Towards a Leader-Driven Supply Chain Cybersecurity Framework
Academic Article
Overview
Additional document info
View All
Overview
Abstract
Supply chains (SC) often span multiple cultures, countries, and time zones with security concerns that, at a high level, can be grouped into two broad areas: 1) products/assets; 2) information technology (IT). SCs can achieve higher operational efficiency if participating entities are highly connected since rapid information transfer helps SC participants be agile, adaptable, and aligned. To be antifragile, a key requirement of highly interconnected systems is strong overall cybersecurity. We posit that individual partners independently enhancing their security may not sufficiently improve the overall SC cybersecurity posture; rather, what is required is that coordinated cybersecurity efforts be driven by the SC’s most powerful member. We propose a conceptual framework for the leader in the SC that involves two broad elements: 1) supplier/member selection; 2) continuous training, development, and risk assessment of SC members from a cybersecurity perspective. A use case is provided to expound on the presented ideas.