The Quarterly - Q3 FY26

Supply Chain Security in a Connected World

We don’t need to look far across the industry to observe the effects of cybersecurity issues and incidents stemming from essential partners. A significant influence on the technology ecosystem in which we operate over the past decade has been the adoption of a cloud-first strategy by many organisations. While this approach is well-founded, as it alleviates infrastructure overhead and somewhat simplifies the maintenance of a supportable IT environment, it has also centralised our reliance on the security of our supply chain and further shifted key control consideration towards identity management.

Identity Management: the new organisational perimeter

Identity management has become a foundational pillar of supply‑chain security as organisations shift from traditional on‑premises systems to cloud‑first operating models.

In the past, identity controls were largely perimeter‑based, relying on fixed networks and static access rules. But with the adoption of cloud services, distributed workforces, and interconnected third‑party ecosystems, identity has evolved into the new security boundary.

Modern identity management practices such as Zero Trust access models, continuous authentication, conditional access, privileged access management, and strong lifecycle governance are now essential to ensuring that every human and non‑human identity in the supply chain is verified, authorised, and monitored. This shift not only reduces the risk of compromised credentials being used as an attack vector but also provides the visibility and agility needed to secure complex, globally connected supply‑chain environments.

Cloud: know the region, the availability and how to recover operations

What has become apparent through the adoption of cloud is that as an organisation, risk is not transferable through contract to hyper-cloud providers. As such, entities must be aware of where data is hosted, that is, what region it is located in. Further considerations of the availability of these environments are paramount; is five nines (99.999%) enough? If you span two environments with five nines each, the resulting availability reduces to four nines, so duality is not always the answer.

Further considerations must focus on data replication within and across regions, and the implications of not taking this option: are you exposing the entity to availability risk? If you do take up this option, does the data sovereignty risk come to the fore? Finally, given the consideration of reputable backups, how do you protect them from system compromise and resulting file-level access, and does the data retention enable recovery within tolerable thresholds?

The sources of regulatory obligations

The supply chain is increasingly shaped by legal and regulatory expectations, particularly under Australia’s Corporations Act 2001 and APRA’s CPS 230 Operational Risk Management standard.

The Corporations Act 2001 establishes directors’ duties to act with due care and diligence, including an obligation to maintain adequate risk management systems. In practice, this is often interpreted as requiring systemic risk to be reduced as far as is reasonably practicable. In an interconnected world, that expectation is likely to extend to active oversight of material supply-chain risks such as cyber threats, technology dependencies, and third-party failures, as well as accurate market disclosure of significant operational risks.

CPS 230 reinforces this obligation for regulated entities by requiring a structured approach to identifying, managing, and monitoring operational risks across end-to-end supply chains, including critical service providers and fourth parties.

Together, these frameworks recognise that modern supply chains are deeply interconnected, often global, and digitally enabled, making resilience, visibility, and accountability for external dependencies essential components of effective risk management and organisational security.

Security of Contract, Condition or Warranty – where does cybersecurity sit?

In the context of supply chain security, cybersecurity obligations are increasingly treated as core contractual protections rather than peripheral technical matters, raising the question of whether they operate as contract conditions or warranties.

Traditionally, a condition goes to the root of the contract, and its breach entitles the injured party to termination, while a warranty is a lesser promise giving rise only to damages.

Because connected supply chains rely so heavily on digital systems, data integrity, and always-on operations, cybersecurity commitments (for example, maintaining specific controls, complying with recognised standards, and promptly notifying and remediating breaches) are increasingly being treated — and debated — as conditions of the contract, not merely warranties.

A material cyber incident can halt operations, expose confidential information, and cascade across interconnected suppliers, undermining the very purpose of the contractual relationship. As a result, parties may now elevate cybersecurity to an essential contractual term, supported by audit rights, step‑in provisions, and termination triggers, reflecting its role as a foundational element of security of supply rather than a secondary or technical warranty.

A joint response is the only response

Effective cyber response, incident, and crisis management is a critical pillar of supply chain security in a connected world, where speed and coordination often constrain the scale of harm.

Cyber incidents rarely occur in isolation; they can rapidly ripple across vendors, customers, and infrastructure partners, making timely engagement essential for containment and recovery.

Organisations must therefore be prepared not only with technical response plans, but with clear governance, decision-making authority, and communication pathways that enable swift action across legal, operational, and executive teams.

A willingness to engage early with affected partners, regulators, and customers demonstrates accountability and supports trust, while delays or opacity can amplify operational disruption, legal exposure, and reputational damage, potentially impacting the ongoing viability of executives. In modern supply chains, effective incident and crisis management is less about perfect prevention and more about resilience: the ability to detect, respond, collaborate, and adapt quickly when cyber risk materialises. Blame and root cause analysis do not belong in the incident room; the fear of accountability for decisions is something for the post-incident review with a sole focus on improving the response and, in turn, the ecosystem.

Regularly testing cyber response plans is essential to ensure they are practical, understood, and effective under real-world pressure. Scenario-based exercises, tabletop simulations, and supplier-inclusive drills help organisations identify gaps in decision-making, communication, and technical capability before an actual incident occurs, strengthening resilience and confidence across the entire supply chain.

Resilience is a shared responsibility

Security of supply in today’s connected world can no longer be anchored solely in physical controls or organisational boundaries.

Identity management has become the new perimeter, reflecting a reality in which access, trust, and authority flow across users, systems, and third parties — rather than being confined to a firewall.

At the same time, cloud adoption demands informed governance. This means understanding where data resides, how availability is assured, and whether replication and backups genuinely support resilience rather than simply create an illusion of safety. These technical realities are reinforced by the sources of our obligations, from statutory duties and prudential standards to contractual commitments, which increasingly frame cybersecurity as a condition central to the contract itself.

Ultimately, no single entity can secure a modern supply chain in isolation. Cyber risk is shared and not transferable, and so too must be the response: preparedness, clear contractual expectations, and the willingness to engage collaboratively and decisively during incidents. These are what transform connectivity from a source of fragility into a foundation for resilience.

Supply Chain Security in a Connected World is part of The Quarterly – Q3 FY26

Key Contributor:

Richard Atheron

General Manager, Technology Security

This article was also strengthened by a wider group of Novigi specialists, whose withering years of toil and rich experience added depth and clarity to the perspectives shared.

For more information about anything you’ve read here, or if you have a more general inquiry, please contact us.

 

Key Contributors

The people behind this edition

PRIVACY COLLECTION NOTICE

Pin It on Pinterest

Share This