Cybersecurity in the supply chain
To mitigate cybersecurity risks along the supply chain, organisations need to understand and assess their risks, define their requirements and specifications for their suppliers, subcontractors and providers, and verify compliance. To this end, companies, public authorities and organisations should take a strategic approach to cybersecurity risks in their IT/OT supply chain. This is known as Cyber Supply Chain Risk Management (C-SCRM).
Ideally, the strategy is based on a continuous review of all dependencies in the IT/OT supply chain. The United States' National Institute of Standards and Technology (NIST) has published a helpful publication and key practices (NISTIR 8276).
Pilot project with Planzer Transport AG
To enable companies, authorities and organisations in Switzerland to pragmatically implement their supply chain cybersecurity requirements, the National Cyber Security Centre (NCSC) has conducted a pilot project with Planzer Transport AG and developed an easy-to-understand process and specific resources.
Measures to protect against cyberattacks in the supply chain
1. Know your supply chain and be aware of cyber risks
2. Selecting and prioritising suppliers
- Partners who, due to their privileged access to your organisation's internal systems, could have a negative impact on your IT/OT. For example: partners who are responsible for operating a system in your organisation's network.
- Partners who provide hardware or software to your organisation that could cause damage if compromised. For example: Microsoft Office or other specialised applications or systems operated by your organisation.
- Partners who provide key services to your organisation that, if discontinued or interrupted, would affect the confidentiality, availability or integrity of data. For example: SaaS, logistics or outsourcing partners such as service desks or product suppliers.
In order to prioritise your suppliers, you need to know what cyber risks they face, what dependencies exist and what information you share with them. To help your organisation ask the right questions and take targeted action to strengthen your cyber resilience, the National Cyber Security Centre (NCSC) has worked with Planzer Transport AG to develop a set of key questions.
3. Review of the current situation
4. Preliminary meeting with suppliers and discussion of supplier review
5. Supplier review
Planzer Transport AG's experience has shown that the only way to improve conditions in your own supply chain is for your suppliers to recognise the need for change and to understand how it will benefit their business. Supply chain management should therefore focus on building supplier expertise. There are two approaches to performing a supplier review: self-assessment and on-site inspections.
Self-assessments are a good first step and can be followed up with on-site visits or audits, for example. The decision to carry out an audit is based on the assumption that suppliers are unwilling to implement customer requirements and therefore need to be monitored. Planzer Transport AG's practical experience shows that suppliers generally want to implement requirements, but may not be in a position to do so or may need to be incentivised. To help your organisation ask the right questions of your suppliers, the National Cyber Security Centre (NCSC) has worked with Planzer Transport AG to develop a set of key questions.








