Articles
Cybersecurity in the connected supply chain
Digital supply chains increasingly use data capture and share data with many parties through data transfer and the use of internet-connected devices (the Internet of Things). The many connection points can place a company's IT infrastructure at greater risk of cyber-attack, and successful attacks can have a more significant impact on operations than previously. For example, an automated warehouse cannot easily fall back to paper picking.
Cybersecurity is, therefore, more important than ever. Just one successful cyber-attack could have a catastrophic impact on the business. An operations shutdown or inability to fulfil deliveries or customer orders has an immediate impact of lost sales as well as the possibility of customers moving away permanently. Any data leak will seriously affect the business’s reputation among customers and suppliers. In addition to the direct operational and sales costs, there are the costs of restoring systems and data, and the huge disruption and drain on management time. Supply chains often use personal customer data, for example, when delivering directly to the customer’s home. The loss of this data could well incur regulatory investigation and prosecution where fines can be millions of pounds in the worst cases. Not surprisingly, if cybersecurity is part of an individual’s responsibilities, even if they are not in IT management, the impact on their personal career could be severe.
Businesses cannot afford to cut corners in this area and need to dedicate sufficient time to identify all risks. This might include war-gaming possible situations and putting in place measures to ensure that a lost password or phishing attack will have only limited impact. Training all staff on being alert for phishing attacks and the basics of password security is essential. External experts can identify weaknesses in hardware, software, and firewalls using penetration testing (ethical hacking). These assessments and preparations can include how data and interactions with suppliers are managed, ensuring that their systems and procedures meet the required quality standards. For example, it may be prudent to insist that all suppliers meet the ISO/IEC 27001 certification standard for information and cyber security or have a Cyber Essentials accreditation.
Ensuring that cybersecurity is a standard part of discussions with technology solution providers, suppliers, and customers is crucial.