Skip to main content

ISACA report uncovers significant Supply Chain Security gaps in India and globally

 • Indian organizations seem to have a better clarity on various supply chain security gaps compared to other responding nations

55% expressed highest concern in ransomware threats among all potential supply chain risks

83% identified he need for better governance in the organization’s supply chain


ISACA® has just launched new global research results, Supply Chain Security Gaps: A 2022 Global Research Report that has divulged interesting threats and security gaps in the supply chain ecosystem globally. In India, just like many other developing economies, supply chain challenges have rocked both enterprises and consumers alike, making it harder to access certain goods and maintain business continuity. Increasing security threats have only heightened these concerns, and this ISACA survey report illuminates IT professionals’ key concerns around security challenges and how their organizations are responding to them.  It received responses from more than 1,300 IT professionals with pressing supply chain insights.  In the Indian market, the report findings cited the following supply chain risks as their key concerns:

Ransomware 55%

Hardware with embedded malware 44%

Third-party data storage 42%

Compromised software 42%

Software security vulnerabilities 40%

Poor information security practices by suppliers 32%

Third-party service providers or vendors with physical or virtual access to information systems, software code or IP 29%


“To advance digital trust, there needs to be a level of confidence in the security, integrity and availability of all systems and suppliers,” says David Samuelson, ISACA CEO. “As we have seen from previous incidents, customers do not differentiate between an attack on an element of your supply chain and an attack on your own systems. Now is the time to take swift and meaningful actions to improve supply chain security and governance.”

Additionally, the ISACA report demonstrates concrete data on overall supply chain security gaps and behavioural pattern within organisations. Some of the most striking results have been listed below –

 

87 Percent of the respondents in India feel their organization’s leaders have sufficient understanding of supply chain risks compared to 70 percent globally. 

About 56 percent indicate they have high confidence in the security of their organization’s supply chain

60 percent have high confidence in the access controls throughout their supply chain. 

Among all potential supply chain risks, 55 per cent of the respondents were concerned about ransomware threats

73 percent believe that organization’s supply chain issues will improve while 24 percent feel it will remain the same

More than 1 in 5 organisations (21 percent) experienced attacks on digital supply chain in the last 1 year

Almost 91 percent include cybersecurity and privacy assessments in their supplier assessment process

83 percent feel organization’s supply chain need better governance than what is currently in place

A much higher percentage of organizations in India say their risk assessments include supply chain assessments for IoT devices (83% in India compared to 51 percent globally) and AI (60 percent compared to 39 percent globally), compared to organizations in other countries.


"Key stakeholders – private enterprises, governments, supply chain institutions, and other associated third-party vendors will need to work closely to eradicate crucial supply chain security gaps,” says R V Raghu, Director at Versatilist Consulting India Pvt Ltd, and ISACA Ambassador. “It is imperative that there is a disclosure of open-source software components and threat and vulnerability analysis of key third parties involved and robust supply chain governance to ensure an effective IT supply chain security."

To read the full survey report and access additional resources on how organizations can enhance supply chain security and governance, visit www.isaca.org/supply-chain-security. ISACA also offers additional publications on the topic, including the How to Manage Supply Chain Risk ebook, as well as cybersecurity resources at www.isaca.org/resources/cybersecurity. 

 

About ISACA:  ISACA® (www.isaca.org) is a global community advancing individuals and organizations in their pursuit of digital trust. For more than 50 years, ISACA has equipped individuals and enterprises with the knowledge, credentials, education, training and community to progress their careers, transform their organizations, and build a more trusted and ethical digital world. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in digital trust fields such as information security, governance, assurance, risk, privacy and quality. It has a presence in 188 countries, including 225 chapters worldwide. Through its foundation One in Tech, ISACA supports IT education and career pathways for under resourced and underrepresented populations.


Comments

Popular posts from this blog

Convin launches AI-powered agent assist platform for banks & financial institutions

Bengaluru-based Convin.ai, a leading AI-driven platform that reimagines virtual assisted selling for businesses, today announced that it has launched an AI-powered agent assist platform that helps  them better prioritize their collection accounts resulting in a 25% increase in the closure rate.  The new platform also  has a proactive alert mechanism and sentiment analysis that triggers a red alert in case of any shouting or abuse during the call so that necessary steps can be taken to tackle such a situation.  The proactive alert mechanism has helped Convin’s BFSI customers improve their CSAT scores by 30%.  Three main pillars supporting the just launched platform are – 1. Automated quality management, which scores the call performance and identifies training opportunities for agents; 2. Call behaviour analysis which uncovers the behaviour outcome of calls (wins and losses) and 3. Automated quality coaching based on the above 2 that completely removes ...

Composecure’s global study shows India leading APAC in its preference for metal cards with Indian millennials seeing it as a lifestyle statement

A staggering nine of 10 consumers in India (91%) would select an offer that includes a metal payment card if all rewards and benefits were equal, which is up 6% from a prior Edgar, Dunn survey done for Composecure in 2019. This was the highest percentage of all regions surveyed and much higher than the global average of 70%. Other Asia Pacific regions also showed a strong preference for metal cards: 82% of Indonesia, 82% of China, 76% of Hong Kong and 71% of Singapore. The Asia Pacific region consistently ranked highest among the countries for awareness, interest and importance of metal cards. The survey identified India and Indonesia as two of the top nations with awareness and affinity toward metal payment cards. Both countries had the highest percentage of customers who would feel positive about their banks because they offered metal cards, significantly higher than the average survey respondent (89% vs. 58%). Metal payment cards offer financial institutions and other card issuers...

Vector Consulting Group expands its footprint and launches operations in Indonesia

Vector Consulting Group, India’s largest homegrown management consulting firm, announced its foray into the Indonesian market. The move will see Vector Consulting Group extend its India leadership into the international market with the launch of Indonesia operations as the homegrown consulting firm explores strategic growth opportunities in Southeast Asia. The consulting firm’s foray into Indonesia marks its first step toward growing its footprint and network outside India. As part of its expansion plan, the consulting firm has established its physical presence in Indonesia and will hire local talent to run its consulting practice in the country. Capitalising on its ‘implementation-first’ approach, Vector Consulting Group will offer its marquee consulting services to clients across sectors such as consumer goods, auto and auto components, textile and garments, equipment manufacturing, life sciences, and engineering and construction. For the consulting firm enabling organisational...