As businesses increasingly embrace digital technologies and interconnectivity, the threat of cyberattacks is rising, despite robust security measures.
Editor’s Note: This article marks the beginning of a series by SK Jeong, a professor from the University of Tennessee and an expert in digital supply chain management. Jeong is renowned for his research on software vulnerabilities and the economic impacts of cyberattacks. He delves into why cybersecurity is crucial for supply chain professionals and outlines essential strategies for effective management. For more insights, visit the University of Tennessee Global Supply Chain Institute’s blog, which features key readings from top researchers and scholars on current global supply chain trends.
With the push towards digitalization, the risk of cyberattacks has surged. These attacks are not only becoming more common but also inflicting substantial financial damage. Despite significant investments in cybersecurity, companies with robust defenses are still vulnerable. Attackers often target suppliers with weaker security, using these less-protected links to breach their primary targets.
A case in point is the SolarWinds hack of 2020. SolarWinds, known for its Orion software that helps monitor and manage IT systems, was compromised by state-sponsored hackers who inserted malicious code into a routine update. This breach impacted around 18,000 customers, including U.S. federal agencies, state and local governments, and major corporations.
For over ten years, experts have tracked the growing trend of cyberattacks exploiting vulnerabilities within supply chains. The COVID-19 pandemic accelerated this trend as businesses rapidly adopted digital tools, enhancing productivity but also exposing themselves to more cyber threats through their supply chains.
The Role of Cybersecurity in Supply Chain Management
A major factor in the exploitation of supply chains is the often inadequate cybersecurity measures of suppliers. Smaller companies, which constitute a significant portion of the supply chain, frequently lack the resources to safeguard against cyber threats. These suppliers, focusing more on operational efficiency and cost rather than cybersecurity, remain vulnerable, echoing challenges faced with other emerging supply chain issues like sustainability.
Supply chain managers must prioritize cybersecurity, integrating it into supplier selection and development processes. In a digitally interconnected world, vulnerabilities within the supply chain can jeopardize even the most secure organizations. Thus, supply chain professionals need to take a proactive role in managing cybersecurity risks.
Navigating the Software Supply Chain
Just as physical products rely on multiple suppliers, software products are built from various modules, forming intricate “software supply chains.” These software supply chains face similar risks to traditional supply chains, with vulnerabilities in lower-tier modules potentially exposing entire systems to attacks.
For instance, in 2021, the Log4J vulnerability—a flaw in a widely used logging software—allowed attackers to compromise systems without valid credentials. Digital goods are inherently accessible from outside, making them susceptible to exploitation of newly discovered vulnerabilities before they are patched.
Recent Trends and Best Practices
To combat these rising threats, both government bodies and industry groups have introduced frameworks for improving supply chain cybersecurity.
The Software Bill of Materials (SBOM) is a key tool, similar to the traditional Bill of Materials, which outlines the software components used in a product. This transparency aids organizations in tracking vulnerabilities and addressing issues in the software supply chain more effectively.
Additionally, standardized frameworks like the National Institute of Standards and Technology (NIST) Cybersecurity Supply Chain Risk Management framework offer systematic approaches to managing supply chain cybersecurity risks.
Proactive managerial oversight is also essential. Cyberattack strategies are continually evolving, and no single solution is permanent. Collaborative efforts across organizations can help mitigate potential risks. For example, the collective response to the Log4J vulnerability demonstrated how coordinated actions can effectively minimize the impact of cybersecurity threats.
In our next installment, we will examine recent cyberattack incidents within supply chains and the valuable lessons they offer.
About the Global Supply Chain Institute
The University of Tennessee’s Global Supply Chain Institute (GSCI) stands at the forefront of supply chain innovation and professional development. The institute’s flagship event, the UT Supply Chain Forum, convenes over 80 leading companies biannually to share knowledge, network, and recruit top talent in the field of supply chain management.



