• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Navigating Supplier Risk Challenges to Shore Up Cyber Defenses

Think Tank
Think Tank RSS FeedRSS

Navigating Supplier Risk Challenges to Shore Up Cyber Defenses

SYMBOLS OF TRADE AND RISK HOVER OVER TWO HANDS TYPING ON A KEYBOARD

Image: iStock.com/Thapana Onphalai

May 30, 2023
Steve Durbin, SCB Contributor

Organizations are paying too little attention to the risk of their supply chain information being compromised through cyberattack.

Solarwinds, Log4J, Kaseya, and just recently 3CX, are just a few examples of instances where companies failed to fully assess the risk profile of their supplier relationships. Following are some key challenges that need to be addressed.

Pressure to cut external costs. Hampered by budget constraints, organizations are under pressure to seek services from suppliers that can offer “more for less.” Even the most well-established suppliers tend to move toward cost-cutting measures, potentially at the expense of information security.

Infrastructure stretched by remote work. Remote working is nothing new, and the associated risks are fairly well known. Still, a majority of businesses are relying on it at an unprecedented scale. Meanwhile, the business infrastructure, and the suppliers that enable it, are being stretched to near breaking point. At a time where cyber risk is at an all-time high, and attack vectors are growing exponentially, organizations are in need of more agile approaches to infrastructure integrity, with the ability to promptly diagnose and address risk in the supply chain.

Supply chain risk management lacking structure. A recent ransomware attack on a major supply chain partners caused semiconductor giant Applied Materials to lose $250 million. Such incidents remind us that while companies may have become better versed at managing operational risk, their ability to manage information risk from a supply-chain perspective is often poor or questionable. Supplier relationships usually represent a soft underbelly that can cause considerable damage to any business in the event of unexpected disruptions.

Traditional approaches to supply chain security failing. Many suppliers feel the frustration of filling out lengthy security questionnaires from prospective or existing partners, when information interchange or shared system access is only likely to be minor. This results in inefficiencies in both the supplier and partner organizations. A “one-size-fits-all” approach exposes organizations to greater security risks because it lacks the ability to prioritize the most sensitive and critical suppliers.

Suppliers struggling to keep up with innovative organizations. Business strategies and operating models were upended by the COVID-19 pandemic. Many organizations responded by accelerating their innovation and marketing capabilities. While they may be able to flex their own culture and in-house security measures to cope with increased web-enablement and remote working, their suppliers may struggle to keep pace without dropping a cybersecurity ball or two.

The following best practices can help organizations manage risk in their supply chains more effectively.

Make information security business as usual, not an afterthought. The key to overcoming supplier risk is embedding information security across the entire supplier management lifecycle — from the time when supplier requirements are defined to when contracts are renewed, renegotiated or terminated. Collaborate with legal and procurement teams so that risk‐based requirements are reflected in supplier contracts. Consult information security teams at every step in the process.

Categorize and prioritize suppliers based on risk. Triage vendors based on what level of information and systems the supplier has access to. Next, try to understand the level of exposure the organization has with this particular supplier. In the case of software suppliers, identify individual components and software dependencies by creating a software bill of materials (SBOM). If suppliers are deemed to be critical, perform thorough due diligence: Where do they operate from? What are their capabilities? What security processes do they have in place? Do they have a history of security incidents? Are they compliant with security and privacy standards?

Build a process for ongoing assurance. A one-off, point-in-time assessment is no longer sufficient when it comes to effective supplier risk management. Ideally, organizations should have a monitoring and reporting process in place to identify whether the risk profile in an individual supplier relationship is changing. For example, any changes in legal, financial, partnership or ownership status, or security incident, should trigger a reassessment of supply chain exposure and subsequent risks. 

Continue to monitor and fine-tune. Review the entire supply chain lifecycle from a security standpoint annually at least. Identify priority actions, determine issues and implement any controls, systems, process or automation that are necessary to reduce supply chain risks ahead of time.

The writing’s on the wall. Supply chain attacks have grown by more than 700% over the past three years, and are likely to further increase. To build resilience against supply chain risks, organizations must build smarter supplier risk-management profiles and follow guidelines that serve as an enabler to ongoing business success, rather than a barrier. 

Steve Durbin is chief executive of the Information Security Forum.

Supply Chain Visibility Regulation & Compliance Supply Chain Security & Risk Mgmt Supply Chains in Crisis

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • On Demand - Webinar Descartes Tue Jun 23 2026 11a ET.png

    Descartes AI Exchange: AI Agents for Fleet Performance Management

    General SCM
  • A UNIFORMED OFFICER STANDS NEAR A HIGHWAY WITH TRUCKS ON IT

    U.S. Customs Ramps Up AI Investment in Push to Sharpen Enforcement

    Artificial Intelligence
  • On Demand Webinar - Arkieva - Wed Jun 24 2026 2p ET.png

    Shift Left Planning: Why Many Plans Fail to Execute—and How to Fix It

    Webinars
  • A MAP OF THE STRAIT OF HORMUZ SHOWING DOZENS OF BLUE DOTS DISTRIBUTED THROUGHOUT THE WATERWAY

    Traffic Flows Through Hormuz Despite Shock Ship Attack

    Global Gateways
  • Satellite view of the Strait of Hormuz with white graphic lines representing global shipping lanes and maritime traffic between the Persian Gulf and Gulf of Oman.

    Hormuz Highlights How Maritime Risk Assessment Needs to Change

    Global Gateways

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing