Case Study: Supply Chain and Third Party Strategy and Security Uplift
Client: An ASX top 20 company
Fortian developed a threat-informed, supply chain security strategy for an ASX top 20 company, assessing current state across policy, process, technology and supplier relationships, defining a clear target state, and delivering a prioritised three year roadmap to get there.
The Challenge
Supply chain compromise has become one of the most prominent attack vectors facing large organisations, and the client, with a substantial and diverse supplier base, recognised the need to take a strategic view:
- A large, complex supplier ecosystem, with security processes that had developed across different parts of the business over time
- Supplier security managed through established mechanisms, including questionnaires and contractual requirements, that warranted review against the evolving threat environment
- A need to understand how supply chain security effort should be weighted across a large supplier base, with the deepest assurance directed at the highest risk suppliers
- A desire to know where the client stood against industry peers and recognised frameworks, and what a mature target state should look like
Our Approach
Fortian brought the client's supply chain security practices together into a single strategy with a clear way forward. The engagement covered:
- Supply Chain Threat Model – Developed a threat model for the client's supply chain, so the target state and controls responded to the threats the client actually faces
- Current State Review – Reviewed the client's supply chain security posture across policies, standards, contractual documents, current processes, the supplier base, the existing supplier questionnaire, technology in use, and supplier relationships and situational awareness
- Process Mapping – Mapped existing supply chain security processes across the business, establishing a complete picture of how supplier security was managed in practice
- Maturity Assessment and Benchmarking – Assessed processes and maturity against NIST CSF and ISO 27001, and conducted industry benchmarking to position the client against its peers
- Target State Definition – Articulated a clear supply chain security target state, informed by the threat model, the maturity assessment and the benchmarking
- Gap Analysis – Analysed current state against target state, highlighting required updates to policy and standards, documentation, processes and supplier relationships, and identifying applicable technology requirements
- Risk-Tiered Control Mapping – Developed a mapping of controls to supplier risk tiers, so the depth of assurance applied to each supplier was proportionate to the risk it represented
- Three Year Roadmap – Developed a prioritised three-year roadmap to uplift the client's supply chain security from current state to target state
Delivery Approach
Fortian ran the engagement as a staged program:
- Developed the supply chain threat model first, so every subsequent judgement about target state and controls reflected the client's actual threat environment
- Reviewed current state across the full breadth of the supply chain security function: documents, processes, suppliers, technology and relationships
- Assessed maturity against NIST CSF and ISO 27001 and benchmarked the client against industry peers, establishing an objective baseline
- Defined the target state and ran the gap analysis against it, translating findings into specific required changes
- Delivered the risk-tiered control mapping and the prioritised three-year roadmap
The Outcome
The engagement gave the client a strategic foundation for its supply chain security uplift program:
- A supply chain threat model specific to the client's business and supplier ecosystem
- A complete view of current state across policy, process, supplier base, technology and relationships, mapped across the business
- An objective maturity baseline against NIST CSF and ISO 27001, with industry benchmarking showing where the client stood against peers
- A clearly articulated target state, and a gap analysis identifying the specific changes needed across policy, documentation, processes, relationships and technology
- A risk-tiered control model matching assurance effort to supplier risk
- A prioritised three year roadmap the client could execute against, sequenced to build capability progressively
Why Fortian
Fortian's depth across supply chain threat, security governance and industry benchmarking gave the client a coherent strategy and a three year path it could commit to.
Supply chain security cuts across contracts, procurement, technology and the everyday working relationships a business has with its suppliers. That breadth is what Fortian brought to the engagement. The review covered the entire supply chain security lifecycle with the target state built around threats the client faces.