risk. The rise of e-commerce and non-store retailing within consumer, manufacturing, and distribution is placing huge demands on technology-driven solutions to streamline operations. To keep track of real-time stock levels, tracking software allows for improved accuracy over end-to-end manufacture to delivery to the customer. It requires non-stop communication between partners at each step, with different software systems managing the flow interdependently. Add to that the numerous back-office partners that support payroll, or settlement, or host IT systems. All of these functions require new approaches to managing risk.
Breaches in security can erode market value and damage brand reputation. The attack in 2020 on SolarWinds and the Florida-based IT company Kaseya spread through 200 corporate networks that used its software. The failure to appreciate risk in the overall end-to-end system had a significant material impact on their operations, highlighting the need to re-address the approach to risk management and look wider than an organizationโs own corporate domain. Smaller companies are equally at risk. In 2021, 40 percent of ransomware victims had less than 100 employees,

Carl Nightingale is a Partner and Cyber Security Expert at PA Consulting.

.