Chris Whyborn on ensuring cybersecurity across the supply chain

Cyber risks in the supply chain are often underestimated. It is therefore important not only to ensure an organization’s cybersecurity but also its global digital supply chain, including second and third tier suppliers.

The European Union’s (EU) NIS2 Directive requires organizations to protect their systems and systematically assess risks in their supply chain. Companies must demonstrate that third parties are integrated into a robust security management system. Compliance with global ISO standards is helpful for implementing and demonstrating NIS2 compliance. These standards also help establish a strong cybersecurity baseline, showing the supply chain that a company is prepared for cyber attacks.

Chris Whyborn
Chris Whyborn

ISO 27001 is the leading international standard for information security management, providing a practical framework for an effective information security management system (ISMS). It simplifies compliance with applicable security requirements, helping to foster an organization-wide information security culture. ISO/IEC certification can lower IT security costs by reducing the risk of security breaches and the consequences of data breaches, such as financial damage and reputational harm. It is also a significant business enabler, giving access to contracts with government and those companies with flowed-down information security requirements.

ISO 28000 covers cybersecurity in the supply chain from a management and risk perspective, helping organizations identify weak points across global supply chains and develop disaster management strategies. The standard requires that cybersecurity is managed through the three pillars of risk assessment, asset protection, and integrated resilience.

Cybersecurity steps

The Charter of Trust (CoT) is an international industry initiative involving Siemens, IBM, Bosch, Danfoss, TÜV SÜD and others. It aims to strengthen cybersecurity, particularly along digital supply chains, through a practical methodology covering three interrelated steps. The first defines fundamental, cross-industry cybersecurity criteria for all suppliers with digital services. This aims to eliminate fundamental vulnerabilities from the outset and establish a common security baseline.

The second step involves suppliers performing risk assessments that evaluate the type, scope, and relevance of their interfaces with the company. Thirdly, depending on the criticality level, the defined requirements must be verified in different ways, for example, through self-disclosure, documented evidence or technical tests. Particularly for highly critical suppliers, on-site audits will play a key role.

In terms of content, the CoT approach is based on common international standards and can be integrated into existing procurement and compliance processes. To evaluate the implementation of the requirements on the supplier side, a conformity assessment in accordance with the relevant best practice is sometimes appropriate. Standard compliance provides suitable evidence that can be part of the contractual requirements that companies agree with their suppliers.

Checks and balances

Ensuring the supply chain is secure goes beyond a tick-box compliance exercise as it must be a model of continuous assurance. This should include appropriate due diligence that verifies a supplier’s baseline cybersecurity maturity. They should be categorized based on their access to data or network. For example, a Tier 1 cloud provider requires deeper scrutiny than a Tier 3 office supplies vendor. It is also important to look for global certifications like ISO/IEC 27001, and demand evidence that the supplier follows a secure development lifecycle (SDLC).

a high-angle, top-down view captures two warehouse workers managing inventory in a central aisle of a large fulfillment center

In terms of the contractual relationship, trust must be built on clear, enforceable expectations. This can include the right to audit, so that a supplier’s security controls can be inspected, or requesting a SOC 2 Type II report annually. The supply chain is also increasingly requiring mandatory breach notifications, with strict time windows for reporting a suspected compromise. Contracts should also define who is financially and operationally responsible if a supplier’s vulnerability causes a downstream breach in a company’s network.

Once the contract is signed, it is increasingly common for companies to require a Software Bill of Materials (SBOM) for software and firmware, that allows the identification of known vulnerabilities within supplier’s IT Infrastructure. Tools can also be deployed to provide real-time security ratings based on public-facing telemetry. Companies should also define vulnerability disclosure requirements so that suppliers have a clear, public way to report and receive security flaws.

It’s also vital to consider fourth-party risks management and ensure suppliers are checking their suppliers. This should include a requirement for sub-contractor transparency – while a Tier 1 supplier is secure, their coding may be outsourced to a Tier 4 firm with no security, putting the company is at risk. Flow-down clauses in contracts also mean that security requirements go from a supplier to their subcontractors.

As cyber threats can arise internally or via third-parties that have access to critical data, every part of the supply chain should embed cybersecurity in the design phase of any product, service or underlying process. Likewise, comprehensive training for employees and other stakeholders is key to mitigating cyber risks, with an active culture that engages employees in cybersecurity being encouraged. Cybersecurity needs to be seen as a business-enabling priority for management and flow down throughout the organization and supply chain, irrespective of business size and location.

Chris Whyborn
www.tuvsud.com

Chris Whyborn is the Head of Cybersecurity Services (UK and Europe) at TÜV SÜD. Chris has more than 40 years of security and investigations experience in a wide variety of operational, management, policy and consultancy roles. This includes providing risk assessment and security advice to senior ministers and diplomats from UK and EU nations.