• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Supply Chain Blind Spots: Why Cyber Compliance Needs Prioritization

Think Tank
Think Tank RSS FeedRSS

Supply Chain Blind Spots: Why Cyber Compliance Needs Prioritization

A GRAPHIC SHOWING A MAP OF THE WORLD AND CYBER SECURITY NETWORKS456.jpg

Photo: iStock.com/cemagraphics

October 15, 2025
Marie Hattar, SCB Contributor

Companies must build resilience to protect their supply chains against cyber attacks. Yet many view security as an issue to be addressed once a product has been designed. And when flaws are uncovered later in the development lifecycle or within supply chain components, the consequences can be significant.

Further complicating the situation is that products like cars, medical devices and cloud platforms include a complex mix of hardware and software components sourced across the globe. This means that a single insecure component, such as a firmware module or chiplet, can compromise the entire assembly.

Numerous regulations have been introduced to mitigate cybersecurity risks, creating a web of compliance that organizations must meet. These include Europe’s comprehensive Cyber Resilience Act (CRA), executive orders such as EO 14028 on software bill of materials (SBOM), sector-specific mandates like CMMC for the defense industry, and international standards such as ISO/SAE 21434 for automotives.

If a company fails to obtain the relevant cyber certifications, it might be unable to ship or have to recall non-compliant models, along with incurring heavy financial penalties.

For example, Porsche can no longer sell its Macan, Boxster and Cayman cars in Europe due to its failure to meet UN ECE R155 requirements. This regulation mandates strict cybersecurity protocols and development processes for all new cars in Europe.

Vulnerabilities identified early in the design process are far less expensive than those uncovered in production. If a flaw is found later in the development process, the cost of a redesign can be significant. Shifting security to an earlier stage is much cheaper than retrofitting it later. 

Medtronic had to pull multiple insulin pumps from the market because it hadn’t planned for cybersecurity updates. The recalls weren’t a result of the brands ignoring cybersecurity, but rather failing to address cyber certification as a priority on day one.

Many digital products depend on global suppliers, and with hardware and software no longer built-in silos, solving the cybersecurity problem is challenging. To reduce the risks and avoid blind spots in security coverage, integrity validation is required to continuously check data and code. This ensures that flaws or vulnerabilities are identified and addressed rather than waiting for cybercriminals to find and exploit them.

Supply chain security isn’t static; it's a constant process to ensure that vulnerabilities don’t creep in at any point. A key part of mitigating risks and eliminating security issues is introducing software and hardware bills of materials (SBOMs and HBOMs). This ensures that organizations have the tools to continuously track and validate the integrity of all components across the supply chain. For example, a company not only generates and publishes the SBOM for code it creates, but all upstream suppliers are required to do the same, so the information can be combined to provide forensic accounting for regulatory bodies or other stakeholders. BOMs are so critical for securing interconnected supply chains that many regulations now mandate them.

Organizations that fail to design with security in mind from the outset increase the likelihood of a data breach and service disruption. Therefore, cybersecurity can no longer be an afterthought in the development process —compliance assurance needs to be prioritized at every stage. The cost of remediation and risk of delays increase significantly if it’s left until later, which can make or break a product's viability. 

Adopting a secure-by-design approach ensures a company's products meet all compliance requirements. Rather than firefighting certification standards, organizations should treat cybersecurity as a strategic priority, and enforce it as part of their supply chain DNA from day one.

Marie Hattar is senior vice president of Keysight Technologies.

Regulation & Compliance Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • A GLEAMING TUNNEL OF LIGHTS CURVES AWAY INTO A HORN

    Gartner: Top 25 Supply Chain Organizations Are Embracing AI

    Global Logistics
  • HANDS TYPE ON A KEYBOARD UNDER A SUPER IMPOSED DIGITIZED MAP OF THE WORLD, ALONG WITH IMAGES OF A SHIP, A SHOPPING CART AND OTHER SYMBOLS OF INTERNATIONAL LOGISTICS

    Five Demand-Forecasting Mistakes Supply Chain Leaders Are Rethinking

    Technology
  • TWO WORKERS IN HI-VIS VESTS AND HARDHATS CONSULT A BANK OF COMPUTER SCREENS

    How a Poor Hiring Process Leads to High Turnover in Supply Chain

    HR & Labor Management
  • The outside of Oracle Corporation's corporate headquarters located in Silicon Valley. Photo: iStock.com/Sundry Photography

    Oracle Cuts 21,000 Jobs, More to Come From AI

    Technology
  • 037_a_roadmap_for_the_ai_journey_v1-(540p).png

    Watch: A Roadmap for the AI Journey

    Artificial Intelligence

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing