Supply chain security involves analyzing every vendor and component in the chain of products and services that support an organization's operations. Understanding these dependencies helps identify risks ranging from component shortages to security vulnerabilities introduced by third-party suppliers.
Supply Chain Management
When I'm delivering services and products to my clients, I'm also looking at the vendors that supply products and services to me. This develops what's called the supply chain, and we need to manage the whole supply chain, and we need to look at the supply chain of our vendors.
Let's say I'm a company that creates a product and I'm selling that product to my clients. There's material that goes into creating that product, and I'm getting that from other vendors, and they're getting material from other vendors. So what happens is we create this chain of material that goes into creating the product that I'm going to sell to my clients. We call that the supply chain, and it's something that we have to analyze from a security perspective to make sure we're doing security correctly.
Let's take a look at a laptop supply chain just for some context, and let's look at a specific brand. Let's say this is a Dell computer. Dell purchases a lot of products from other different entities. For instance, they purchase their chips and their motherboards and all their processing power and their Wi-Fi from other companies. If you look at a Dell laptop you can see where it says Intel in there, or AMD, or wherever they're purchasing it from. You can see the different components from all of these other companies.
One of the things that they'll purchase from other companies is batteries. They'll purchase batteries from other companies to put in their laptops. I know this because at one point in time there was a bad batch of batteries that went out and it affected a lot of Dells and a lot of Macs and a lot of Asus, a lot of different brands it affected, because they were all buying from some of the same suppliers.
So we see a supplier of the battery. Well, they have purchased the products to make these batteries, they purchased from other people. There are chemicals that go into these batteries, and the company that makes the battery is not necessarily the company that goes and mines all of these chemicals that go into the batteries. So we see this whole supply chain form, and they can get very large.
There can be a lot of vulnerabilities to these supply chains. There could be shortages, there could be changes in products, there could be security issues with it. For instance, in this case right here, the battery, there could be chemical shortages, which creates a shortage in batteries, which creates a shortage in the amount of laptops. We saw this recently with chips: there was a shortage on chips, which caused all sorts of problems with how many laptops were on the market, and that drove up the price of these laptops.
So what we need to do is a supply chain analysis, and figure out what this supply chain is, so that we make sure we're buying the right products.
It's one of the reasons why there are really expensive laptops that are business-line laptops and really inexpensive lines of laptops that are more for the consumer. A consumer is usually buying one laptop, and it's not a big deal if the products and services that go into delivering that product vary a little bit, because they're just buying the one machine. But it becomes more critical when you are a business and you've got thousands of machines. If you have thousands of different machines, then that can be problematic.
So by buying the business level laptops, you're guaranteed a little more with what goes into that laptop, and making sure that there's an element of security involved, and that the product that's going into it remains relatively consistent. It's one of the reasons why some of these business-line products actually cost more than their consumer level counterpart.
One of the issues that creeps in with supply chain is the visibility. We don't always get a really good sense of what all goes into this laptop, nor do we have a limitless number of resources to research all of that. So what we're going to have to do is make a decision on: do we trust the company that's providing this laptop, and can we get some visibility into their supply chain to understand if they are providing a good product for us?
Some of the third party dependencies might be different hardware or software. Maybe it's different code libraries or different code that goes into it, different modules, different packages, maybe different container images. So there's a lot of things that will go into these products and services.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →