[Paper Review] Assessing Supply Chain Cyber Risks
This paper proposes a structured framework for Supply Chain Cyber Risk Management (SCCRM) using expert judgment and forecasting models to assess attack probabilities and associated costs when suppliers are compromised. By integrating threat intelligence data with probabilistic modeling and dynamic linear models, the approach enables risk monitoring, supplier ranking, and proactive risk alarms, with a key result showing total expected losses of €737.27k from supplier-related cyber risks.
Risk assessment is a major challenge for supply chain managers, as it potentially affects business factors such as service costs, supplier competition and customer expectations. The increasing interconnectivity between organisations has put into focus methods for supply chain cyber risk management. We introduce a general approach to support such activity taking into account various techniques of attacking an organisation and its suppliers, as well as the impacts of such attacks. Since data is lacking in many respects, we use structured expert judgment methods to facilitate its implementation. We couple a family of forecasting models to enrich risk monitoring. The approach may be used to set up risk alarms, negotiate service level agreements, rank suppliers and identify insurance needs, among other management possibilities.
Motivation & Objective
- To address the growing challenge of cyber risks in interconnected supply chains, especially when direct data on attacks is scarce.
- To develop a practical, data-informed method for assessing cyber risk across suppliers and parent organizations using expert judgment.
- To enable predictive risk monitoring through time-series forecasting models that track evolving attack probabilities.
- To support managerial decisions such as supplier selection, SLA negotiation, and insurance needs through quantified risk indicators.
- To extend traditional risk assessment by incorporating indirect risks from suppliers and forecasting future attack likelihoods.
Proposed method
- The framework uses structured expert judgment to estimate attack probabilities and impact distributions when empirical data is unavailable.
- It models downtime durations using Gamma distributions based on expert-estimated quartiles (e.g., Gamma(1.79, 0.40) for the company).
- Customer loss proportions are modeled using Beta distributions (e.g., Beta(0.13, 1.74)) derived from expert assessments.
- Expected direct and indirect costs are calculated by aggregating downtime costs and customer loss impacts, yielding total expected cost of €737.27k.
- Dynamic Linear Models (DLMs) are fitted to forecast attack probabilities (AP, IAP, GAP) k-steps ahead with 95% predictive intervals.
- The system is implemented in Python and integrated with a Threat Intelligence System (TIS) to ingest real-time data on attack vectors and security posture.
Experimental results
Research questions
- RQ1How can cyber risk be assessed in supply chains when historical attack data is limited or unavailable?
- RQ2What role do suppliers play in indirectly increasing the cyber risk exposure of a parent organization?
- RQ3How can expert judgment be systematically combined with threat intelligence data to produce reliable risk indicators?
- RQ4Can predictive models forecast future attack probabilities to enable proactive risk management?
- RQ5How can risk scores be used to rank suppliers, negotiate SLAs, or inform insurance decisions?
Key findings
- The total expected cost of cyber risk from suppliers is estimated at €737.27k, with €517.16k from direct company downtime and €116.73k–103.38k from two suppliers.
- Supplier 1 induces higher expected losses (€116.73k) than Supplier 2 (€103.38k), indicating a higher risk profile.
- The model forecasts that the induced attack probability from Supplier 2 worsens over time, eventually reversing initial risk rankings.
- The DLMs successfully forecast future attack probabilities with 95% prediction intervals, enabling early warning systems.
- The framework supports dynamic risk monitoring, with visualized trends showing evolving attack probabilities over 100 time steps.
- The approach enables practical applications such as supplier ranking, SLA negotiation, and insurance needs assessment through quantified risk indicators.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.