Managing cyber risk in supply chains: a review and research agenda

dc.contributor.authorGhadge, Abhijeet
dc.contributor.authorWeiß, Maximillian
dc.contributor.authorCaldwell, Nigel D.
dc.contributor.authorWilding, Richard D.
dc.date.accessioned2019-12-16T15:11:29Z
dc.date.available2019-12-16T15:11:29Z
dc.date.issued2019-07-25
dc.description.abstractPurpose: Despite growing research interest in cyber security, inter-firm based cyber risk studies are rare. Therefore, this study investigates cyber risk management in supply chain contexts. Methodology: Adapting a systematic literature review process, papers from interdisciplinary areas published between 1990 and 2017 were selected. Different typologies, developed for conducting descriptive and thematic analysis were established using data mining techniques to conduct a comprehensive, replicable and transparent review. Findings: The review identifies multiple future research directions for cyber security/resilience in supply chains. A conceptual model is developed, which indicates a strong link between IT, organisational and supply chain security systems. The human/behavioural elements within cyber security risk are found to be critical; however, behavioural risks have attracted less attention due to a perceived bias towards technical (data, application and network) risks. There is a need for raising risk awareness, standardised policies, collaborative strategies and empirical models for creating supply chain cyber-resilience. Research implications: Different type of cyber risks and their points of penetration, propagation levels, consequences and mitigation measures are identified. The conceptual model developed in this study drives an agenda for future research on supply chain cyber security/resilience. Practical implications: A multi-perspective, systematic study provides a holistic guide for practitioners in understanding cyber-physical systems. The cyber risk challenges and the mitigation strategies identified support supply chain managers in making informed decisions. Originality: This is the first systematic literature review on managing cyber risks in supply chains. The review defines supply chain cyber risk and develops a conceptual model for supply chain cyber security systems and an agenda for future studies.en_UK
dc.identifier.citationGhadge A, Weiβ M, Caldwell ND, Wilding R. (2020) Managing cyber risk in supply chains: a review and research agenda. Supply Chain Management, Volume 25, Issue 2, February 2020, pp. 223-240.en_UK
dc.identifier.cris23891161
dc.identifier.issn1359-8546
dc.identifier.urihttps://doi.org/10.2139/ssrn.3426030
dc.identifier.urihttp://dspace.lib.cranfield.ac.uk/handle/1826/14843
dc.language.isoenen_UK
dc.publisherEmeralden_UK
dc.rightsAttribution-NonCommercial 4.0 International*
dc.rights.urihttp://creativecommons.org/licenses/by-nc/4.0/*
dc.subjectCyber risksen_UK
dc.subjectCybersecurityen_UK
dc.subjectCyber-attacksen_UK
dc.subjectCyber resilienceen_UK
dc.subjectSupply chain risk managementen_UK
dc.subjectSupply chain resilienceen_UK
dc.subjectSystematic literature reviewen_UK
dc.subjectText miningen_UK
dc.titleManaging cyber risk in supply chains: a review and research agendaen_UK
dc.typeArticleen_UK

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Managing_cyber_risk_in_supply_chains-2019.pdf
Size:
2.31 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.63 KB
Format:
Item-specific license agreed upon to submission
Description: