Tuesday, 13 February 2018

SERM - The Domino Effect

Credit Stock Photo

I have two little monsters and like the little monsters they are, they love the whole Disney Pixar thing. One edition of Disney Pixar that we have watched maybe a little over what feels like one or two million times is Robots. For anyone who knows the story behind the film, they will be familiar with the dominoes scene which marks the triumphant return of Bigweld – the company’s missing boss and hero to the main character – Rodney Copperbottom. For those who are not familiar, Rodney causes the crash of hundreds of billions of dominoes by just toppling one. This domino effect, which starts innocently enough, can lead to disastrous effects.


Let’s exchange the Pixar setting for your organisation. Think of your organisation as the last domino, the biggest in the chain, centred in a large circle of a long list of “supplier” dominoes. Would a breach that affects, spreads and ultimatley topples a supplier have disastrous effects for you? The real impact of toppling a supplier is ultimately unknown, unless your organisation has taken steps to adequately asses the risks suppliers present. This process is known as Supplier Evaluation and Risk Management or SERM.


Let’s break SERM down;
  • Supplier Evaluation is;

    • Gathering information on the suppliers we have. First and foremost, we need to determine how many suppliers we have! Many organisations have only a rough head count of suppliers, Supplier Evaluation will give organisations a firm grip on the actual size of their supplier domino chain! From identifying the length of the domino chain, we will be able to accurately gauge the level of risk they present to the organisation.
    • Identifying what these suppliers do.  The risks a supplier presents to an organisation is largely dependent on what that supplier does for the organisation. A supplier that provides office furniture, can be viewed as much less risky than one that provides data analytic services. In the case of the office furniture supplier, an assessment can be considered complete once it’s determined that they pose little risk to the information security of the organisation. Whereas for the data analytics provider, it’s necessary to dig a little deeper and get to the crux of the risk they pose to the business.

    • Assessing how good a supplier is at Security is the deeper digging. This assessment can be conducted via a combination of the following activities,

      • Requesting that the supplier respond to a broad set of short yes or no questions about the security controls they have in place.
      • Requiring evidence (where necessary) that demonstrates that the controls they attest to; are indeed in place.
      • Benchmark the configuration of their estate, highlighting missing patches, outdated OS and Common Vulnerabilities and Exposures (CVE).
  • Risk Management
    After completing the evaluation, we have a clearer view of how dominoes in the chain may fall. Now, we need to weigh the impact of their fall. This helps an organisation determine the risk each vulnerable domino exposes them to. Would the risk be minor, maybe effecting a gentle shake upon our domino or will it be a major, earth shattering crash, that would tumble our organisation completely?
    We can determine the size of the supplier domino by;

    • The supplier’s risk score, based on the Supplier Evaluation.
    • Their impact on our organisation's short and long-term goals and objectives. Imagine we are an organisation that delivers Online Training. As an Online Trainer, we have an online meeting supplier - which we use daily to deliver webinars to our customers across the globe. Our online meeting supplier is hit by a cyber-attack and topples. Unless an alternative can be used, this will result in our inability to deliver Training.... Such an event would be disastrous to our customers and therefore our brand and our organisation, even though we have not been directly hit by the cyber-attack ourselves, our domino has fallen.

We must, at this point have the understanding that SERM is a multiphase process. To adequately measure the risk posed by our suppliers, we need to;
  1. Distribute surveys to all suppliers
  2. Gather those response
  3. Analyse and assess the responses
  4. Distribute follow up surveys if required
  5. Gather those responses
  6. Gauge the level of risk posed by those suppliers
  7. Implement safeguards or take necessary steps to remove or mitigate individual supplier risk.

Take a moment to consider how arduous this process could potentially be. The length of the supplier domino chain could be miles! This doesn’t just depend on the size of your organisation, even the smallest of organisations could have many suppliers. The length of the domino chain largely depends on the nature of the business.

If you apply the manual approach of SERM, which traditionally includes delivering excel based or telephone call questionnaires to all of your suppliers, will not only incur exponential costs in terms of man hours and material costs, but think about the level of expertise your team will need to have. What if you have a supplier that is not the most, let us say, “responsive”. Your SERM team will need to spend the extra time in chasing down supplier responses to capture an adequate Supplier Risk picture. Cast your eyes back to the sheer number of phases SERM has, the manual approach is usually a lengthy, laborious and error-prone process.

Yes, you will have a process in place, but is it effective? Can you adequately perform a comprehensive examination of your suppliers? To the point where you can identify the risks within your supplier domino chain and track remediation efforts? As the saying goes, do it nice or do it twice. For these reasons, among others - automation is a must.

The NotPetya outbreak which dominated the news last year is a case study that underpins the benefits of SERM. Perhaps..... If the clients of MeDoc had an automated SERM process in place, they would have been able to adequately weigh the risk MeDoc posed as their supplier. This could have resulted in the prevention or at least mitigation of the outbreak we saw spread throughout the Ukraine way back in June. Automated SERM would have highlighted the insecurities in the supply chain by automatically distributing surveys, allowing for real time status of surveys as well as providing automated reminders sent to those suppliers who have not completed the survey in a given timescale. Upon survey completion, automated SERM allows for immediate report provision which eliminates gap between time survey submissions and risk visibility.

Allowing the clients of MeDoc to weigh the risk to them would give them the choice of whether to keep trusting MeDoc as their supplier. For those conspiracy theorists out there, who will say to me “ah yes but the NotPetya attack was not about Cyber”. Firstly, I agree! There is indeed evidence that suggests NotPetya was more than just Cyber-Attack. Secondly and most importantly, what about Equifax? Or Uber? Or ? Almost all damages associated with breaches could have been severely mitigated or at least prevented if automated SERM were to be in place. By highlighting the risks to the business 3rd party suppliers pose and ascertaining exactly what those risks mean will ultimately allow the decisions to be made to prevent our domino from tumbling. 

Now, impressive as it may seem, we have come a long way without a mention of the feared EU GDPR, but... we would be neglectful to not discuss the requirements of SERM under EU GDPR. Article 4 defines the role of the data controller as “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data...” In the context of a SERM project, your organisation would be considered as the data controller. The suppliers you evaluate will fall under the role of data processor, who would be “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.” 


Between you and your supplier, right from the very beginning of your working relationship, there must be a clear understanding on what Personally Identifiable Information (PII) each party will be processing. This must include the metrics used to gauge how sensitive it is. Classification of sensitive data (e.g. gender and marital status etc.) should be clearly defined so when SERM is applied, we will have an accurate, clear picture of what risk they present to the business should a supplier be breached.
As we have alluded to, the primary purpose of SERM is to survey your suppliers and gauge the level of a risk (how big of a domino) they pose to your business. Automated SERM surveys will enable your organisation to ascertain the level of protection your suppliers currently have in place and provide you with a clear risk picture of your supplier chain. If the level of risk is not acceptable by your organisation, it may be that you may need to call a cease to your business relationship with that supplier, effectively removing them from the chain of dominoes to prevent yours from falling.
Without doubt, the absolute best way to acquire an accurate risk picture of your supplier chain is through using automated SERM. ZeroDayLab would be pleased to demo our automated SERM process, please contact us for more information.

What we know is a drop, what we don’t know is an ocean
Isaac Newton

95 comments:

  1. Very good info. Lucky me I discovered your blog by chance (stumbleupon). I have saved as a favorite for later!
    Techno

    ReplyDelete
  2. Best Corporate Video Production Company in Bangalore and top Explainer Video Company in Bangalore , 3d, 2d Animation Video Makers in Chennai.

    Thank you for your informative post!!!

    ReplyDelete
  3. Such a very useful article. Very interesting to read this article. I would like to thank you for the efforts you had made for writing this awesome article.
    Data Science Course in Pune
    Data Science Training in Pune

    ReplyDelete
  4. Nice blog. I finally found great post here Very interesting to read this article and very pleased to find this site. Great work!
    Data Science Training in Pune
    Data Science Course in Pune

    ReplyDelete
  5. I feel very grateful that I read this. It is very helpful and very informative and I really learned a lot from it.
    Data Analytics Course in Pune
    Data Analytics Training in Pune

    ReplyDelete
  6. Thumbs up guys your doing a really good job. It is the intent to provide valuable information and best practices, including an understanding of the regulatory process.
    Cyber Security Course in Bangalore

    ReplyDelete
  7. I am impressed by the information that you have on this blog. Thanks for Sharing
    Ethical Hacking in Bangalore

    ReplyDelete
  8. Wow! Such an amazing and helpful post this is. I really really love it. I hope that you continue to do your work like this in the future also.
    Ethical Hacking Training in Bangalore

    ReplyDelete
  9. Hi buddies, it is great written piece entirely defined, continue the good work constantly.

    Data Science Course

    ReplyDelete
  10. It is extremely nice to see the greatest details presented in an easy and understanding manner.

    Data Science Training

    ReplyDelete
  11. I like this post and there is obviously a lot to know about this. I think you made some good points in Features also i figure that they having a great time to peruse this post. They might take a decent site to make an information, thanks for sharing it to me Keep working, great job!
    Braces in Bangalore

    ReplyDelete
  12. wonderful article contains lot of valuable information. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article.
    This article resolved my all queries.good luck an best wishes to the team members.continue posting.learn digital marketing use these following link
    Digital Marketing Course in Chennai

    ReplyDelete
  13. Excellent blog with very impressive content found very unique and useful thanks for sharing,
    Invisalign in Bangalore

    ReplyDelete
  14. Wonderful blog found to be very impressive to come across such an awesome blog. I should really appreciate the blogger for the efforts they have put in to develop such an amazing content for all the curious readers who are very keen of being updated across every corner. Ultimately, this is an awesome experience for the readers. Anyways, thanks a lot and keep sharing the content in future too.

    Digital Marketing Course

    ReplyDelete
  15. Terrific post thoroughly enjoyed reading the blog and more over found to be the tremendous one. In fact, educating the participants with it's amazing content. Hope you share the similar content consecutively.

    Data Analytics training in bhilai

    ReplyDelete
  16. Thank you for sharing such nice content so keep posting.
    microsoft solitaire online

    ReplyDelete
  17. I want to leave a little comment to support and wish you the best of luck.we wish you the best of luck in all your blogging enedevors.
    data science course bangalore

    ReplyDelete
  18. i am glad to discover this page : i have to thank you for the time i spent on this especially great reading !! i really liked each part and also bookmarked you for new information on your site.
    best data science courses in bangalore

    ReplyDelete
  19. Excellent Blog! I would like to thank for the efforts you have made in writing this post. I am hoping the same best work from you in the future as well. I wanted to thank you for this websites! Thanks for sharing. Great websites!
    Data Science Training in Bangalore

    ReplyDelete
  20. i am glad to discover this page : i have to thank you for the time i spent on this especially great reading !! i really liked each part and also bookmarked you for new information on your site.
    data scientist course in bangalore

    ReplyDelete
  21. I am glad to discover this page. I have to thank you for the time I spent on this especially great reading !! I really liked each part and also bookmarked you for new information on your site.
    Data Science Training in Chennai

    ReplyDelete
  22. i am glad to discover this page : i have to thank you for the time i spent on this especially great reading !! i really liked each part and also bookmarked you for new information on your site.
    cyber security training in bangalore

    ReplyDelete
  23. Thanks for posting the best information and the blog is very helpful.data science institutes in hyderabad

    ReplyDelete
  24. i am glad to discover this page : i have to thank you for the time i spent on this especially great reading !! i really liked each part and also bookmarked you for new information on your site.
    artificial intelligence training in chennai

    ReplyDelete
  25. Terrific post thoroughly enjoyed reading the blog and more over found to be the tremendous one. In fact, educating the participants with it's amazing content. Hope you share the similar content consecutively.

    data science course in varanasi

    ReplyDelete
  26. I want to leave a little comment to support and wish you the best of luck.we wish you the best of luck in all your blogging enedevors.
    data science training in chennai

    ReplyDelete
  27. I am glad to discover this page. I have to thank you for the time I spent on this especially great reading !! I really liked each part and also bookmarked you for new information on your site.
    Data Science Course Syllabus

    ReplyDelete
  28. Impressive blog to be honest definitely this post will inspire many more upcoming aspirants. Eventually, this makes the participants to experience and innovate themselves through knowledge wise by visiting this kind of a blog. Once again excellent job keep inspiring with your cool stuff.

    Data Science Training in Bhilai

    ReplyDelete
  29. Wonderful blog found to be very impressive to come across such an awesome blog. I should really appreciate the blogger for the efforts they have put in to develop such an amazing content for all the curious readers who are very keen of being updated across every corner. Ultimately, this is an awesome experience for the readers. Anyways, thanks a lot and keep sharing the content in future too.

    Data Science Course in Bhilai

    ReplyDelete
  30. toptan iç giyim tercih etmenizin sebebi kaliteyi ucuza satın alabilmektir. Ürünler yine orjinaldir ve size sorun yaşatmaz. Yine de bilinen tekstil markalarını tercih etmelisiniz.

