I come across a survey report on the subject of supply chain risk management from Gartner 2023. It states that “supply chain attacks are on the rise, with 63% of respondents saying their organization has suffered a supply chain attack in the past year”.
A number of questions have popped into my head and I’d like to untangle them with you!

Supply chain – Photo by Jacques Dillies on Unsplash
When I was a child, I used to imagine the paths a product would take before it reached my hands. Later, I learned that this path is what we call the supply chain.
In essence, the supply chain is all the stages a product goes through, from the collection of raw materials to final delivery to the consumer. It’s a logistical ballet of manufacturing, processing, transport, storage and distribution.
This organizational complexity conceals potential vulnerabilities, notably those highlighted by the Gartner report.
Your company buys products and services from company A, but company A buys its products and services from company B, on which it depends for services from company C.
If Company C suffers a security incident, or the quality of its products is affected, what impact does this have on you, three rungs down the chain?
How can I, as a company, ensure that my operations are well managed and that my products are delivered to my customers without being compromised all along the chain, from source to destination?
Understanding the importance of safety in risk management
Threats to the supply chain are manifold, from security incidents – including ransomware – to natural disasters, social unrest or the manufacture of fake products.
Each of these disturbances has a potentially devastating impact.
When you buy a computer, camera or other IT equipment, how can you be sure it hasn’t been compromised, i.e. modified to spy on you or engage in other malicious activity?
Concrete examples of attacks on the supply chain
Let’s look at some real-life cases:
In Japan, the 2011 earthquake and tsunami caused the automotive industry to suffer from a shortage of parts.
The Target incident of 2013 remains etched in memory, where a data breach began with a phishing attack against an HVAC subcontractor, resulting in the compromise of millions of customers’ financial information.
In 2017, the NotPetya cyber attack led to colossal losses for Maersk, whose global supply chain came to a grinding halt.
Also in 2017, a vulnerability in the apache Struts open source software allowed hackers to break intoEquifax‘s systems and steal the personal information of almost 147 million people.
Also in 2017, a compromised version of CCleaner cleaning software was downloaded by 2.27 million users, giving hackers potential access to their computer systems.
Then the SolarWinds attack is one of the best-known examples of a supply chain attack. In September 2019, hackers compromised SolarWinds’ Orion software, widely used for managing computer networks. They then used this position to launch attacks against specific organizations that used this software i.e. tens of thousands of organizations, including US government agencies.
On December 9, 2021, a vulnerability was discovered in the Apache Log4j code (CVE-2021-44228), on December 14, 2021 a second vulnerability was discovered (CVE-2021-45046) and finally on December 17, 2021, a third vulnerability (CVE-2021-45105). The flaw allows an attacker to inject malicious code into a log message, which can then be executed by the vulnerable server. This gives the attacker total control over the system, enabling him to steal data, install malware or disrupt service operation. This software is used by many companies(estimated at 44%worldwide).
Closer to home, in July 2022, the Rogers telecommunications company went down, causing damage to Interac customers, for payments at La Ronde, SQDC, Montreal’s 311 service and Quebec City’s bike-sharing services were impacted.
It’s a very short list, but these events are indicative of the inherent vulnerability of interconnected systems. Clearly, understanding cybersecurity is not just about protecting our own networks, but also taking into account the risks associated with those of our partners and suppliers.
Link to ISO27001:2022
The new version of ISO 27001:2022 focuses on information security management in supplier relations. More specifically, Annex A controls 5.19, 5.20, 5,21and 5.22deal with information security in supplier relations.
The aim here is to protect the organization’s valuable assets that are accessible to suppliers.
The standard also emphasizes the importance of information security management in the supply chain. Processes and procedures must be defined and implemented to effectively manage information security throughout the supply chain.
Suggestions for action to manage the supply chain
So how do you manage risk? In concrete terms, this means :
Identify your suppliers: obtain a list of the suppliers, products and services you use in the course of your work or to deliver a product to your customers. Document the types of services or products these suppliers offer you.
Identify critical suppliers: in our long list of suppliers, some are more critical than others, so for each supplier we ask ourselves a few minimal questions to sort them out:
Does the supplier have access to confidential data? Yes/No
Does he have access to personal information? Yes/No
Does it pose a risk to us if it were compromised? Yes/No
What if it’s critical to us for some other reason? Yes/No
Identify risks: for each critical supplier, we define the hazards, risks or threats that could impact that supplier and us at the same time, using scenarios such as data leakage, corruption, service unavailability and so on. For each risk scenario, we use the Probability X Impacts formula to determine which threat is the most significant, and easily rank them in order of importance.
Validate the security level of our suppliers: once we have our list and our risks, we need to prevent incidents by ensuring that security measures are taken by our suppliers, by carrying out audits of their practices and/or security tests against their systems.
Also, make sure that your supplier also validates his own suppliers.
It’s a good idea to validate these levels regularly.
Manage risks: validate service level agreements (SLAs) and incident communication practices to ensure rapid detection and communication.
Specifically for the software installed on your workstations, validate the SBOM (Software Bill Of Materials), a list of all the software components and dependencies of an application. It’s comparable to the list of ingredients in a recipe, but for software.
Diversify your suppliers: relying on one or two suppliers may seem convenient, but it’s better to spread the risk or have an exit strategy for a supplier when needed. So, if possible, have a little redundancy in your suppliers.
Be reactive: establish contingency plans, alternatives to your practices in case of failure. Maintain good communication and incident management with partners. Do you know who to contact if you discover an incident?
Acting before, during and after an incident is the key to good supply chain management.
That said, it’s crucial to realize that the smooth running of our operations and information systems is intimately linked to that of our suppliers and business partners.
The events I’ve listed above should make you reconsider your supplier management practices. I know that incorporating safety practices into a daily routine can seem like a daunting task, but it’s essential if we are to have a healthy business, manage risk and continue to grow our business with confidence.
The future of information security in supply chains?
Artificial intelligence (AI):
AI will play a crucial role in threat detection by analyzing supply chain data in real time, across multiple sources with multiple data types to make a simple dashboard.
It can identify anomalies and suspicious behavior, enabling companies to react more quickly to security incidents.
Blockchain:
Blockchain can be used to secure transactions in the supply chain by creating an immutable and transparent record of all activities.
This strengthens trust between stakeholders and reduces the risk of fraud.
The Internet of Things (IoT):
The IoT can be used to collect real-time data on products and supply chain processes. This data can then be analyzed to identify vulnerabilities and security risks.
Collaborative cybersecurity:
Companies can collaborate with each other to share information on threats and best practices in supply chain security.
Links and references
https://www.cyber.gc.ca/fr/orientation/cybermenace-provenant-chaines-approvisionnement