Cyberattacks are no longer purely an IT problem. Today, they affect supply chains, logistics processes, payment systems, production operations and digital platforms. This is precisely why cyber resilience is becoming increasingly important for companies in industry and retail. When a critical service provider becomes unavailable, a logistics system is blocked or a payment process stops working, the result can quickly become an operational risk with direct consequences for revenue, customer satisfaction and security of supply.
The Swiss Federal Office for Cybersecurity (BACS) highlighted this issue prominently at the “Cyber Security Forum – Industry and Retail”, organised together with Markant AG. The focus was not only on the technical defence against cyberattacks, but on the resilience of entire value chains. For GRC professionals, this sends an important signal: cybersecurity, supplier management, Business Continuity Management and governance need to become much more closely integrated.
Key Takeaways
BACS makes it clear that industry and retail are particularly vulnerable to cyber disruptions across the supply chain because of their high level of digital interconnectedness.
Dependencies on suppliers, logistics providers, IT providers, digital platforms and payment systems are particularly critical.
For companies, it is no longer sufficient to focus on individual technical security measures. What is required is an integrated GRC approach that centrally manages risks, controls, suppliers, continuity plans, responsibilities and evidence.
Vendor Risk Management, Business Continuity Management, Incident Management and a robust Information Security Management System based on ISO 27001 are becoming particularly important.
Why Supply Chains Are Becoming a Cyber Risk
Modern industrial and retail companies are highly interconnected. Orders, inventory levels, transport data, payment information, production planning and customer communication all depend on digital systems.
Many of these processes are no longer operated entirely in-house. Instead, companies rely on external partners, digital platforms, cloud services, software providers and logistics companies.
This connectivity creates efficiency, but it also introduces new attack surfaces. A cyberattack on one supplier can affect numerous other companies. A compromised service provider can put sensitive data at risk. An outage of a logistics system can delay deliveries. A disruption to payment processing can directly affect sales.
For GRC professionals, this means that the organisation’s risk profile does not end at the company boundary. It also includes critical third parties, digital interfaces, outsourced processes and dependencies throughout the value chain.
Cyber Resilience Is More Than IT Security
Many companies still treat cybersecurity primarily as the responsibility of the IT department. This perspective is too narrow.
Cyber resilience describes an organisation’s ability to prevent cyber incidents, detect them, respond effectively and rapidly restore business operations following a disruption.
This involves several management disciplines at the same time:
- Information security ensures that systems, data and processes are adequately protected.
- Risk management assesses which threats are particularly relevant to critical business processes.
- Compliance ensures that regulatory requirements, internal policies and customer requirements are fulfilled.
- Business Continuity Management defines how critical processes can be maintained or restored during a crisis.
- Vendor Risk Management evaluates whether external partners provide the required level of security and resilience.
- Incident Management ensures that incidents are rapidly detected, assessed, escalated and documented.
Real cyber resilience only emerges when these disciplines work together.
Why Industry and Retail Are Particularly Exposed
Industry and retail are highly dependent on functioning supply, logistics and payment processes. At the same time, companies in these sectors work with large numbers of external partners.
These include manufacturers, retailers, wholesalers, transport companies, payment providers, IT service providers, platform providers, software suppliers and cloud providers.
An outage can therefore spread quickly across the value chain.
If a supplier cannot deliver, products become unavailable. If a logistics provider cannot schedule shipments, goods remain stuck. If an ERP system becomes unavailable, orders, invoices and inventory movements may no longer be processed. If payment systems fail, companies can experience immediate revenue losses.
In addition, many organisations operate under significant pressure regarding time, margins and availability. Cyber resilience is therefore not only a security issue. It is also a question of operational stability and competitiveness.
The Role of GRC in Building Resilient Supply Chains
Governance, Risk and Compliance provide the organisational framework required to make cyber risks across the supply chain manageable.
Without clear governance, responsibilities remain unclear. Without risk management, critical dependencies are overlooked. Without compliance and appropriate evidence management, organisations cannot demonstrate their controls to regulators, customers, auditors or management.
An effective GRC approach should answer at least the following questions:
- Which suppliers and service providers are critical to our business processes?
- Which systems, data and interfaces connect us with these partners?
- Which cyber risks could affect our ability to deliver, manufacture, manage logistics or process payments?
- What minimum information security requirements do we impose on suppliers?
- How do we regularly verify compliance with these requirements?
- Which continuity plans exist if a critical service provider becomes unavailable?
- How do we document risks, measures, controls and responsibilities?
- How quickly can we respond during an incident and provide relevant information to regulators or other stakeholders?
These questions demonstrate that resilience cannot be achieved through isolated measures. It requires a continuous management system.
ISO 27001 as a Foundation for Supply Chain Resilience
ISO 27001 is a key starting point for many companies looking to manage information security systematically.
The standard requires a risk-based approach, clear responsibilities, defined controls, regular reviews and continuous improvement.
ISO 27001 is particularly relevant in the context of supply chain cybersecurity. Companies must consider not only internal risks, but also risks arising from external relationships, outsourced processes and dependencies on service providers.
This includes supplier security requirements, contractual security obligations, access controls, monitoring, incident processes and evidence.
For industry and retail, ISO 27001 can therefore provide a foundation for connecting cybersecurity, Vendor Risk Management and Business Continuity Management.
Companies that already operate an ISMS should evaluate whether supply chain risks are sufficiently integrated. Organisations without a structured ISMS should use current developments as an opportunity to establish a systematic approach to information security.
Vendor Risk Management: Suppliers Need to Be Managed, Not Just Procured
Many companies have established procurement processes but lack sufficiently mature Vendor Risk Management.
It is no longer enough to assess a supplier once and then mark it as “approved”. Cyber risks continuously change. New systems, interfaces, subcontractors and threats can rapidly alter the risk profile.
Modern Vendor Risk Management should therefore follow a risk-based approach.
Critical suppliers require more detailed assessments, stricter requirements and more frequent reviews than less critical partners.
The key is to establish clear connections between the supplier, the relevant business process, the associated risks, contractual requirements, controls and remediation measures.
Typical components of effective Vendor Risk Management include:
- Supplier classification based on criticality
- Security questionnaires and evidence requirements
- Assessment of certifications such as ISO 27001
- Contractual security and notification obligations
- Assessment of subcontractors and cloud dependencies
- Regular reassessments
- Remediation tracking for identified weaknesses
- Integration with Incident Management and BCM processes
This transforms supplier management from an administrative task into a strategic risk management capability.
Business Continuity Management: What Happens When a Critical Partner Fails?
Cyber resilience is not only about preventing attacks. What matters equally is how well an organisation is prepared for disruption.
Business Continuity Management addresses one fundamental question: Which processes need to continue operating under difficult conditions, and how can the organisation ensure that they do?
For industry and retail, particularly relevant scenarios include:
- Failure of a critical logistics provider
- Unavailability of an ERP or inventory management system
- Disruption of payment processes
- Cyberattack against a critical supplier
- Ransomware incident affecting a service provider
- Failure of a cloud platform
- Loss of access to ordering, inventory or delivery data
Effective BCM combines Business Impact Analysis, recovery plans, crisis communication, defined responsibilities, escalation paths and regular testing.
External dependencies need to be explicitly incorporated into this process. Only then can companies realistically assess how resilient their operations actually are.
Incident Management: Fast Response Requires Clear Processes
When a cyber incident occurs, every hour counts.
Companies need to quickly determine who makes decisions, who needs to be informed, which systems are affected, which partners need to be involved and whether regulatory notification obligations apply.
Supply chain incidents can be particularly complex.
An incident may originate at an external service provider, spread to internal systems through digital interfaces and simultaneously affect customers, authorities or additional partners.
Without predefined Incident Management processes, organisations risk delays, information gaps and unnecessary exposure.
A robust Incident Management process should therefore be connected directly to Vendor Risk Management and Business Continuity Management.
Critical suppliers need to be incorporated into escalation processes. Contact persons, notification channels and contractual obligations must be known in advance. Incidents must be documented, assessed and reviewed after resolution.
Regulatory Pressure Continues to Increase
Although the BACS forum itself does not constitute new regulation, its focus on supply chain resilience reflects a broader regulatory trend.
Across Europe and Switzerland, pressure on companies to systematically manage cyber risks and provide evidence of appropriate security measures continues to increase.
NIS2, DORA, the Cyber Resilience Act, data protection requirements and sector-specific regulations all have several elements in common: they demand greater transparency, stronger third-party risk management, clear responsibilities and robust documentation.
Even organisations that are not directly regulated can be affected indirectly through customer requirements, supplier assessments or contractual obligations.
For GRC teams, the implication is clear: individual regulatory requirements should no longer be managed in isolation.
Companies need an integrated view of risks, controls, policies, audits, suppliers and incidents.
What Companies Should Do Now
BACS’s focus on industry, retail and supply chain cyber resilience provides a good opportunity for companies to assess their current position.
Organisations should evaluate whether their GRC structures accurately reflect the real dependencies within their value chain.
Five steps are particularly important.
First, companies should identify their critical business processes. These include processes whose disruption would have a direct impact on revenue, security of supply, production, customer service or regulatory obligations.
Second, critical suppliers, service providers and digital platforms should be mapped to these business processes. Only then can companies understand which external dependencies are truly critical.
Third, cyber risks associated with these dependencies should be assessed. This should cover not only technical vulnerabilities, but also availability, data access, subcontractors, incident response capabilities and recovery times.
Fourth, appropriate controls and measures should be defined. These include security requirements, contractual provisions, continuity plans, regular reviews and evidence requirements.
Fifth, all relevant information should be documented centrally and reviewed regularly. Without a central data foundation, risks remain fragmented and audits become unnecessarily complex.
Why Excel and Email Are Not Enough
Many companies still manage supplier risks, continuity plans and compliance evidence using Excel spreadsheets, email and separate document repositories.
This may work for small individual processes. However, it is not sufficient for robust GRC management across complex supply chains.
The core problem is the lack of connection between information.
A supplier may be stored in one spreadsheet, a related risk in another, the contract in a document folder, an audit report as an email attachment and the continuity plan in a separate file.
As a result, it becomes difficult to determine which risks remain open, which measures are overdue and which controls are actually effective.
A GRC platform creates structure by connecting suppliers, risks, controls, measures, responsibilities, audits, incidents and BCM scenarios.
This provides a unified view of cyber resilience and supply chain risk.
Conclusion
Through its Cyber Security Forum for industry and retail, BACS sends a clear signal: cybersecurity needs to be viewed from the perspective of entire value chains.
For companies, this means that suppliers, logistics providers, payment processes and digital platforms need to be integrated into GRC management.
Cyber resilience is not achieved through individual technical security measures. It requires clear governance, risk-based supplier management, robust Business Continuity Management, effective Incident Management processes and auditable evidence.
Companies that connect these elements today not only reduce cyber risk. They also strengthen operational stability, regulatory readiness and trust among customers and business partners.
For industry and retail, now is the right time to stop treating supply chain risks as a secondary issue. They belong at the centre of a modern GRC strategy.
FAQ: Supply Chain Cyber Resilience and GRC
What does cyber resilience in the supply chain mean?
Supply chain cyber resilience describes an organisation’s ability to identify and manage cyber risks across external dependencies while remaining operational during disruptions.
These dependencies include suppliers, logistics providers, IT service providers, digital platforms, payment providers and other critical partners.
Why are industry and retail particularly vulnerable to supply chain cyber risks?
Industry and retail rely heavily on external partners and interconnected digital systems.
Orders, deliveries, inventories, payments and production processes are highly interconnected. If a critical service provider becomes unavailable or is compromised, the consequences can directly affect availability, revenue and customer service.
What role does GRC play in cyber resilience?
GRC provides the organisational framework required to systematically manage cyber risks.
Governance defines responsibilities, Risk Management assesses threats and dependencies, and Compliance ensures that requirements are fulfilled and supporting evidence is available.
Together, these disciplines make cyber resilience manageable and auditable.
How does ISO 27001 help manage supply chain risks?
ISO 27001 provides a risk-based framework for information security.
It helps companies systematically manage risks, controls, responsibilities and improvement measures. In a supply chain context, ISO 27001 supports the structured management of external dependencies, service provider risks and supplier security requirements.
What is the difference between Vendor Risk Management and traditional supplier management?
Traditional supplier management often focuses on pricing, service, contracts and quality.
Vendor Risk Management additionally considers risks such as information security, data protection, business continuity, subcontractors, regulatory requirements and incident response capabilities.
It is therefore a core component of modern cyber resilience.
Why is Business Continuity Management important for supply chains?
Business Continuity Management helps ensure that critical business processes can continue or be restored quickly during disruptions.
If a supplier, logistics system or IT service provider fails, organisations need clear continuity plans, defined responsibilities and recovery strategies.
Which companies should take action now?
Any organisation whose critical business processes depend heavily on digital systems, external service providers, supply chains, logistics or payment systems should take action.
This is particularly relevant for manufacturing, industry, retail, logistics, food supply, production companies and regulated sectors.
How can Zazoon support supply chain cyber resilience?
Zazoon helps companies centrally manage risks, suppliers, controls, audits, incidents and BCM processes.
This creates an integrated view of cyber resilience, supply chain risks and compliance requirements. Organisations can structure evidence more effectively, assign responsibilities clearly and consistently track remediation measures.
Table of Contents
- Key Takeaways
- Why Supply Chains Are Becoming a Cyber Risk
- Cyber Resilience Is More Than IT Security
- Why Industry and Retail Are Particularly Exposed
- The Role of GRC in Building Resilient Supply Chains
- ISO 27001 as a Foundation for Supply Chain Resilience
- Vendor Risk Management: Suppliers Need to Be Managed, Not Just Procured
- Business Continuity Management: What Happens When a Critical Partner Fails?
- Incident Management: Fast Response Requires Clear Processes
- Regulatory Pressure Continues to Increase
- What Companies Should Do Now
- Why Excel and Email Are Not Enough
- Conclusion
- FAQ: Supply Chain Cyber Resilience and GRC
- What does cyber resilience in the supply chain mean?
- Why are industry and retail particularly vulnerable to supply chain cyber risks?
- What role does GRC play in cyber resilience?
- How does ISO 27001 help manage supply chain risks?
- What is the difference between Vendor Risk Management and traditional supplier management?
- Why is Business Continuity Management important for supply chains?
- Which companies should take action now?
- How can Zazoon support supply chain cyber resilience?