• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Aligning Procedures Across the Supply Chain is Critical to Cybersecurity

Think Tank
Think Tank RSS FeedRSS

Aligning Procedures Across the Supply Chain is Critical to Cybersecurity

A MAN IN A SUIT HOLDS A PHONE WITH A GRAPHIC OF THIN BLUE LINES HOVERING OVER IT

Photo: iStock.com/Arkadiusz Warguła

July 6, 2023
Roger Albrecht, SCB Contributor

Organizations go to great lengths to secure their data, systems and facilities from cyber-attack. But even the most secure enterprise can fall victim to a business partner that doesn’t apply the same standards to its operations.

Indeed, most cyber risk comes from third-party relationships. In a recent survey by CyberRisk Alliance Business Intelligence, 57% of respondents said they had experienced a breach or attack via their third-party providers. Almost four out of 10 (39%) identified a business partner, subcontractor or IT services provider as responsible for the incident. Organizations of all sizes see an average of three attacks via third parties per year. A total of 79% of companies plan to invest in third-party risk management technologies.

Recently, we’ve seen a relaxed approach to cybersecurity, whereby organizations will ask providers to demonstrate compliance with their internal standards by responding to a questionnaire. 

In one case, a renowned provider suggested that its large manufacturing client use the provider’s policies instead of its own. But companies should know that these policies and procedures govern the management and operations of their cybersecurity, and they assume added risk when they step outside their own regulations to take on another business’s guidelines.

The standards that guide companies allow room for interpretation. A manufacturer with strong intellectual property, for example, will be more stringent about defining and applying protective measures for patents and research and development than an organization that merely wants an increased level of information protection with a heterogenous group of service clients.

In the example above, dealing with the complexity of the provider’s policies and procedures was quite a challenge for this manufacturer. Many of the policies existed as read-only files for auditing purposes. We’ve seen examples of client security regulations that run from 200 to 2,000 pages — but the number of security regulations is no indicator of quality.

Evaluating Providers’ Procedures 

Who should read and understand all this information?

A focused individual requires more than 23 hours to read 700 pages. And reading doesn’t equal understanding; it takes two or three repetitions to fully grasp content. Comparing a full set of enterprise policies and regulations with those of a provider could take as long as 12 to 18 days.

In comparing security assessment findings between sibling companies, readers can digest no more than 50 short, easily understandable sentences in an hour. It requires up to 125 people-days — the equivalent of half a year — to make complex comparisons. And doubling the number of sentences in a given document quadruples the number of comparisons needed, with quality assurance accounting for roughly half the effort. All told, this work could carry a budget requirement of more than $200,000.

Industry research shows the average total cost of a single breach to be about $4.35 million. This can be avoided with a solid, common understanding of how to manage and operate cybersecurity.

Aligning the Ecosystem 

Organizations have come up with a number of ways to solve the policy-review problem. Some use Adobe Acrobat and Microsoft Word to compare words or sets of words, but these tools can’t divine semantical meanings. Others use Microsoft Excel, which requires previous segregation of documents into sentences and can’t match keywords in alternative phrasing.

Businesses can dramatically improve their alignment of security protocols across providers in a supply chain with artificial intelligence that’s designed to semantically compare text. New technologies can improve the quality of comparisons, saving up to 70% of manual work in a single project, and up to 90% in repetitive comparisons.

AI enables companies to upload documents from digital formats or content from corporate wikis, and set thresholds to achieve the desired level of confidence. The technology makes possible semantical understanding of documents in minutes, and semantical quality comparison in hours.

The management of cybersecurity risk is a critical function within supplier ecosystems. With most cyberthreats coming through third-party relationships, companies must quickly and thoroughly compare their policies against those of their providers. New AI text-review capabilities not only cut the burden of that important task by multiples, but when accompanied by a level of consultative support, can help make the difference between a cyber-secure relationship or a risky one.

Roger Albrecht is a partner with ISG, and co-lead of ISG Global Cybersecurity.

Regulation & Compliance Sourcing/Procurement/SRM Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • A PILE OF COFFEE BEANS SITS IN A COMPLETELY WHITE SPACE.

    U.S. to Levy 25% Tariff on Brazil, After 301 Investigation

    Global Trade & Economics
  • GIST-webinar-DecisionPoint.png

    From Fragmented Tools to Unified Workflows: How to Transform Field Operations

  • 023_automation's_scalability_in_the_warehouse_v1 (540p).png

    Watch: Automation's Scalability in the Warehouse

    All Warehouse Services
  • TWO WORKERS SITTING AT A DESK CONSULT OVER A TABLET COMPUTER, SEVERAL COLLEAGUES VISIBLE BEHIND THEM

    Supply Chain Resilience in Today’s Geo-Political Mess

    Artificial Intelligence
  • A WOMAN IN A BLUE SUIT AND PEARLS SPEAKS INTO MULTIPLE MICROPHONES

    Japan’s Takaichi Urges Passage of Vessels in Call With Iran

    Global Gateways

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing