SlideShare a Scribd company logo
1 of 43
WHO CARES?
SUPPLY CHAIN MANAGERSā€™ PERCEPTIONS REGARDING
CYBER SUPPLY CHAIN RISK MANAGEMENT
IN THE DIGITAL TRANSFORMATION ERA
109578401 HOANG TO NHU
109578403 DO THI TRANG
109678402 NGUYEN THI HONG NHUNG
Perceptions of supply chain managers for cyber supply chain risk management (CSCRM)
How can organizations deploy a CSCRM strategy?
ABSTRACT
Digital transformation
Cyber supply chain
Cyber security
1. INTRODUCTION
1. INTRODUCTION
CYBER SECURITY
CYBER RISKS COMPANIES CSCRM
in a supply chain are
seen as the top threats
tend to adopt security
measures to protect
themselves
is necessary for a better
level of resilience
through the cyber supply
chain
ORGANIZATIONS LITERATURE
involved in a supply chain
do not make the same
decisions
gives technical aspects
rather than organization
aspects across the
supply chain
as top threats
THIS RESEARCH
helps organizations to understand how they can deploy a
cyber security strategy
RQ1.
How relevant are the elements of CSCRM perceived by
companies in a supply chain?
RQ2.
How aligned are the perceptions about CSCRM of companies
in a supply chain?
Manufacturers Logistics Providers Retailers
Survey of the perceptions of supply chain managers regarding 3 main stages:
Section 2: Overview of the literature of CSCRM
Section 3: Research methodology
Section 4: Investigation results
Section 5: Findings of the analysis
Section 6: Conclusion
2. THEORETICAL BACKGROUND
Cyber supply chain
risk management
(CSCRM)
CSCRM
PURPOSE
is to extend control on cyber risks which enables a
continuously adaptive capacity.
Supply chain resilience
relates to a fit between riskiness and related level of
preparedness to manage the risks.
Humans
are limited to make objective estimations.
INDIVIDUALS
seem to rely on their perception of risks on their own
confidence and belief.
Decisions
are subjective for what might happen and how they think
it might affect.
Different approaches
by different people make different effects.
Cyber risks
Sources of risks
Responsibility and ownership of the CSCRM
Information exchanged
Countermeasures to manage cyber risks.
CSCRM process includes
Initiatives and
countermeasures to
manage cyber risks
Sources of cyber risks
Cyber risks
in supply chain
Responsibility
of CSCRM process
34%
25%
34%
2%
ELEMENTS OF CSCRM PROCESS
Information exchanged
in the supply chain 5%
2.1 CYBER RISKS in supply chain
ā€¢ Type 1 includes incidents of phishing and theft or data manipulation.
ā€¢ Type 2 covers cyberstalking and harassment, stock market manipulation, blackmailing and corporate espionage.
BACKBONE RISKS
ā€¢ ERP system malfunction
ā€¢ Crash of companyā€™s website
ā€¢ Lack of network connectivity
ā€¢ Malware
ā€¢ Data breach
ā€¢ Damage of records
ā€¢ Theft of credentials
2.2 SOURCES of cyber risks
INTERNAL EXTERNAL
MALICIOUS
NON-INTENTIONAL
Suppliers/contractors
Current
employees
Former
employees
Suppliers/
contractors
Customers
Competitors
Hackers/
Hacktivists
Current employees
Former employees
Technical problems
Customers
Natural disasters
Technical problems
Colicchia (2019)
2.2 SOURCES of cyber risks
ā€¢ Employees
ā€¢ Physical objects
ā€¢ Technical assets
Ghade (2020)
2.3 RESPONSIBILITY AND OWNERSHIP
of CSCRM process
ā€¢ Entire company should
engage in the CSCRM
process with strong
commitment.
ā€¢ Cyber security should be a
department in the company.
2.4 INFORMATION EXCHANGED
in the supply chain
Inventory Sales data Invoices Discounts
Order status Production plan Performance Master data
2.5 INITIATIVES AND COUNTERMEASURES
to manage cyber risks
Pre-attack
Actions at the technical
level and those directed
at or carried out by
human factors
Trans-attack
Data consistency checks
and task forces
Post-attack
Forensics, incident
documentation,
insurance and recovery
and backup procedures
Companies seem to respond with pre-attacker phase rather than the others.
However, all phases should have a varied set of actions to cover different attacks and
different risk environments.
3. METHOD
3.1 SAMPLE
Focus on a specific sector, specifically the FMCG
industry in Italy
The Italian FMCG industry is placed among the top four
markets in Europe for logistics flows and generated
turnover, and it is one of the fastest-growing sectors
across Europe, after Spain in 2016
The Italian FMCG supply chain has gone through a deep
transformation, leading to the adoption of the principles
of efficient consumer response (ECR) and IT
technologies
3.1 SAMPLE AND DATABASE
The questionnaire was distributed to 524 companies,
with the following representation: 321 manufacturers,
134 logistics service providers and 69 retailers.
Managers in charge of supply chain management or logistics
are chosen as potential respondents for this survey (with
minimum 5 years experience)
112 full questionnaires returned.
3.1 DESIGN
The resulting questionnaire consisted of six different sections
The questions were measured by five-point Likert scales, ranging from ā€œvery relevantā€ to ā€œnot relevantā€,
from ā€œlow impactā€ to ā€œvery high impactā€ (according to the assessment scale presented by Hallikas et al.,
2004) or from ā€œvery low probabilityā€ to ā€œvery high probabilityā€ (according to the assessment scale
presented by Hallikas et al., 2004)
Use ANOVA with F statistics value with a significance level of 5% to analyse the results.
4. RESULTS
4.3. Perception of the sources
of risk
4.2. Perception of the risk
events
4.1. Profile of the
respondentsā€™ sample
4.4. Involvement of the
organizationā€™s departments in
cyber and information risk
management
4.5. Perception of the criticality
of the information shared
across the supply chain
4.6. Perception of the
countermeasures and actions for
mitigating cyber risks
4.1 PROFILE of the respondentsā€™ sample
64 manufacturers
31 logistics service
providers 17 retailers
4.2 PERCEPTION of the risk events
the whole FMCG supply chain has experienced
the same risk events
an almost unanimous consensus around the
two events considered to be the most
dangerous ones
Malware has been judged to be a high risk,
especially by retailers
4.3 PERCEPTION of the risk events
The Bubble diagram reports the mean values of the three variables for each assessed risk event: impact
(vertical axis), probability (horizontal axis) and occurrence (bubble diameter, i.e. the larger the bubble
diameter, the more recently the risk event has occurred)
Show the occurrence affects the perception of the level of riskness of the evaluated events, especially in
terms of impact
4.4.PERCEPTION of the sources of risk
Retailers have a generally weaker perception of the sources of cyber and information risks in their supply chain
Hackers are seen as the most dangerous source of risk, ranking first in all groups of respondents
The ā€œhuman factorā€ and the ā€œenemy withinā€ are common threats to all categories of organizations in the FMCG
supply chain
Logistics Service Providers seem to perceive technical reasons as one of the main causes of risks for their business
continuity
4.4 INVOLVEMENT of the organizationā€™s department in
cyber and information risk management
Most involved
4.5 PERCEPTION of the criticality of the information shared
across the supply chain
Manufacturer on the master data and invoicing side along with data about their sales
Retailers on the discounts and promotional data along with inventory
Logistics Service Providers on transport data
4.6 PERCEPTION of the countermeasures andactions for
mitigating cyber risks
Level of perception regarding the
initiatives and countermeasures for
managing cyber risks
IT technical side is still dominant in
every stage of the FMCG supply chain
No unanimous consensus regarding
some technical measures
The perceptions
of risk events
5.1
The sources of
risk
5.2
The ownership
of the CSCRM
process
5.3 5.4
The
countermeasures
to mitigating
cyber risks
5. DISCUSSION
5.1. THE PERCEPTION of risk events
Logistics Service Providers have a broader perception of the risk events compared to
Manufacturers and Retailers
ā€¢ Those risks with higher occurrence are perceived more vividly compared
to other risk with lower values of occurrence
ā€¢ Little awareness leads to underestimating the importance of risk events
(and the other way around)
5.1. THE PERCEPTION of risk events
5.2. THE SOURCE of risk
ā€¢ The so-called ā€œhuman factorā€ is seen as one of the predominant threats to
cyber security in supply chains and this is in line with previous literature
(Ghadge et al., 2020).
ā€¢ Logistics Service Providers are more concerned about technical problems
that could undermine the continuity of their business operations
5.3. THE OWNERSHIP of the CRM process
ā€¢ The medium-high scores assigned to the majority of the business
departments
ā€¢ The human resources department is at the bottom of the list and this
shows a contradiction in terms of approach to the ā€œhuman factorā€ in the
CSCRM process
5.4.THE COUNTERMEASURE to mitigating cyber risks
Table 9 reports an
overall high level of
relevance assigned to
the set of initiatives
but a medium level of
alignment of the
respondentsā€™
perceptions related to
them.
Overall, a certain level of alignment of the perception about the elements composing the CSCRM
process among the various actors of the FMCG supply chain exists. In this case, it appears that
Manufacturers and Retailers are more focused on their domain rather than on the supply chain. On
the contrary, it seems that Logistics Service Providers can overcome this limitation and have a
broader perception of the risks, sources of risks and criticality of information and data exchanged
that span across the different stages of the supply chain.
DISCUSSION
6 .1. Theoretical implications
This study provides the scientific community with a vertical analysis of a
supply chain, something that extends the existing theory on CSCRM
It also contributes to extending the current theory with the proposal of
a paradigm that highlights the role of Logistics Service Providers as
ā€œorchestratorsā€ of the CSCRM process.
6. CONCLUSIONS
6 .2. Practical implications
This study provides the industrial community with thought-provoking
insights on the misalignment between the perceived relevance of the human
factor as a source of risk (high) and the perceived importance of
countermeasures to mitigate the risk events stemming from that source
(low)
This study could help organizations devise procedures and policies to report
incidents and create common and shared knowledge about risks that could
help them assess the level of risk in their supply chains more closely
01. č§£ę±ŗē”šéŗ¼å•é”Œ ?
02. ē‚ŗ什éŗ¼é€™å€‹å•é”Œå¾ˆé‡č¦ ?
03. ꏐå‡ŗēš„č«–é»žęˆ–å‡čŖŖę˜Æē”šéŗ¼ ?
6 .2. Practical implications
04. å¦‚ä½•č­‰ę˜Žä»–å€‘č«–é»žčˆ‡å‡čŖŖē‚ŗēœŸ ?
05. åÆ¦č­‰ē ”ē©¶čˆ‡ēµęžœ
06. å­øč”“č²¢ē»čˆ‡åÆ¦å‹™č²¢ē»
THANKS FOR LISTENING!

More Related Content

What's hot

PPT -Lean Supply Chain Presentation
PPT -Lean Supply Chain PresentationPPT -Lean Supply Chain Presentation
PPT -Lean Supply Chain PresentationIke. M Nwamuo, MSQA
Ā 
Trial exam questions+answers logistics and supply chain management 2
Trial exam questions+answers logistics and supply chain management 2Trial exam questions+answers logistics and supply chain management 2
Trial exam questions+answers logistics and supply chain management 2Khaoula Marai
Ā 
Strategic supply chain management and logistics
Strategic supply chain management and logisticsStrategic supply chain management and logistics
Strategic supply chain management and logisticsBhavi Bhatia
Ā 
Supply chain managements
Supply chain managementsSupply chain managements
Supply chain managementsSarwat Shabbir
Ā 
Seminar Report on Supply Chain Management
Seminar Report on Supply Chain ManagementSeminar Report on Supply Chain Management
Seminar Report on Supply Chain ManagementAnkur Mehta
Ā 
Logistics and supply chain management in the hotel industry impa
Logistics and supply chain management in the hotel industry  impaLogistics and supply chain management in the hotel industry  impa
Logistics and supply chain management in the hotel industry impahoannguyen
Ā 
Supply chain management
Supply chain managementSupply chain management
Supply chain managementMohammed Kurmot
Ā 
Trends in Supply Chain Management - Presentation by GRA Supply Chain Consultants
Trends in Supply Chain Management - Presentation by GRA Supply Chain ConsultantsTrends in Supply Chain Management - Presentation by GRA Supply Chain Consultants
Trends in Supply Chain Management - Presentation by GRA Supply Chain ConsultantsRebecca Manjra
Ā 
MIS 14 Supply Chain Management
MIS 14 Supply Chain ManagementMIS 14 Supply Chain Management
MIS 14 Supply Chain ManagementTushar B Kute
Ā 
Supply chain management practice by Spining Industry.
Supply chain management practice by Spining Industry.Supply chain management practice by Spining Industry.
Supply chain management practice by Spining Industry.Monir Uz Zaman
Ā 
Srm Presentation
Srm PresentationSrm Presentation
Srm PresentationMuhammed Akgun
Ā 
Emerging trends in supply chain management
Emerging trends in supply chain managementEmerging trends in supply chain management
Emerging trends in supply chain managementeSAT Publishing House
Ā 
Supply chain in Pakistan
Supply chain in PakistanSupply chain in Pakistan
Supply chain in PakistanMuneeb Ahmed
Ā 
Introduction to supply chain management (scm)
Introduction to supply chain management (scm)Introduction to supply chain management (scm)
Introduction to supply chain management (scm)Catherine Royer-Hoyez
Ā 
Supply Chain Management_Presentation
Supply Chain Management_PresentationSupply Chain Management_Presentation
Supply Chain Management_PresentationA. K. M. Nayeemul Hassan
Ā 
IT in supply chains
IT in supply chainsIT in supply chains
IT in supply chainsiskandaruz
Ā 
SCM & CRM & ERP
SCM & CRM & ERPSCM & CRM & ERP
SCM & CRM & ERPRanak Ghosh
Ā 

What's hot (20)

PPT -Lean Supply Chain Presentation
PPT -Lean Supply Chain PresentationPPT -Lean Supply Chain Presentation
PPT -Lean Supply Chain Presentation
Ā 
Trial exam questions+answers logistics and supply chain management 2
Trial exam questions+answers logistics and supply chain management 2Trial exam questions+answers logistics and supply chain management 2
Trial exam questions+answers logistics and supply chain management 2
Ā 
Strategic supply chain management and logistics
Strategic supply chain management and logisticsStrategic supply chain management and logistics
Strategic supply chain management and logistics
Ā 
Supply chain managements
Supply chain managementsSupply chain managements
Supply chain managements
Ā 
Seminar Report on Supply Chain Management
Seminar Report on Supply Chain ManagementSeminar Report on Supply Chain Management
Seminar Report on Supply Chain Management
Ā 
Logistics and supply chain management in the hotel industry impa
Logistics and supply chain management in the hotel industry  impaLogistics and supply chain management in the hotel industry  impa
Logistics and supply chain management in the hotel industry impa
Ā 
Supply chain management
Supply chain managementSupply chain management
Supply chain management
Ā 
Chapter 1
Chapter 1Chapter 1
Chapter 1
Ā 
Demand chain management
Demand chain managementDemand chain management
Demand chain management
Ā 
Trends in Supply Chain Management - Presentation by GRA Supply Chain Consultants
Trends in Supply Chain Management - Presentation by GRA Supply Chain ConsultantsTrends in Supply Chain Management - Presentation by GRA Supply Chain Consultants
Trends in Supply Chain Management - Presentation by GRA Supply Chain Consultants
Ā 
MIS 14 Supply Chain Management
MIS 14 Supply Chain ManagementMIS 14 Supply Chain Management
MIS 14 Supply Chain Management
Ā 
Supply chain management practice by Spining Industry.
Supply chain management practice by Spining Industry.Supply chain management practice by Spining Industry.
Supply chain management practice by Spining Industry.
Ā 
Srm Presentation
Srm PresentationSrm Presentation
Srm Presentation
Ā 
Emerging trends in supply chain management
Emerging trends in supply chain managementEmerging trends in supply chain management
Emerging trends in supply chain management
Ā 
Supply Chain Management & new trends
Supply Chain Management & new trendsSupply Chain Management & new trends
Supply Chain Management & new trends
Ā 
Supply chain in Pakistan
Supply chain in PakistanSupply chain in Pakistan
Supply chain in Pakistan
Ā 
Introduction to supply chain management (scm)
Introduction to supply chain management (scm)Introduction to supply chain management (scm)
Introduction to supply chain management (scm)
Ā 
Supply Chain Management_Presentation
Supply Chain Management_PresentationSupply Chain Management_Presentation
Supply Chain Management_Presentation
Ā 
IT in supply chains
IT in supply chainsIT in supply chains
IT in supply chains
Ā 
SCM & CRM & ERP
SCM & CRM & ERPSCM & CRM & ERP
SCM & CRM & ERP
Ā 

Similar to Ppt cscrm (1)

SupplyChainRiskAreas
SupplyChainRiskAreasSupplyChainRiskAreas
SupplyChainRiskAreasJeremy Castle
Ā 
Supply Chain Risk Management corrected - Whitepaper
Supply Chain Risk Management corrected - WhitepaperSupply Chain Risk Management corrected - Whitepaper
Supply Chain Risk Management corrected - WhitepaperNIIT Technologies
Ā 
ORX Cyber Risk Presentation March 2019
ORX Cyber Risk Presentation March 2019ORX Cyber Risk Presentation March 2019
ORX Cyber Risk Presentation March 2019Amy Lauder
Ā 
Effective Solutions for Your Supply Chain Risks
Effective Solutions for Your Supply Chain RisksEffective Solutions for Your Supply Chain Risks
Effective Solutions for Your Supply Chain RisksHalo BI
Ā 
Assuring the Security of the Supply Chain - Designing best practices for cybe...
Assuring the Security of the Supply Chain - Designing best practices for cybe...Assuring the Security of the Supply Chain - Designing best practices for cybe...
Assuring the Security of the Supply Chain - Designing best practices for cybe...Ollie Whitehouse
Ā 
SCL Event - Louis Ferretti - IBM - Project Executive, Product Environmental ...
SCL Event -  Louis Ferretti - IBM - Project Executive, Product Environmental ...SCL Event -  Louis Ferretti - IBM - Project Executive, Product Environmental ...
SCL Event - Louis Ferretti - IBM - Project Executive, Product Environmental ...Global Business Intel
Ā 
Supply Chain optimization & risks factors
Supply Chain optimization & risks factorsSupply Chain optimization & risks factors
Supply Chain optimization & risks factorsAlok Anand
Ā 
Managed Detection and Response (MDR) Whitepaper
Managed Detection and Response (MDR) WhitepaperManaged Detection and Response (MDR) Whitepaper
Managed Detection and Response (MDR) WhitepaperMarc St-Pierre
Ā 
Cloud Cybersecurity: Strategies for Managing Vendor Risk
Cloud Cybersecurity: Strategies for Managing Vendor RiskCloud Cybersecurity: Strategies for Managing Vendor Risk
Cloud Cybersecurity: Strategies for Managing Vendor RiskHealth Catalyst
Ā 
Supply chain predictability - English.pdf
Supply chain predictability - English.pdfSupply chain predictability - English.pdf
Supply chain predictability - English.pdfKarthikeyan Muthukrishnan
Ā 
The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...
The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...
The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...Symantec
Ā 
The State of Cybersecurity and Digital Trust 2016
The State of Cybersecurity and Digital Trust 2016The State of Cybersecurity and Digital Trust 2016
The State of Cybersecurity and Digital Trust 2016Accenture Operations
Ā 
FMEA - Achieve Operational Excellence.pdf
FMEA - Achieve Operational Excellence.pdfFMEA - Achieve Operational Excellence.pdf
FMEA - Achieve Operational Excellence.pdfHamza Arif
Ā 
Mitigating the Risk of Counterfeit ICT in the DoD Supply Chain
Mitigating the Risk of Counterfeit ICT in the DoD Supply ChainMitigating the Risk of Counterfeit ICT in the DoD Supply Chain
Mitigating the Risk of Counterfeit ICT in the DoD Supply ChainKyrl Erickson
Ā 
CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...
CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...
CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...Global Business Intel
Ā 
Overcoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOvercoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOnRamp
Ā 
Preventing and Managing Supply Chain Disruptions
Preventing and Managing Supply Chain DisruptionsPreventing and Managing Supply Chain Disruptions
Preventing and Managing Supply Chain DisruptionsThomas Tanel
Ā 
Cybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdfCybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdfDaveNjoga1
Ā 
IT Security Risks Survey 2014
IT Security Risks Survey 2014IT Security Risks Survey 2014
IT Security Risks Survey 2014- Mark - Fullbright
Ā 

Similar to Ppt cscrm (1) (20)

SupplyChainRiskAreas
SupplyChainRiskAreasSupplyChainRiskAreas
SupplyChainRiskAreas
Ā 
Supply Chain Risk Management corrected - Whitepaper
Supply Chain Risk Management corrected - WhitepaperSupply Chain Risk Management corrected - Whitepaper
Supply Chain Risk Management corrected - Whitepaper
Ā 
ORX Cyber Risk Presentation March 2019
ORX Cyber Risk Presentation March 2019ORX Cyber Risk Presentation March 2019
ORX Cyber Risk Presentation March 2019
Ā 
Supply Chain Mgmt Risks
Supply Chain Mgmt Risks Supply Chain Mgmt Risks
Supply Chain Mgmt Risks
Ā 
Effective Solutions for Your Supply Chain Risks
Effective Solutions for Your Supply Chain RisksEffective Solutions for Your Supply Chain Risks
Effective Solutions for Your Supply Chain Risks
Ā 
Assuring the Security of the Supply Chain - Designing best practices for cybe...
Assuring the Security of the Supply Chain - Designing best practices for cybe...Assuring the Security of the Supply Chain - Designing best practices for cybe...
Assuring the Security of the Supply Chain - Designing best practices for cybe...
Ā 
SCL Event - Louis Ferretti - IBM - Project Executive, Product Environmental ...
SCL Event -  Louis Ferretti - IBM - Project Executive, Product Environmental ...SCL Event -  Louis Ferretti - IBM - Project Executive, Product Environmental ...
SCL Event - Louis Ferretti - IBM - Project Executive, Product Environmental ...
Ā 
Supply Chain optimization & risks factors
Supply Chain optimization & risks factorsSupply Chain optimization & risks factors
Supply Chain optimization & risks factors
Ā 
Managed Detection and Response (MDR) Whitepaper
Managed Detection and Response (MDR) WhitepaperManaged Detection and Response (MDR) Whitepaper
Managed Detection and Response (MDR) Whitepaper
Ā 
Cloud Cybersecurity: Strategies for Managing Vendor Risk
Cloud Cybersecurity: Strategies for Managing Vendor RiskCloud Cybersecurity: Strategies for Managing Vendor Risk
Cloud Cybersecurity: Strategies for Managing Vendor Risk
Ā 
Supply chain predictability - English.pdf
Supply chain predictability - English.pdfSupply chain predictability - English.pdf
Supply chain predictability - English.pdf
Ā 
The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...
The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...
The Stand Against Cyber Criminals Lawyers, Take The Stand Against Cyber Crimi...
Ā 
The State of Cybersecurity and Digital Trust 2016
The State of Cybersecurity and Digital Trust 2016The State of Cybersecurity and Digital Trust 2016
The State of Cybersecurity and Digital Trust 2016
Ā 
FMEA - Achieve Operational Excellence.pdf
FMEA - Achieve Operational Excellence.pdfFMEA - Achieve Operational Excellence.pdf
FMEA - Achieve Operational Excellence.pdf
Ā 
Mitigating the Risk of Counterfeit ICT in the DoD Supply Chain
Mitigating the Risk of Counterfeit ICT in the DoD Supply ChainMitigating the Risk of Counterfeit ICT in the DoD Supply Chain
Mitigating the Risk of Counterfeit ICT in the DoD Supply Chain
Ā 
CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...
CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...
CPO Event - Louis Ferretti, What Every Procurement Professional Should Know ...
Ā 
Overcoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOvercoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security Model
Ā 
Preventing and Managing Supply Chain Disruptions
Preventing and Managing Supply Chain DisruptionsPreventing and Managing Supply Chain Disruptions
Preventing and Managing Supply Chain Disruptions
Ā 
Cybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdfCybersec Supply Chain Risks and Governance v0.1.pdf
Cybersec Supply Chain Risks and Governance v0.1.pdf
Ā 
IT Security Risks Survey 2014
IT Security Risks Survey 2014IT Security Risks Survey 2014
IT Security Risks Survey 2014
Ā 

Recently uploaded

VIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130 Available With Room
VIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130  Available With RoomVIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130  Available With Room
VIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130 Available With Roomdivyansh0kumar0
Ā 
Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...lizamodels9
Ā 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
Ā 
Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...lizamodels9
Ā 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
Ā 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
Ā 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
Ā 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
Ā 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Serviceankitnayak356677
Ā 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
Ā 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdfOrient Homes
Ā 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
Ā 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
Ā 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
Ā 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
Ā 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechNewman George Leech
Ā 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...lizamodels9
Ā 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear RegressionRavindra Nath Shukla
Ā 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
Ā 

Recently uploaded (20)

VIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130 Available With Room
VIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130  Available With RoomVIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130  Available With Room
VIP Kolkata Call Girl Howrah šŸ‘‰ 8250192130 Available With Room
Ā 
Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ā¤ļø88604**77959_Russian 100% Genuine Escor...
Ā 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Ā 
Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ā¤ļø8860477959 Escorts 100% Genuine Servi...
Ā 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
Ā 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
Ā 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
Ā 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Ā 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Ā 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
Ā 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdf
Ā 
Best Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting PartnershipBest Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting Partnership
Ā 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
Ā 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
Ā 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
Ā 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
Ā 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman Leech
Ā 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ā¤ļø8860477959 Escorts...
Ā 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
Ā 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
Ā 

Ppt cscrm (1)

  • 1. WHO CARES? SUPPLY CHAIN MANAGERSā€™ PERCEPTIONS REGARDING CYBER SUPPLY CHAIN RISK MANAGEMENT IN THE DIGITAL TRANSFORMATION ERA 109578401 HOANG TO NHU 109578403 DO THI TRANG 109678402 NGUYEN THI HONG NHUNG
  • 2. Perceptions of supply chain managers for cyber supply chain risk management (CSCRM) How can organizations deploy a CSCRM strategy? ABSTRACT
  • 3. Digital transformation Cyber supply chain Cyber security 1. INTRODUCTION
  • 5. CYBER SECURITY CYBER RISKS COMPANIES CSCRM in a supply chain are seen as the top threats tend to adopt security measures to protect themselves is necessary for a better level of resilience through the cyber supply chain ORGANIZATIONS LITERATURE involved in a supply chain do not make the same decisions gives technical aspects rather than organization aspects across the supply chain as top threats
  • 6. THIS RESEARCH helps organizations to understand how they can deploy a cyber security strategy RQ1. How relevant are the elements of CSCRM perceived by companies in a supply chain? RQ2. How aligned are the perceptions about CSCRM of companies in a supply chain?
  • 7. Manufacturers Logistics Providers Retailers Survey of the perceptions of supply chain managers regarding 3 main stages: Section 2: Overview of the literature of CSCRM Section 3: Research methodology Section 4: Investigation results Section 5: Findings of the analysis Section 6: Conclusion
  • 8. 2. THEORETICAL BACKGROUND Cyber supply chain risk management (CSCRM)
  • 9. CSCRM PURPOSE is to extend control on cyber risks which enables a continuously adaptive capacity. Supply chain resilience relates to a fit between riskiness and related level of preparedness to manage the risks. Humans are limited to make objective estimations.
  • 10. INDIVIDUALS seem to rely on their perception of risks on their own confidence and belief. Decisions are subjective for what might happen and how they think it might affect. Different approaches by different people make different effects.
  • 11. Cyber risks Sources of risks Responsibility and ownership of the CSCRM Information exchanged Countermeasures to manage cyber risks. CSCRM process includes
  • 12. Initiatives and countermeasures to manage cyber risks Sources of cyber risks Cyber risks in supply chain Responsibility of CSCRM process 34% 25% 34% 2% ELEMENTS OF CSCRM PROCESS Information exchanged in the supply chain 5%
  • 13. 2.1 CYBER RISKS in supply chain ā€¢ Type 1 includes incidents of phishing and theft or data manipulation. ā€¢ Type 2 covers cyberstalking and harassment, stock market manipulation, blackmailing and corporate espionage.
  • 14. BACKBONE RISKS ā€¢ ERP system malfunction ā€¢ Crash of companyā€™s website ā€¢ Lack of network connectivity ā€¢ Malware ā€¢ Data breach ā€¢ Damage of records ā€¢ Theft of credentials
  • 15. 2.2 SOURCES of cyber risks INTERNAL EXTERNAL MALICIOUS NON-INTENTIONAL Suppliers/contractors Current employees Former employees Suppliers/ contractors Customers Competitors Hackers/ Hacktivists Current employees Former employees Technical problems Customers Natural disasters Technical problems Colicchia (2019)
  • 16. 2.2 SOURCES of cyber risks ā€¢ Employees ā€¢ Physical objects ā€¢ Technical assets Ghade (2020)
  • 17. 2.3 RESPONSIBILITY AND OWNERSHIP of CSCRM process ā€¢ Entire company should engage in the CSCRM process with strong commitment. ā€¢ Cyber security should be a department in the company.
  • 18. 2.4 INFORMATION EXCHANGED in the supply chain Inventory Sales data Invoices Discounts Order status Production plan Performance Master data
  • 19. 2.5 INITIATIVES AND COUNTERMEASURES to manage cyber risks Pre-attack Actions at the technical level and those directed at or carried out by human factors Trans-attack Data consistency checks and task forces Post-attack Forensics, incident documentation, insurance and recovery and backup procedures Companies seem to respond with pre-attacker phase rather than the others. However, all phases should have a varied set of actions to cover different attacks and different risk environments.
  • 21. 3.1 SAMPLE Focus on a specific sector, specifically the FMCG industry in Italy The Italian FMCG industry is placed among the top four markets in Europe for logistics flows and generated turnover, and it is one of the fastest-growing sectors across Europe, after Spain in 2016 The Italian FMCG supply chain has gone through a deep transformation, leading to the adoption of the principles of efficient consumer response (ECR) and IT technologies
  • 22. 3.1 SAMPLE AND DATABASE The questionnaire was distributed to 524 companies, with the following representation: 321 manufacturers, 134 logistics service providers and 69 retailers. Managers in charge of supply chain management or logistics are chosen as potential respondents for this survey (with minimum 5 years experience) 112 full questionnaires returned.
  • 23. 3.1 DESIGN The resulting questionnaire consisted of six different sections The questions were measured by five-point Likert scales, ranging from ā€œvery relevantā€ to ā€œnot relevantā€, from ā€œlow impactā€ to ā€œvery high impactā€ (according to the assessment scale presented by Hallikas et al., 2004) or from ā€œvery low probabilityā€ to ā€œvery high probabilityā€ (according to the assessment scale presented by Hallikas et al., 2004) Use ANOVA with F statistics value with a significance level of 5% to analyse the results.
  • 24. 4. RESULTS 4.3. Perception of the sources of risk 4.2. Perception of the risk events 4.1. Profile of the respondentsā€™ sample 4.4. Involvement of the organizationā€™s departments in cyber and information risk management 4.5. Perception of the criticality of the information shared across the supply chain 4.6. Perception of the countermeasures and actions for mitigating cyber risks
  • 25. 4.1 PROFILE of the respondentsā€™ sample 64 manufacturers 31 logistics service providers 17 retailers
  • 26. 4.2 PERCEPTION of the risk events the whole FMCG supply chain has experienced the same risk events an almost unanimous consensus around the two events considered to be the most dangerous ones Malware has been judged to be a high risk, especially by retailers
  • 27. 4.3 PERCEPTION of the risk events The Bubble diagram reports the mean values of the three variables for each assessed risk event: impact (vertical axis), probability (horizontal axis) and occurrence (bubble diameter, i.e. the larger the bubble diameter, the more recently the risk event has occurred) Show the occurrence affects the perception of the level of riskness of the evaluated events, especially in terms of impact
  • 28. 4.4.PERCEPTION of the sources of risk Retailers have a generally weaker perception of the sources of cyber and information risks in their supply chain Hackers are seen as the most dangerous source of risk, ranking first in all groups of respondents The ā€œhuman factorā€ and the ā€œenemy withinā€ are common threats to all categories of organizations in the FMCG supply chain Logistics Service Providers seem to perceive technical reasons as one of the main causes of risks for their business continuity
  • 29. 4.4 INVOLVEMENT of the organizationā€™s department in cyber and information risk management Most involved
  • 30. 4.5 PERCEPTION of the criticality of the information shared across the supply chain Manufacturer on the master data and invoicing side along with data about their sales Retailers on the discounts and promotional data along with inventory Logistics Service Providers on transport data
  • 31. 4.6 PERCEPTION of the countermeasures andactions for mitigating cyber risks Level of perception regarding the initiatives and countermeasures for managing cyber risks IT technical side is still dominant in every stage of the FMCG supply chain No unanimous consensus regarding some technical measures
  • 32. The perceptions of risk events 5.1 The sources of risk 5.2 The ownership of the CSCRM process 5.3 5.4 The countermeasures to mitigating cyber risks 5. DISCUSSION
  • 33. 5.1. THE PERCEPTION of risk events Logistics Service Providers have a broader perception of the risk events compared to Manufacturers and Retailers
  • 34. ā€¢ Those risks with higher occurrence are perceived more vividly compared to other risk with lower values of occurrence ā€¢ Little awareness leads to underestimating the importance of risk events (and the other way around) 5.1. THE PERCEPTION of risk events
  • 35. 5.2. THE SOURCE of risk ā€¢ The so-called ā€œhuman factorā€ is seen as one of the predominant threats to cyber security in supply chains and this is in line with previous literature (Ghadge et al., 2020). ā€¢ Logistics Service Providers are more concerned about technical problems that could undermine the continuity of their business operations
  • 36. 5.3. THE OWNERSHIP of the CRM process ā€¢ The medium-high scores assigned to the majority of the business departments ā€¢ The human resources department is at the bottom of the list and this shows a contradiction in terms of approach to the ā€œhuman factorā€ in the CSCRM process
  • 37. 5.4.THE COUNTERMEASURE to mitigating cyber risks Table 9 reports an overall high level of relevance assigned to the set of initiatives but a medium level of alignment of the respondentsā€™ perceptions related to them.
  • 38. Overall, a certain level of alignment of the perception about the elements composing the CSCRM process among the various actors of the FMCG supply chain exists. In this case, it appears that Manufacturers and Retailers are more focused on their domain rather than on the supply chain. On the contrary, it seems that Logistics Service Providers can overcome this limitation and have a broader perception of the risks, sources of risks and criticality of information and data exchanged that span across the different stages of the supply chain. DISCUSSION
  • 39. 6 .1. Theoretical implications This study provides the scientific community with a vertical analysis of a supply chain, something that extends the existing theory on CSCRM It also contributes to extending the current theory with the proposal of a paradigm that highlights the role of Logistics Service Providers as ā€œorchestratorsā€ of the CSCRM process. 6. CONCLUSIONS
  • 40. 6 .2. Practical implications This study provides the industrial community with thought-provoking insights on the misalignment between the perceived relevance of the human factor as a source of risk (high) and the perceived importance of countermeasures to mitigate the risk events stemming from that source (low) This study could help organizations devise procedures and policies to report incidents and create common and shared knowledge about risks that could help them assess the level of risk in their supply chains more closely
  • 41. 01. č§£ę±ŗē”šéŗ¼å•é”Œ ? 02. ē‚ŗ什éŗ¼é€™å€‹å•é”Œå¾ˆé‡č¦ ? 03. ꏐå‡ŗēš„č«–é»žęˆ–å‡čŖŖę˜Æē”šéŗ¼ ? 6 .2. Practical implications
  • 42. 04. å¦‚ä½•č­‰ę˜Žä»–å€‘č«–é»žčˆ‡å‡čŖŖē‚ŗēœŸ ? 05. åÆ¦č­‰ē ”ē©¶čˆ‡ēµęžœ 06. å­øč”“č²¢ē»čˆ‡åÆ¦å‹™č²¢ē»