    Digitürk başvuru güncel adresine hoşgeldiniz. Hemen başvuru yaparsanız anında kurulum yapmaktayız.

    tutku iç giyim Türkiye'nin önde gelen iç giyim markalarından birisi olmasının yanı sıra en çok satan markalardan birisidir. Ürünleri hem çok kalitelidir hem de pamuk kullanımı daha fazladır.

    nbb sütyen hem kaliteli hem de uygun fiyatlı sütyenler üretmektedir. Sütyene ek olarak sütyen takımı ve jartiyer gibi ürünleri de mevcuttur. Özellikle Avrupa ve Orta Doğu'da çokça tercih edilmektedir.

    yeni inci sütyen kaliteyi ucuz olarak sizlere ulaştırmaktadır. Çok çeşitli sütyen varyantları mevcuttur. iç giyime damga vuran markalardan biridir ve genellikle Avrupa'da ismi sıklıkla duyulur.

    iç giyim ürünlerine her zaman dikkat etmemiz gerekmektedir. Üretimde kullanılan malzemelerin kullanım oranları, kumaşın esnekliği, çekmezlik testi gibi birçok unsuru aynı anda değerlendirerek seçim yapmalıyız.

    iç giyim bayanların erkeklere göre daha dikkatli oldukları bir alandır. Erkeklere göre daha özenli ve daha seçici davranırlar. Biliyorlar ki iç giyimde kullandıkları şeyler kafalarındaki ve ruhlarındaki özellikleri dışa vururlar.

    ReplyDelete
  31. Aha, it's a good discussion about this paragraph at this place on this website, I read all of that, so now I'm commenting here too...Eligible travelers can obtain a Tourist visa to Turkey and pay the e Visa Turkey cost online by filling an online form with their personal details and passport information.

    ReplyDelete
  32. This is very cool article about domino effect. I think your blog is very interesting. You can lead instagram blog too. You can buy instagram followers to promote your page

    ReplyDelete
  33. Since situations change, our bodyguards close protection in UK
    undergo refresher training regularly. They are evaluated after each training to assess whether they are fit for security assignments.

    ReplyDelete
  34. This is really very nice post you shared, i like the post, thanks for sharing..
    data scientist certification malaysia

    ReplyDelete
  35. Attractive component of the material. I just stumbled across your web site and accession capital to say that I really enjoyed your site. With just a few clicks, foreign nationals can apply for a
    Kenya visa on arrival from their home. Fill the form with accurate and complete information about the passenger's data.

    ReplyDelete
  36. I am a new user of this site, so here I saw several articles and posts published on this site, I am more interested in some of them, will provide more information on these topics in future articles.

    Data Analytics Course in Bangalore

    ReplyDelete
  37. Great post happy to see this. I thought this was a pretty interesting read when it comes to this topic Information. Thanks..
    Artificial Intelligence Course

    ReplyDelete
  38. Loved the way you have written the piece of content. Thanks for sharing. We are one of the best Dental Clinic in South Delhi.

    ReplyDelete
  39. Thanks for this incredible information. I think you could make a video about domino effect and post it on Youtube. By the way if you want to get more subscribers for your channel, you can repeatly use the help of https://viplikes.net/buy-youtube-subscribers to quickly boost their number.

    ReplyDelete
  40. Nice Post i have read this article and if I can I would like to suggest some cool tips or advice and perhaps you could write future articles that reference this article. I want to know more!
    Data Analytics Course in Gurgaon

    ReplyDelete
  41. I would like to say that this blog really convinced me to do it and thanks for informative post and bookmarked to check out new things of your post…
    Data Science Institute in Noida

    ReplyDelete
  42. I love to read this, thank you... Getting an Indian visa online is easy. You can apply via evisa India website online fully securely.





    ReplyDelete
  43. Venuepro is made up of 14 comprehensive modules that deliver all aspects of event and venue management. Venuepro is constantly under further development by consulting with industry experts and global venue and space owners. Venue Management Software

    ReplyDelete
  44. Diesel Brothers offer different types of services, Truck and Trailer , Reefer, Truck Alignment, Roadside Assistance, and APU.

