CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 4

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 4

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 4 6912 3456 Centro de Ciberseguridad Industrial

Step 4. Your organization’s cybersecurity ends where that of your suppliers ends

In the previous three steps, we have built governance, understood industrial operations, and developed the necessary capabilities to protect, detect, and respond to a cyber incident. Now a reality appears that many organizations discover too late.

A large part of the risk no longer originates inside the plant, but enters every day through the supply chain. Equipment manufacturers, integrators, maintenance companies, engineering firms, cloud providers, remote access, technical support, software updates, managed services… all of them are part of the normal functioning of industrial operations and, therefore, are also part of its attack surface.

The question is no longer: Are our systems secure? It becomes a much more important one:

To what extent does our ability to resist a cyberattack depend on decisions made by other organizations?

The real risk is not the suppliers

A common mistake consists of evaluating only whether a supplier has certifications, policies, or certain security controls. All of that is important, but what matters is understanding what dependency we have created. Dependency is also a risk, and NIS2 forces us to govern it. Two suppliers with the exact same level of cybersecurity can represent completely different risks, and this does not depend solely on how they work; it depends on how much the organization needs to keep depending on them to maintain operations. The questions begin to change:

  • Which supplier could stop an essential process?

  • Who maintains the engineering stations?

  • Which integrators know the process logic?

  • Which manufacturers can modify the PLCs or the SCADA?

  • What would happen if one of them disappeared tomorrow?

  • What capacity do we have to replace them?

SG2CI incorporates the supply chain into the management system

SG2CI provides three closely related domains for this fourth step:

  • D8. Governance and trust in the supply chain, where criteria are established to select, classify, and supervise suppliers participating in industrial operations.

  • D9. Supplier capabilities and performance management, aiming to periodically evaluate the technical, organizational, and cybersecurity capabilities of third parties whose activities may affect essential processes.

  • D10. Collaboration with public and private bodies, because industrial resilience no longer depends solely on the organization itself, but also on the ability to share information, coordinate actions, and learn together with the rest of the industrial ecosystem.

In this way, the supply chain is no longer managed solely through contracts, but becomes a permanent risk management capability.

The CCI Catalog for evaluating industrial ecosystem capabilities

To facilitate this work, SG2CI incorporates the CCI Catalog. Its objective is not only to locate manufacturers, integrators, or industrial cybersecurity solutions, but it also provides a structured view of the cybersecurity capabilities of the technological ecosystem surrounding the organization.

Thanks to this, it is possible to identify specialized suppliers, understand their capabilities, compare alternatives, and have objective criteria to support decisions related to operational continuity and resilience. Because managing the supply chain is not just about buying better, but also about reducing critical dependencies before they become a problem.

How to know if this fourth step has been achieved?

At the end of this phase, the organization should clearly know which suppliers are critical for each essential process, what level of dependency exists regarding each of them, how their cybersecurity capabilities are evaluated, and what measures have been planned to reduce risk when that dependency becomes excessive.

It should also be able to demonstrate that supplier management is part of industrial cybersecurity governance and not just part of the procurement process. It is not about distrusting suppliers; it is about understanding that the organization’s resilience will largely depend on the resilience of the ecosystem it belongs to.

A final reflection

Years ago, organizations protected only what was inside their perimeter. Today, that perimeter has virtually disappeared.
Every remote access, every software update, every cloud service, every integrator, and every manufacturer expands the real scope of the organization.

Resilience is not built solely by strengthening the organization, but also by strengthening relationships of trust with the entire industrial ecosystem it depends on.

In the next post, we will address the fifth step of the itinerary, where we will analyze how to objectively measure the level of maturity achieved, prioritize investments, and build a roadmap for continuous improvement using MACIN.

José Valiente
 CCI Director