• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Beyond the Headlines: The Many Forms of Modern-Day Cyber Disruption
SCB FEATURE

Beyond the Headlines: The Many Forms of Modern-Day Cyber Disruption

A GLEAMING MATRIX OF LIGHTED COLORED LINES FLOWS INTO THE DISTANCE

Image: iStock/piranka

October 21, 2024
Robert J. Bowman, SupplyChainBrain

The biggest threats to supply chain cyber resilience aren’t necessarily the ones that grab the biggest headlines.

Cybersecurity failures were definitely in the news in 2024, but the year’s most serious issue — the outage at security vendor CrowdStrike, which affected millions of Windows systems around the world — wasn’t the result of a intentional attack, notes Kayne McGladrey, senior member of the Institute of Electrical and Electronics Engineers (IEEE). It was caused by a flaw in an update of the CrowdStrike software. Yet it cost a wide range of companies, including airlines, public transit, healthcare and financial services, an estimated $5.4 billion.

The upside of the event is that it motivated companies to reevaluate their most trusted security vendors and re-assess the resilience of their supply chain systems, McGladrey says. “It caused them to start having meaningful conversations about the risks of business interruptions associated with a key supplier having a substantial outage."

Some businesses affected by the CrowdStrike outage fared better than others. Delta Airlines, for one, was forced to cancel thousands of flights, resulting in lawsuits being filed against the airline by affected passengers, and by Delta against CrowdStrike.

Other organizations, by contrast, proved to be “fairly resilient” in the face of the outage, Kayne McGladrey says, thanks to having previously “tested and workshopped their business-continuity plans.”

“It was a good lesson learned for organizations of all sizes,” he adds, proving that threats to cyber resilience don’t always come from the bad actors that garner the most media attention.

Even where an intentional attack is involved, the headlines don’t always reflect the most likely threat. “We focus on ransomware because it’s big and noisy,” McGladrey says. Yet e-mail scams known as “pig butchering,” in which victims are enticed by fraudsters to pay out large amounts of money over extended periods of time, make up a larger volume of incidents.

McGladrey says supply chain risk ranked third on many companies’ cyber-resilience “radar” in 2024. Thanks in large part to an earlier incident, the hacking of the IT management platform SolarWinds in late 2020, there was already a “remarkable focus” on improving supply chain security, resulting in a significant decline in breaches.

Which doesn’t mean it’s time for companies to take their eyes off the ball. On the contrary, McGladrey says, cyber thieves learned from the CrowdStrike incident how easy it was to compromise vendors through the insertion of bad code. And ransomware remains a serious problem, threatening the data and everyday operations of private and public organizations the world over.

McGladrey says it’s crucial that businesses undertake a detailed risk assessment of every vendor and supplier with which they work. In each case, they should have a keen sense of how their software and hardware systems would be impacted.

Companies need to pose a series of vendor security questions, or VSQs, that elicit precisely what a given supply chain partner is doing to protect itself from cyberattack. In essence, they should be applying the same level of diligence to every supplier relationship that is already mandated by the federal government in its own procurement guidelines. The Biden Administration’s Executive Order 14028, issued in May, 2021, requires that all prospective sellers of software to the government provide a detailed bill of materials for the product in question.

Similar requirements are emerging in the states as well. New York’s Department of Financial Services, for one, requires that security measures be imbedded into contracts with third-party suppliers that are storing or processing customers’ data.

The actual level of awareness by companies of the need to be super-resilient against cyber disruption depends on each organization’s level of maturity toward managing risk at the business level, McGladrey says. Those that see cybersecurity as a cost center, lacking strategic alignment within the organization as well as with outside partners, are more vulnerable. “If an organization has a low maturity attitude and tends to be fairly reactive, it’s going to continue to struggle to have adequate cyber risk,” he says.

Some industries are more “mature” than others in this sense, driven by the inherent requirements of their business. Healthcare, for example, already must generate a wealth of information about its supply chain to satisfy regulators. As a result, McGladrey says, “they can tell you by the nickel how much a data breach costs them.” Other industries such as construction are less advanced in compiling the necessary data to convince top executives and boards of directors of the need for a substantial investment in cyber resilience.

The coming year will bring “a continued permutation” of cyberattacks, driven by such factors as geopolitical strife, attacks by hostile nation states, the growing sophistication of generative artificial intelligence, and ever-present criminal enterprises that lack a “western philosophy of ethics,” McGladrey says. Which means that businesses must adopt a hyper-vigilant approach to cybersecurity that considers every type of incident that can bring operations to a halt, and compromise sensitive data, whether the result of hostile action or Murphy’s Law.

“Companies are going to need to really focus on what are those risks that affect their business, and how can they minimize them most effectively,” McGladrey says.

    RELATED CONTENT

    RELATED VIDEOS

    Supply Chain Visibility Regulation & Compliance Supply Chain Security & Risk Mgmt
    • Related Articles

      Birkenstock CEO Accuses Amazon of 'Modern-Day Piracy'

      Podcast | Connecting the Dots: The Role of the Modern-Day Warehouse Execution System

    Robert J. Bowman, SupplyChainBrain

    Watch: How eGourmet Solutions Scaled Order Management to Meet Rapid Growth

    More from this author

    Subscribe to our Daily Newsletter!

    Timely, incisive articles delivered directly to your inbox.

    Featured Product

    Popular Stories

    • A LARGE CYLINDRICAL OBJECT SHRINK-WRAPPED IN WHITE PLASTIC IS LOWERED BY CRANE ONTO A FLAT BED TRUCK ON A DOCK

      AI Boom Has European Buyers Paying Extra to Secure Gas Turbines

      Technology
    • 016_ai_and_data_transformation_in_distribution_v1-(540p).png

      Watch: AI and Data Transformation in Distribution

      Artificial Intelligence
    • DOMINO EFFECT FINANCIAL MONEY KNOCK-ON CONSEQUENCES iStock-Devrimb-1500012566.jpg

      Podcast | The Tariff Conundrum for Supply Chains: Pass Along, or Absorb?

      Supply Chain Finance & Revenue Management
    • A GROUP OF NINE PEOPLE STAND SMILING IN A ROW IN THE SUNSHINE BENEATH A SIGN SAYING PORT OF LOS ANGELES

      Transportation Secretary Announces American Supply Chain Sovereignty Initiative

      Global Gateways
    • Ebook_TransformingSupplyChain_thumbnail.jpg

      Transforming Your Supply Chain From Cost Center to Growth Driver

      Forecasting & Demand Planning

    Digital Edition

    2026 esg cover main scb q2 2026 cover

    SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

    VIEW THE LATEST ISSUE

    Case Studies

    • Recycled Tagging Fasteners: Small Changes Make a Big Impact

    • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

      Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

    • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

      Moving Robots Site-to-Site

    • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

    • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

    Visit Our Sponsors

    4flow Arkieva Blue Yonder
    Carton Cloud CoEnterprise Dassault
    Duravant E2Open General Logistics Systems
    Hy-Tek iGPS Korber
    Lyngsoe Procurability Quinyx
    SAP Sikick Systech
    S&P Global Mobility TADA TransImpact
    US Bank Werner Enterprises WSI
    • More From SCB
      • Featured Content
      • Video Library
      • Think Tank Blog
      • SupplyChainBrain Podcast
      • Whitepapers
      • On-Demand Webinars
      • Upcoming Webinars
    • Digital Offerings
      • Digital Issue
      • Subscribe
      • Manage Email Preferences
      • Newsletters
    • Resources
      • Events Calendar
      • 2026 Event Coverage
      • SCB's Great Supply Chain Partners
      • Supplier Directory
      • Case Study Showcase
      • Supply Chain Innovation Awards
      • 100 Great Partners Form
    • SCB Corporate
      • Advertise on SCB.COM
      • About Us
      • Privacy Policy
      • Contact Us
      • Data Sharing Opt-Out

    All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

    Design, CMS, Hosting & Web Development :: ePublishing