search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
SUPPLY CHAIN


Ensuring cybersecurity along the supply chain


By Chris Whyborn, head of cybersecurity services (UK & Europe), TÜV SÜD Business Assurance


Supply chain cybersecurity Cybersecurity risks within the supply chain are often underestimated. It is therefore important not only to assure an organisation’s cybersecurity but also its global digital supply chain, including second and thirdtier suppliers. The European Union’s (EU) NIS2 Directive requires organisations to protect their systems and systematically assess risks in their supply chain. Compliance with global ISO standards is helpful for implementing and demonstrating NIS2 compliance. These standards also help establish a strong cybersecurity baseline, showing the supply chain that a company is prepared for cyber attacks. ISO 27001 is the leading international standard for information security management, providing a practical framework for an effective information security management system (ISMS). It simplifies compliance with applicable security requirements, helping to foster an organisation-wide information security culture.


ISO 28000 covers cybersecurity in the supply chain from a management and risk perspective, helping organisations identify weak points across global supply chains and develop disaster management strategies. The standard requires that cybersecurity is managed through the three pillars of risk assessment, asset protection and integrated resilience.


Supply chain cybersecurity steps The Charter of Trust (CoT) is an international industry initiative involving Siemens, IBM, Bosch, Danfoss, TÜV SÜD and others. It aims to strengthen cybersecurity, particularly along digital supply chains, through a practical methodology covering three interrelated steps. The first defines fundamental, cross- industry cybersecurity criteria for all suppliers with digital services. This aims to eliminate fundamental vulnerabilities from the outset and establish a common security baseline. The second step involves suppliers performing risk assessments that evaluate the type, scope and relevance of their interfaces with the company. Thirdly, depending on the criticality level, the defined requirements must


36


be verified in different ways, for example, through self-disclosure, documented evidence or technical tests. Particularly for highly critical suppliers, on-site audits will play a key role.


Cybersecurity checks and balances


Ensuring the supply chain is secure goes beyond a tick-box compliance exercise as it must be a model of continuous assurance. This should include appropriate due diligence that verifies a supplier’s baseline cybersecurity maturity. They should be categorised based on their access to data or network. For example, a Tier 1 cloud provider requires deeper scrutiny than a Tier 3 office supplies vendor. It is also important to look for global certifications like ISO/IEC 27001, and demand evidence that the supplier follows a secure development lifecycle (SDLC). In terms of the contractual relationship, trust must be built on clear, enforceable expectations. This can include the right to audit, so that a supplier’s security controls can be inspected, or requesting a SOC 2 Type II report annually. The supply chain is also increasingly requiring mandatory breach notifications, with strict time windows for reporting a suspected compromise. Contracts should also define who is financially and operationally responsible if a supplier’s vulnerability causes a downstream breach in a company’s network.


JULY/AUGUST 2026 | ELECTRONICS FOR ENGINEERS


For this reason, one should consider fourth- party risks management and ensure suppliers are checking their suppliers. This should include a requirement for sub-contractor transparency – while a Tier 1 supplier is secure, their coding may be outsourced to a Tier 4 firm with no security, putting the company at risk. Flow-down clauses in contracts also mean that security requirements go from a supplier to their subcontractors. A valuable step in evaluation of supply chain risk is to carry out a Business Impact Assessment (BIA), a process defined within ISO 22301 - Security and resilience - Business continuity management systems- Requirements. In this context that would mean assessing the impact on the operation of the loss of any part of the supply chain, putting in place proportionate mitigations or alternative suppliers.


As cyber threats can arise internally or via third parties that have access to critical data, every part of the supply chain should embed cybersecurity in the design phase of any product, service or underlying process. Likewise, comprehensive training for employees and other stakeholders is key to mitigating cyber risks, with an active culture that engages employees in cybersecurity being encouraged. Cybersecurity needs to be seen as a business-enabling priority for management and flow down throughout the organisation and supply chain, irrespective of business size and location.


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36  |  Page 37  |  Page 38  |  Page 39  |  Page 40  |  Page 41  |  Page 42  |  Page 43  |  Page 44  |  Page 45  |  Page 46