Purpose The purpose of this paper is to explore how companies approach the management of cyber and information risks in their supply chain, what initiatives they adopt to this aim, and to what extent along the supply chain. In fact, the increasing level of connectivity is transforming supply chains, and it creates new opportunities but also new risks in the cyber space. Hence, cyber supply chain risk management (CSCRM) is emerging as a new management construct. The ultimate aim is to help organizations in understanding and improving the CSCRM process and cyber resilience in their supply chains. Design/methodology/approach This research relied on a qualitative approach based on a comparative case study analysis involving five large multinational companies with headquarters, or branches, in the UK. Findings Results highlight the importance for CSCRM to shift the viewpoint from the traditional focus on companies' internal information technology (IT) infrastructure, able to "firewall themselves" only, to the whole supply chain with a cross-functional approach; initiatives for CSCRM are mainly adopted to "respond" and "recover" without a well-rounded approach to supply chain resilience for a long-term capacity to adapt to changes according to an evolutionary approach. Initiatives are adopted at a firm/dyadic level, and a network perspective is missing.

Managing cyber and information risks in supply chains: insights from an exploratory analysis

Colicchia C.;
2019-01-01

Abstract

Purpose The purpose of this paper is to explore how companies approach the management of cyber and information risks in their supply chain, what initiatives they adopt to this aim, and to what extent along the supply chain. In fact, the increasing level of connectivity is transforming supply chains, and it creates new opportunities but also new risks in the cyber space. Hence, cyber supply chain risk management (CSCRM) is emerging as a new management construct. The ultimate aim is to help organizations in understanding and improving the CSCRM process and cyber resilience in their supply chains. Design/methodology/approach This research relied on a qualitative approach based on a comparative case study analysis involving five large multinational companies with headquarters, or branches, in the UK. Findings Results highlight the importance for CSCRM to shift the viewpoint from the traditional focus on companies' internal information technology (IT) infrastructure, able to "firewall themselves" only, to the whole supply chain with a cross-functional approach; initiatives for CSCRM are mainly adopted to "respond" and "recover" without a well-rounded approach to supply chain resilience for a long-term capacity to adapt to changes according to an evolutionary approach. Initiatives are adopted at a firm/dyadic level, and a network perspective is missing.
2019
Case studies; Information control; Resilience; Risk management; Supply-chain management
File in questo prodotto:
File Dimensione Formato  
colicchia et al 2018 cyber risk.pdf

accesso aperto

: Post-Print (DRAFT o Author’s Accepted Manuscript-AAM)
Dimensione 358.06 kB
Formato Adobe PDF
358.06 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11311/1119295
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 66
  • ???jsp.display-item.citation.isi??? 51
social impact