Learning Objectives:
-
Understand the systemic risks posed by supply chain vulnerabilities.
-
Identify the key threats to supply chain security.
-
Develop strategies for mitigating supply chain risks.
-
Recognise the importance of collaboration and information sharing.
6.1 The Systemic Nature of Supply Chain Risk
Supply chain attacks are increasingly prominent targets, and the impact of supply chain attacks is often severe . The complexity of modern supply chains, combined with growing reliance on open-source software and its downstream dependencies, has created a “perfect storm” for systemic cyber risk . A breach at one vendor can cascade across dozens of organisations simultaneously .
Key Systemic Risks:
-
Cascading Impact: A breach at one vendor can affect multiple organisations
-
Regulatory Triggers: Supply chain breaches are regulatory triggers
-
Reputational Liabilities: Supply chain breaches are reputational liabilities
-
Shareholder Events: Supply chain breaches are shareholder events
The RBI’s approach to supply chain risk includes requiring payment system operators to strengthen vendor risk programs covering IAM, cloud security, incident response, and digital payment security controls . The RBI has made it clear that third-party cyber risk is now treated as a systemic risk, not an operational one .
6.2 Key Threats to Supply Chain Security
Cyber Threats:
-
Infostealers: Malware that steals credentials and data
-
Supply Chain Attacks: Attacks targeting software supply chains
-
Cloud Compromise: Attacks targeting cloud service providers
-
Credential Theft: Theft of credentials used to access systems
Operational Threats:
-
Service Disruptions: Disruptions to third-party services
-
Data Breaches: Breaches of third-party systems containing sensitive data
-
Regulatory Violations: Violations of regulations by third parties
The ECB Guide addresses the need to assess risks including lock-in and concentration risks, multi-tenancy risks, data protection and geopolitical risks, long and complex sub-outsourcing chains (generally beyond two or three contractual layers), and vendor dependence across the institution’s entire provider landscape .
6.3 Mitigating Supply Chain Risks
The Bank of England and Orpheus collaboration provides a model for mitigating supply chain risks :
Establishing Trust and Collaboration:
-
Building strong relationships with suppliers
-
Creating trust and collaboration with suppliers
-
Developing a ‘one team approach’
Clear Communication:
-
Agreeing on a communications plan
-
Ensuring that threat intelligence and alerting is exchanged promptly
-
Preventing misunderstandings and ensuring coordinated responses
Data Validation:
-
Rigorous data validation
-
Automated tooling in addition to analyst verification
-
Cross-checking data with the Bank of England
Tailored Engagement:
-
Tailoring alerting and engagement cadence to fit the supply chain
-
Avoiding overwhelming suppliers with unnecessary alerts
-
Ensuring more meaningful collaboration
Workshops and Seminars:
-
Hosting workshops or seminars with suppliers
-
Boosting collective security awareness
-
Sharing best practices and discussing emerging threats
6.4 Geopolitical Risk in Supply Chains
The ECB has emphasised that economic interdependence has become a source of vulnerability to deliberate weaponisation of dependencies . The ECB Guide requires that financial institutions explicitly assess political and legal risks of third-country jurisdictions .
Key Geopolitical Considerations:
-
Strategic Autonomy: The need to reduce dependence on geopolitically distant suppliers
-
Reshoring and Friendshoring: Strategies for relocating production to friendly countries
-
Coalitions of the Willing: Collaborative approaches to supply chain security