Overview of the outcomes of the survey towards a cyber resilient supply chain
| Elements of CSCRM | Perceived relevance | Alignment of perceptions | Highlights | How to build a cyber resilient supply chain | Main related literature |
|---|---|---|---|---|---|
| Cyber risks – probability | Medium-low | Medium-high | •Values of impact generally higher than probability | •Raise more awareness in terms of incidence occurrence to align perceptions (e.g. incident reporting policies) | Volpentesta et al. (2011); Scholten and Schilder (2015); Tao et al. (2016), Radanliev et al. (2020) |
| Cyber risks – impact | Medium-high | Medium-high | •Logistics Service Providers have a broader perception of the risk events | ||
| Cyber risks – occurrence | Medium | Medium-high | •Higher occurrence values seem to influence the perception of impact values | ||
| Sources of risk | Medium | High | •Stronger perception by Logistics Service Providers, playing a key role for the continuity of the entire supply chain | •Give more emphasis to those actions aimed at dealing with the “human factor” (e.g. protecting organizations from unintentional and malicious actions of employees) | Smith et al. (2007), Boyson (2014); Windelberg (2016), Ghadge et al. (2020) |
| •The “human factor” is perceived as one of the main threats | |||||
| Business departments | Medium-high | High | •The importance of involving different business departments is recognized | •Involve the HR dept to manage the “Human Factor” and the SC dept to drive a SC view into the CSCRM process | Trombley (2015), Boone (2017) |
| •IT department seen as the most involved department by far, followed by top management | |||||
| •Supply chain/logistics dept are not seen as top departments | |||||
| •Human resources dept is not perceived as important to be involved | |||||
| Information shared | Medium-high | Medium | •The relevance of some types of information is shared among all the participants (i.e. invoices) | •Leverage LSPs to combine the views of SC players on the types of information to protect and secure in the SC | Bandyopadhyay et al. (2010), Tran et al. (2016); Li and Xu (2020) |
| •Different groups of respondents focus on those types of information more related and critical to their business operations | |||||
| •Logistics service providers show a broader perception of the relevance of different types of shared information | |||||
| Initiatives and countermeasures | High | Medium | •Retailers show weaker perception, while Logistics Service Providers have a stronger perception of initiatives going beyond the boundaries of the single organization | •Empower LSPs to act as a bringing link in the SC to drive risk appraisals across the chain and devise consistent security policies and investments (cyber supply chain balanced resilience) | Gualandris and Kalchschmidt (2015), Colicchia et al. (2019) |
| •Considerable relevance has been allocated to initiatives during the different phases of an incident (pre-attack, trans- and post-attack measures) | |||||
| •Notwithstanding the relevance assigned to the human factor, measures to tackle the “insider threat” (e.g. personnel background checks) are less perceived compared to other initiatives (e.g. IT security tools) |
| Perceived relevance | Alignment of perceptions | Highlights | How to build a cyber resilient supply chain | Main related literature | |
|---|---|---|---|---|---|
| Medium-low | Medium-high | •Values of impact generally higher than probability | •Raise more awareness in terms of incidence occurrence to align perceptions (e.g. incident reporting policies) | ||
| Medium-high | Medium-high | •Logistics Service Providers have a broader perception of the risk events | |||
| Medium | Medium-high | •Higher occurrence values seem to influence the perception of impact values | |||
| Medium | High | •Stronger perception by Logistics Service Providers, playing a key role for the continuity of the entire supply chain | •Give more emphasis to those actions aimed at dealing with the “human factor” (e.g. protecting organizations from unintentional and malicious actions of employees) | ||
| •The “human factor” is perceived as one of the main threats | |||||
| Medium-high | High | •The importance of involving different business departments is recognized | •Involve the HR dept to manage the “Human Factor” and the SC dept to drive a SC view into the CSCRM process | ||
| •IT department seen as the most involved department by far, followed by top management | |||||
| •Supply chain/logistics dept are not seen as top departments | |||||
| •Human resources dept is not perceived as important to be involved | |||||
| Medium-high | Medium | •The relevance of some types of information is shared among all the participants (i.e. invoices) | •Leverage LSPs to combine the views of SC players on the types of information to protect and secure in the SC | ||
| •Different groups of respondents focus on those types of information more related and critical to their business operations | |||||
| •Logistics service providers show a broader perception of the relevance of different types of shared information | |||||
| High | Medium | •Retailers show weaker perception, while Logistics Service Providers have a stronger perception of initiatives going beyond the boundaries of the single organization | •Empower LSPs to act as a bringing link in the SC to drive risk appraisals across the chain and devise consistent security policies and investments (cyber supply chain balanced resilience) | ||
| •Considerable relevance has been allocated to initiatives during the different phases of an incident (pre-attack, trans- and post-attack measures) | |||||
| •Notwithstanding the relevance assigned to the human factor, measures to tackle the “insider threat” (e.g. personnel background checks) are less perceived compared to other initiatives (e.g. IT security tools) |
Notes:
HR = Human resources; SC = supply chain; LSP = logistics service provider
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.