• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Five Ways to Secure the Supply Chain in Times of Conflict

Think Tank
Think Tank RSS FeedRSS

Five Ways to Secure the Supply Chain in Times of Conflict

May 22, 2022
Steve Durbin, SCB Contributor

Rising inflation, surging commodity prices, an uncertain economic recovery and an ongoing Russia-Ukraine crisis — the global economy has had a pretty rough start to 2022. Against such a volatile backdrop, supply chain companies face enormous risks and significant pressure in terms of business disruptions, security and safety of infrastructure, theft or loss of confidential data and a barrage of cybercrime including ransomware and other forms of malicious cyberattacks. Security researchers have identified at least four different types of “wiper malware” (malware that wipes systems and destroys information) unleashed during the Russian conflict. The truth is, our world simply cannot afford another NotPetya type of cyberattack known to result in catastrophic collateral damage and a level of disruption capable of erasing up to half a year’s worth of profit or more.

Because our global economy is so tightly interwoven, cyber fortifications must not happen in isolation. Instead, they must encompass the entire cyber ecosystem, including that of supply chain partners and other layers like sub-suppliers. Organizations and suppliers together must form a collective resilience that proactively neutralizes cyber risks as they manifest. So what can organizations do to help mitigate potential risks and be better armed?

Consistently review supplier inventories. A key foundation of any resilience strategy is to understand the extent of exposure a business has from its supply chain. Visibility is critical and hence organizations must keep up-to-date details of the exact nature of services being outsourced (e.g., software design and build), the type of products being built by suppliers (e.g., hardware and networking products) and their key geographical locations. Technology must be harnessed as a means to alert key personnel when any unforeseen change in supply chain inventories and processes occur.

Perform routine risk assessments. Supply chain environments are continuously evolving and thus it’s important that organizations have real-time status on their cyber risk profile across the entire ecosystem. Organizations must monitor a variety of risks including security, privacy, financial, quality and geopolitical risk to name a few. Start by prioritizing suppliers based on their criticality and geographical location, for example, suppliers that belong in high-risk territories and are most vulnerable to disruption. Place particular emphasis on recently terminated suppliers or ones that were recently acquired; this is where a number of undefined risks could exist. Monitor changes in supplier status (such as legal, financial, ownership, production) and evaluate if their responses fit their own specific needs such as regulatory obligations, risk tolerance and operating environment. Maintain a watchlist of suppliers that have had issues in the past or ones that have high-risk exposure.

Focus on high-risk — or undefined risk — suppliers. Threat actors are known to actively target key suppliers. Large organizations rely on hundreds of suppliers every day so it's probably a good idea to focus on ones that present the highest amounts of risk. Critical suppliers must ideally abide by equal cyber standards as that of the parent organization to achieve a uniform level of security. Start by documenting supply processes and procedures and ensure all key contacts are kept updated. Organizations may also choose to deploy monitoring tools such as open-source intelligence to ensure SSL certificates are up to date and can perform non-intrusive surface scanning. Push vendors to prioritize prompt remediation of software vulnerabilities. Implement initiatives and frameworks to assess supply chain security such as supply chain levels for software artifacts (SLSA) and software bill of materials (SBOM).

Implement a process for terminating suppliers. Last year, 30% of businesses terminated partnerships with third-party vendors due to unacceptable cyber risks attached to them. In case a political or business decision is made to cease business operations in a particular territory, ensure that the supplier is terminated keeping security in mind. This includes deleting all information using data sanitation techniques, removing all physical and network access and revoking all user-access privileges including cloud-based shared data.

Practice your incident response plan. Always be prepared for a scenario where a key supplier is impacted or needs to be isolated especially during times of instability. Create workshops using various scenarios and run tabletop cybersecurity exercises with both internal stakeholders and suppliers. Establish protocols for vulnerability and incident notification with supply chain partners. Create collaborative roles, structures and processes for incident response in the supply chain. Collaborate on lessons learned and fine-tune joint processes as needed. Offer mentoring and coaching to improve their cybersecurity best practices and support them in developing their own incident response mechanisms.

The reality is that supplier disruptions are nothing new and the pendulum of instability will always swing back and forth. Certainly, as more and more organizations embrace hyper-connectivity supplier cyber risks will only intensify. For businesses to become resilient to volatility and disruptions, they must invest in a proactive process that identifies supplier risks throughout the entire lifecycle, from acquisition to termination. As John Locke once famously quipped: “The only defense against the world is a thorough knowledge of it.”

Steve Durbin is chief executive officer of the Information Security Forum.

Technology Data Management (Big Data/IoT/Blockchain) Sourcing/Procurement/SRM Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • A pair of hands reaches towards a cluster of icons showing global logistics network distribution and transportation

    CSCMP's State of Logistics Report: Get Used to the Fog

    Logistics
  • A GROUP OF NINE PEOPLE STAND SMILING IN A ROW IN THE SUNSHINE BENEATH A SIGN SAYING PORT OF LOS ANGELES

    Transportation Secretary Announces American Supply Chain Sovereignty Initiative

    Global Gateways
  • Ebook_TransformingSupplyChain_thumbnail.jpg

    Transforming Your Supply Chain From Cost Center to Growth Driver

    Forecasting & Demand Planning
  • TWO WORKERS DISCUSS DATA SHOWN ON COMPUTER SCREENS

    Gartner: Gap in SC AI Talent Cannot Be Closed by Hiring Alone

    Artificial Intelligence
  • GOVERNANCE SCRUTINY RISK MANAGEMENT ASSESSMENT iStock-champpixs-1465316262.jpg

    Supply Chain Resilience Is Now a Board Governance Imperative

    Supply Chain Finance & Revenue Management

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing