A Methodology for Cybersecurity Risk Assessment in Supply Chains

0Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Supply chain cyberattacks are on the rise as attackers are increasingly exploiting the intricate network of supplier connections between companies. Critical infrastructures too have been successfully targeted using this technique affecting their software and hardware estates, raising serious concerns due to the potential impact on public safety and the proper functioning of countries. This highlights the need to revise cybersecurity risk assessment strategies to stress the focus on threats originating from suppliers. This work proposes a novel supply chain cybersecurity risk assessment tailored for companies with limited cybersecurity expertise and constrained resources to execute risk assessment. Through a set of simple questions, this methodology first captures the perceived likelihood and impact of vulnerabilities and threats that derive from suppliers and target specific organisational assets and then generates cybersecurity risk scores for each relevant threat. A preliminary validation of the methodology is carried out, where generated risk scores are compared to evaluations provided by cybersecurity experts. The results show that the methodology produces risk scores that on average differ by 8% from those deriving from the experts’ assessment, which corroborates the hypothesis that the methodology is reliable even though it does not require detailed information about the suppliers’ cyber posture.

Cite

CITATION STYLE

APA

Gokkaya, B., Aniello, L., Karafili, E., & Halak, B. (2024). A Methodology for Cybersecurity Risk Assessment in Supply Chains. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 14399 LNCS, pp. 26–41). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-031-54129-2_2

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free