A new report from McKinsey & Company sheds light on something we’ve known for many years – organizations are struggling to make significant progress in managing cybersecurity risk in their supply chains.
A key issue is that the risk landscape has changed dramatically in recent years. Historically, the C-suite and board of directors have been concerned with long-acknowledged third-party risks such as quality issues, compliance violations, management changes, and bankruptcy. Today, globalization and an increasingly interconnected supply chain have broadened the risk landscape to encompass new threats. Indeed, just this week, Quest Diagnostics, one of the biggest blood testing providers in the country, warned that nearly 12 million of its customers may have had their financial and medical information breached due to an issue with one of its vendors.
In the wake of these new liabilities, it’s becoming increasingly apparent that organizations must move the needle on supply chain risk management. The question is how?
You don’t know what you don’t know
Key to any progression on this issue is knowing what you’re dealing with. However, as the McKinsey report finds, most organizations don’t know where to start.
Unfortunately, achieving transparency into the security posture of hundreds or thousands, of suppliers in a single supply chain is hard to achieve. Organizations must also contend with proprietary data restrictions. Some vendors, particularly Tier 1 or 2 suppliers, may not want an end customer poking around in their supply chain network looking for indications of cyber risk.
The scope and scale of risk is also incredibly complex. IT and security teams can quickly become overwhelmed as they scramble to ascertain a vendor’s security rigor. Yet without this insight, it becomes impossible to address, quantify, and mitigate cyber risk.
Like a credit score for your vendor’s security posture
You need insights to be presented in an easy-to-understand manner and backed by data that correlates to potential security incidents and context. Security ratings can be highly effective in identifying risky vendors and potential supply chain vulnerabilities. These ratings can help you streamline contingency planning and put procedures in place to protect your organization from an attack or breach in your supply chain.
Security ratings are the cybersecurity equivalent of a credit score. Just as lenders view credit scores to grade how responsibly an individual manages their financial obligations over time, CISOs can use security ratings to quickly and easily communicate the scale and severity of a risk in the supply chain to a non-technical audience in the C-suite, boardroom, or with the vendor in question. Using this high-level, objectively-derived data can simplify the conversation around risk.