Handling cyber risk in your organization’s supply chain isn’t easy. This aspect of Supply Chain Risk Management is a complex problem that even highly sophisticated organizations—like the Department of Defense—struggle to address.
But while finding a silver bullet solution to eliminate your organization’s supply chain vulnerabilities may be out of the question, managing those cyber risks is still possible.
Managing Cyber Risks To Your Supply Chain
Before we get to some solutions, it’s important to understand what cyber risk means to supply chain risk management.
Organizations have been managing risk to their supply chains for decades. Traditionally, this meant finding ways to limit the impact of extreme weather, fires, earthquakes, labor strikes, or other unforeseen hazards associated with running global business operations.
In recent years, the traditional concept of supply chain risk management has expanded to include cybersecurity and cyber risk. The need to incorporate cyber into supply chain risk management is clear: cyber incidents can affect the products or services upon which organizations rely, causing direct business harm.
Managing cyber risk to your supply chain is the process of identifying and mitigating cyber risks affecting the hardware, software, or services that you purchase, acquire, or use from third parties, in order to reduce the cyber risk of your own organization.
For instance, a cyber incident affecting an important manufacturing facility could result in machines being operationally disabled or the theft of sensitive intellectual property. A cyber incident affecting a critical software or hardware vendor could introduce new vulnerability into your organization.
Hardware & Software
Any company that sells a product using hardware or software knows how important it is to test products before they hit the market. But, that’s not always easy or possible. Most organizations outsource the creation of components for hardware and software, so they aren’t able to oversee the production process personally. So how do you gain confidence in your vendors’ development processes and have complete assurance that they’ve created the parts you need with good intentions in a secure facility? You don’t.
For example, let’s say I’m the president of a cell phone company. It’s less expensive for me to get my hardware—chips, wires, circuits, and other components—from a company overseas. As such, I do not oversee the production process of the hardware for my phones.
They are all sent to my production facility, where they are assembled. Again, I don’t oversee that process. The phones I create are smart phones, so once they’re on the market, I let third parties create applications and sell them to other phone users.
Since I don’t have a hand in creating these applications, how do I (and those who have purchased my phones) know that the developer hasn’t rigged the application to steal personal data and information from the phone’s owner?
All of these issues are called supply chain vulnerabilities, which are managed through supply chain risk management.
Overall Services
Aside from hardware and software, supply chain vulnerabilities also need to be managed for “overall services.” These services typically refer to companies that are working under contract for your organization,and have access to (or are interacting with) sensitive data. These companies are considered critical because they have a deep level of access into your organization’s networks, so they may pose a security threat.
For example, if I owned a large financial institution, I might have 15,000 vendors, but only 5,000 who were considered critical. I would take more caution with these critical vendors. Specifically, I would send out questionnaires, perform penetration tests, and use continuous monitoring tools to monitor real-time security incidents. I’d want to do everything I could to ensure my data was secured appropriately so my network wasn’t breached.