DReSC: Digital Resilience in Supply Chains
In a world where logistics and healthcare chains are increasingly digitally connected, vulnerability to cyber attacks is also increasing. Well-known incidents, such as the cyberattack on Maersk in 2017 and on the British National Health Service (NHS), showed how digital disruptions can result in global logistical chaos and millions of pounds in damage. Such attacks exploit known weaknesses – often not technical, but human. In many cases, there is a lack of awareness, digital resilience or cooperation between chain partners. Due to increasing dependence on real-time data sharing – for example, for inventory management or planning – the digital security of the entire chain is only as strong as its weakest link. Investing in your own security is therefore not enough: digital resilience must be tackled collectively.
The Digital Resilience in Supply Chains (DReSC) project investigates how supply chains can be better protected against cyber threats. It looks not only at technical solutions, but also at human and organisational factors. The central question is: where in the chain do measures have the greatest effect, which interventions work, and how can benefits and costs be distributed fairly?
Realistic situations are investigated in collaboration with partners from the logistics and healthcare sectors. Based on this, targeted security interventions are developed, such as awareness campaigns and training courses. Their effectiveness is measured by comparing the risk of cyber attacks before and after the interventions.
The project delivers three important results:
• Insight into weak spots within supply chains, through network analyses and simulations of cyber attacks;
• Effective interventions that strengthen employee behaviour and awareness and focus on vulnerable links in logistics and healthcare chains;
• New collaboration models, with incentives for chain partners to jointly invest in digital security – for example, through fair distribution of costs and revenues.
This approach promotes a security culture in which chain partners feel jointly responsible for digital resilience.