ADVERTISEMENT

How to secure cyber-physical supply chains

Businessman manager using tablet check and control for workers with Modern Trade warehouse
Adi Gaskell
Adi Gaskell Contributor
October 1, 2021 2 min read
  • The distributed nature of control and management of cyber-physical systems makes it hard to effectively secure the system
  • The speed and fluidity of readings and the status of the system can create doubts
  • They may involve real-time control loops with specific performance requirements
  • They can be geographically spread over a large area, with components in locations that lack physical security

Securing supply chains

ADVERTISEMENT
  1. Cybersecurity defences are not infallible - If organizations start with the premise that a breach is inevitable, it changes the way you implement your cybersecurity. “The focus then becomes not just on how a breach can be prevented, but also on other aspects such as mitigation of the hackers’ ability to misuse the information they may have got access to and also planning for a recovery from the breach,” Singh says.
  2. Understand how hackers operate - The modern world is likely to see companies using a wide range of vendors, so it’s important to understand just what hackers will look to exploit in the supply chain in order to access sensitive information. It’s not enough to focus cybersecurity efforts on just your own systems, as the security of the supplier network is only as strong as its weakest links.
  3. Define minimum security requirements - It’s rare for cybersecurity to be a part of supplier contracts, but Singh argues that companies can only establish control if they define minimum security requirements as part of the contracts companies have with their supply chain. “Raising supplier awareness with respect to cybersecurity and helping them maintain minimum standards is essential,” he says. “Providing support in the aftermath of an attack or breach can help recovery and in minimizing the damage.”
  4. Companies should monitor compliance among suppliers - Given the complexity of supply chains, it is unquestionably cumbersome to monitor cybersecurity compliance among such a complex web of vendors. It is, however, a necessity if supply chains are to remain secure. “Vendors must understand that their vulnerabilities can lead to hackers getting an opening into their partner network and make them liable for losses, fines, and potentially even damages from a lawsuit,” Singh explains.
  5. Secure supply chains are a cost of doing business - Given the propensity of cyberattacks around the world, and the significant costs associated with such attacks, cybersecurity is no longer something that can be viewed as a luxury that can only be considered in good times. Instead, it should be viewed as very much a standard cost of doing business in our modern and interconnected world. Doing so is, after all, in the interests of the parent firm and all of their suppliers.
ADVERTISEMENT