Background Image
 
Request a Demo
Claroty Toggle Search
Return to Blog

Strengthening Retail Resilience with Supply Chain Cybersecurity

/ / 6 min read
Featured image for our blog: Strengthening Retail Resilience with Supply Chain Cybersecurity

Digital transformation has upped the security stakes between retailers and third parties such as material suppliers, technology providers, maintenance contractors, logistics partners, and managed service providers. All of them play pivotal roles in the availability and resilience of the cold-storage systems, warehouse automation, building management systems (BMS), and other operational technology (OT) that fuels retail operations, keeps production alive, and the business healthy. 

Retail supply chain cybersecurity requires a deep understanding of these interconnected digital relationships and the third-party exposures and access control lapses that threat actors may leverage to target retailers via the supply chain. A successful compromise can cause cascading operational failures that can negatively impact shipping, inventory tracking, and supply availability.

This blog will explain retail third-party and supply chain cybersecurity environment that must be secured, and identify: 

  • Supply chain cybersecurity risks to address

  • How physical OT assets change risk calculations

  • Why asset visibility, exposure management, segmentation and zero trust are essential in retail

  • The path to operational resilience in retail

What Supply Chain Cybersecurity Means for Modern Retail

Third-party-written applications, integrations, and contractor relationships introduce new digital connections into retail environments. They also can introduce vulnerabilities and unmanaged privileged access that significantly expands a retailer’s attack surface. These are the biggest supply-chain cybersecurity exposures that retail security teams must consider.

Therefore, it’s essential for security teams, and compliance and business leaders, to have complete visibility into third-party relationships—both from a technology and contractual perspective—that informs the overall cybersecurity program. 

Asset management in retail must not only include an inventory of connected IT, OT, and internet-of-things (IoT) devices being introduced or managed by a third party into the retail environment; it also must correlate those assets with known and exploited vulnerabilities, provide insights into weak configurations, identify excessive third-party privileges, and map  attack pathways based on internal and external connections. 

Contractually, relationships with third parties should spell out in vendor risk management deals and service level agreements the protections retailers want in place. These must include multifactor authentication and least-privilege access for external access, data protection such as encryption, incident response plans, and timelines that spell out when suppliers should address known vulnerabilities. 

Any severe exposures are especially relevant for the OT that keeps the physical processes essential to the supply chain up and running. OT and IoT devices are heavily interconnected inside many retail organizations and cannot be taken offline for software and firmware updates without strong consideration for the uptime and availability of key systems. Often a disruption within OT has cascading effects downstream inside an enterprise. 

How Third-Party Connections Expand the Attack Surface

Third parties are essential to the availability and resilience of retail operating environments. 

Real-time analytics, inventory optimization, and remote monitoring demand the integrations contractors provide between IT networks, cloud management platforms, and physical OT assets. The data collected from processes that flow through these complex dependencies improves process efficiency and informs predictive maintenance. It can also expose new pathways that attackers could leverage to burrow deep into the process or enterprise network and disrupt or damage the flow of retail goods feeding the supply chain.

Consider a smart storefront where vendors may manage everything from access controls, to digital signs or energy management systems. Poorly guarded third-party credentials or weak configurations could expose these critical systems to attackers. 

In a retail cold chain, refrigeration systems maintain the viability of temperature-sensitive products in distribution centers or transportation locations. Any disruption from an insecure remote connection that leads to product loss or delivery delays is significant to the business, and could lead to regulatory disclosure mandates. 

External service providers and software integrators are also essential in warehousing and logistics. A compromise via vulnerable software or firmware at one of these suppliers could impact automation in storage facilities, cause fleet management disruptions, or damage from robotics gone awry. 

Moving Beyond Vendor Risk to Supply Chain Resilience

Protecting the physical assets that fuel the retail supply chain requires an operational security strategy built around asset visibility, risk prioritization, and strict access controls.

Asset Visibility Informs Compensating Controls

Continuous discovery of assets in retail OT includes an inventory of controllers, sensors, engineering, workstations, and BMS assets across warehouses and sites. A current asset inventory is critical to overall risk management and the deployment of controls, including compensating controls that are necessary for assets that cannot be taken offline for patching.

Virtual Network Segmentation Isolates Vulnerable Assets

Segmentation allows engineers and asset operators to isolate compromised assets in the event of a breach. It also enables security teams to prioritize which assets are walled off from making risky external connections to third parties or public internet. Organizations must be able to validate using real traffic whether assets such as historian databases and safety systems truly are not reachable when segmented. This is especially important in retail where so many third-party connections are required for the business to function. 

Zero-Trust Limits Blast Radius of Retail Compromises

A zero-trust architecture in retail is imperative to supply-chain security. Zero-trust’s never-trust, always-verified approach eliminates trust-by-default security models and demands instead continuous verification of machine-to-machine and user-to-machine access requests. Paired with segmentation, zero-trust is a critical strategy that narrows the blast radius of a successful compromise. Many OT environments, retail included, remain flat where assets are allowed to communicate unfettered. A zero-trust approach minimizes an attacker’s ability to leverage  these established pathways.

Resilience Relies Upon Rapid Recovery

Operational resilience in retail requires that OT environments be built to withstand and recover quickly from compromises. Best practices include: maintaining verified offline configurations, running operational and business continuity drills, and maintaining manual fail-safe procedures to keep goods moving.

Resilience planning should assume that a critical supplier could become unavailable or compromised. Retailers should identify alternative suppliers, manual operating procedures, backup communications, configuration backups and recovery processes for critical systems. Business continuity plans should explicitly address the failure of external technology and service providers.

Moving from Vendor Risk to Operational Resilience

Retailers now need a broader third-party risk model—one that recognizes that third parties can have direct influence over physical operations.

The question should no longer be simply: Can this vendor access our network?

It should be: What happens to our business if this vendor is compromised?

Answering that question requires retailers to understand their operational dependencies, identify the pathways through which third parties can affect physical systems, limit those pathways and prepare to operate when a trusted partner becomes an untrusted one.

For retailers, third-party cybersecurity is therefore inseparable from operational resilience. Protecting the supply chain means protecting not only data and systems, but also the refrigeration, automation, logistics, facilities and storefront operations that keep products moving and customers served.

Interested in learning about Claroty's Cybersecurity Solutions?

Background Image

Life, uninterrupted

We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.

Claroty
LinkedIn Twitter YouTube Facebook