    Tire repair near me
    Gas near me
    Truck repair shop near me

    ReplyDelete
  45. If you want to have a German quality dream kitchen space that enhances the value of your property, and contributes to improving your productivity and lifestyle, then get in touch with Goettling Interiors and speak to our expert designer today. modular kitchen dubai

    ReplyDelete
  46. You understand your business more than anybody else, keep the content but make it visually appealing and break down info to make it easy to digest. presentation design

    ReplyDelete
  47. Land sterling takes pride in offering best-in-class real estate valuation services in Dubai. Ever Since our inception in 2009, we have put in the best of our efforts to ascertain that our clients receive asset valuation services aimed at helping them make the best, most knowledgeable decisions. valuation companies in dubai

    ReplyDelete
  48. I am a 슬롯사이트 expert. I've read a lot of articles, but I'm the first person to understand as well as you. I leave a post for the first time. It's great!!

    ReplyDelete
  49. I love what you guys do too. Much clever work and reporting!Keep up the good work guys...Turkish visa for USA, You can apply online via Turkish visa website.

    ReplyDelete
  50. Very informative and interesting content. I have read many blog in days but your writing style is very unique and understanding. If you have read my articles then click below.

    salt supplier
    salt manufacturers

    ReplyDelete
  51. Microsoft Office 365 Product Key Activation Free incorporates Microsoft Office, SharePoint Online, Lync Online and Exchange Online combined in a very cloud service which is often as many as day. Office 365 will make it much easier for buyers to collaborate from just about anywhere and on any device https://freeprosoftz.com/microsoft-office-365-product-key/

    ReplyDelete
  52. Hii guys, Traveling to India interests you. For more information about e visa India, please visit our e visa to India page and read all visa requirements & guidelines.

    ReplyDelete
  53. Taking Window 7 item Key free is definitely not a straightforward work. On the off chance that you experience issues with your advanced windows seven establishment and have to improve or re-introduce Windows, you need the windows 7 item key or sequential key. However, immediately, you don't need to look through any extra since here we have recorded fundamental item keys for windows seven most recent 64 digit and 32 cycles. These are present day, working free keys. It positively will be appropriate for all extreme clients. windows 7 crack free product key

    ReplyDelete
  54. Are you perplexed about what design you should pick this time for your kitchen? If yes, then your search ends here as this article would be a great help for you undoubtedly. blog

    ReplyDelete
  55. This very informative and interesting blog. rent a car in lahore

    ReplyDelete



  56. We are also provide crack software. It has a wonderful feature. This is a good job. It is easy to use.
    https://azanpc.com/wondershare-filmora-11-crack-download-latest-version/

    ReplyDelete
  57. Grateful to have you in our lives. Hope you have a merry Christmas and a happy New Year. Hope your holiday season is filled with friendship and .
    Cute Christmas Wishes

    ReplyDelete
  58. This very informative and interesting blog.
    seo retainer

    ReplyDelete
  59. Thanks For Update :

    https://carzillauae.com/range-rover-repair-services/

    ReplyDelete
  60. Thanks for sharing beautiful content. I got information from your blog. keep sharing
    Abogado de accidentes de motocicleta en Virginia

    ReplyDelete
  61. Carzilla Auto is one of Dubai’s leading Porsche garage in Dubai. The company offers a wide range of automotive repair and modification services. Carzilla’s team is ready to change your vehicle, with free pick-up and delivery from your home. Porsche Repair Dubai

    ReplyDelete
  62. This comment has been removed by the author.

    ReplyDelete
  63. Microsoft Office 2010
    Microsoft Office 2010 is great software which is use to enhance the working in system.

    ReplyDelete
  64. I have read some of your blog’s content. I have saved your webpage in my favorites and will visit it again later.

    cockroach pest control dubai

    ReplyDelete
  65. Nice blog. I finally found great post here Very interesting to read this article and very pleased to find this site. Great work! Bmw repair dubai

    ReplyDelete
  66. I wholeheartedly congratulate the writer of this post for explaining the difficult concepts of data science in a simple and easy-to-understand manner. My only regret is that I didn’t read this post earlier. I have made many career decisions in my life after reading this, and have no regrets whatsoever to date.data science course in KL

    ReplyDelete
  67. I feel very grateful that I read this. It is very helpful and very informative and I really learned a lot from it.

    Porsce Repair dubai

    ReplyDelete

  68. Step into a world of luxury and indulge in unforgettable beauty experiences at our ladies salon near me . Our exclusive establishment is dedicated to enhancing your natural beauty and providing you with exceptional services that leave you feeling transformed. From expert hair styling and flawless makeup application to rejuvenating spa treatments and personalized skincare, we offer a comprehensive range of services tailored to meet your unique needs. Our team of talented professionals is committed to delivering the highest quality of service in an exquisite environment.

    ReplyDelete