Strengthening Supply Chain Risk: A Proactive Prioritization Model
摘要
Globalization has enabled interconnected networks of suppliers, manufacturers, and distributors to access international marketplaces, making supply chain attacks a prevalent corporate security concern. Conventional security methods, which emphasize perimeter defense and endpoint protection, often overlook the intricate dynamics of supply chains, and fail to appropriately prioritize risks. This paper presents a prioritization model developed by examining the attack habits and methodologies of attackers. The model enables organizations with large supply chain networks to monitor the current cyber risk of their suppliers, vendors, and affiliates more effectively. By providing an evidence-based comparison, the paper supports the concept of an alternative supply chain risk scoring approach that leverages target selection and evaluation behaviors of attackers. The findings underscore the inadequacies of existing methodologies and illustrate the viability of a proactive defense framework intended to mitigate emergent threats. The objective of this model is to safeguard organizations against supply chain attack risks through the evaluation of distinct patterns exhibited by internationally renowned cyber threat actors in ransomware and other prominent breaches.