Managing cyber risk in supply chains: a review and research agenda

被引:84
|
作者
Ghadge, Abhijeet [1 ]
Weiss, Maximilian [2 ]
Caldwell, Nigel D. [2 ]
Wilding, Richard [1 ]
机构
[1] Cranfield Univ, Cranfield Sch Management, Ctr Logist & Supply Chain Management, Cranfield, Beds, England
[2] Heriot Watt Univ, Dept Logist Res Ctr, Sch Social Sci, Edinburgh, Midlothian, Scotland
关键词
Risk management; Cybersecurity; Text mining; Systematic literature review; Supply chain disruptions; Supply chain risk management; Supply risk; Supply chain resilience; Cyber-attacks; Cyber risks; Cyber resilience; INFORMATION SECURITY; MANAGEMENT; MITIGATION; FUTURE; COLLABORATION; CYBERSECURITY; INTEGRATION; RESILIENCE; KNOWLEDGE; MODELS;
D O I
10.1108/SCM-10-2018-0357
中图分类号
F [经济];
学科分类号
02 ;
摘要
Purpose In spite of growing research interest in cyber security, inter-firm based cyber risk studies are rare. Therefore, this study aims to investigate cyber risk management in supply chain contexts. Design/methodology/approach Adapting a systematic literature review process, papers from interdisciplinary areas published between 1990 and 2017 were selected. Different typologies, developed for conducting descriptive and thematic analysis, were established using data mining techniques to conduct a comprehensive, replicable and transparent review. Findings The review identifies multiple future research directions for cyber security/resilience in supply chains. A conceptual model is developed, which indicates a strong link between information technology, organisational and supply chain security systems. The human/behavioural elements within cyber security risk are found to be critical; however, behavioural risks have attracted less attention because of a perceived bias towards technical (data, application and network) risks. There is a need for raising risk awareness, standardised policies, collaborative strategies and empirical models for creating supply chain cyber-resilience. Research limitations/implications - Different types of cyber risks and their points of penetration, propagation levels, consequences and mitigation measures are identified. The conceptual model developed in this study drives an agenda for future research on supply chain cyber security/resilience. Practical implications - A multi-perspective, systematic study provides a holistic guide for practitioners in understanding cyber-physical systems. The cyber risk challenges and the mitigation strategies identified support supply chain managers in making informed decisions. Originality/value To the best of the authors' knowledge, this is the first systematic literature review on managing cyber risks in supply chains. The review defines supply chain cyber risk and develops a conceptual model for supply chain cyber security systems and an agenda for future studies.
引用
收藏
页码:223 / 240
页数:18
相关论文
共 50 条
  • [1] Managing climate change risks in global supply chains: a review and research agenda
    Ghadge, Abhijeet
    Wurtmann, Hendrik
    Seuring, Stefan
    [J]. INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 2020, 58 (01) : 44 - 64
  • [2] Eleven years of cyberattacks on Chinese supply chains in an era of cyber warfare, a review and future research agenda
    Perez-Moron, James
    [J]. JOURNAL OF ASIA BUSINESS STUDIES, 2022, 16 (02) : 371 - 395
  • [3] Supply chains and ecosystems for servitization: a systematic review and future research agenda
    Davies, Philip
    Liu, Yipeng
    Cooper, Maggie
    Xing, Yijun
    [J]. INTERNATIONAL MARKETING REVIEW, 2023, 40 (04) : 667 - 692
  • [4] Performance measurement of sustainable supply chains A literature review and a research agenda
    Taticchi, Paolo
    Tonelli, Flavio
    Pasqualino, Roberto
    [J]. INTERNATIONAL JOURNAL OF PRODUCTIVITY AND PERFORMANCE MANAGEMENT, 2013, 62 (08) : 782 - 804
  • [5] Resource-efficient supply chains: a research framework, literature review and research agenda
    Matopoulos, Aristides
    Barros, Ana Cristina
    van der Vorst, J. G. A. J.
    [J]. SUPPLY CHAIN MANAGEMENT-AN INTERNATIONAL JOURNAL, 2015, 20 (02) : 218 - 236
  • [6] Objectives for managing cyber supply chain risk
    Windelberg, Marjorie
    [J]. INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2016, 12 : 4 - 11
  • [7] An Impact-wave Analogy for Managing Cyber Risks in Supply Chains
    Guerra, P. J. G.
    Estay, D. A. Sepulveda
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEE IEEM), 2018, : 61 - 65
  • [8] Unravelling and mapping the theoretical foundations of sustainable supply chains: A literature review and research agenda
    Govindan, Kannan
    Demartini, Melissa
    Formentini, Marco
    Taticchi, Paolo
    Tonelli, Flavio
    [J]. TRANSPORTATION RESEARCH PART E-LOGISTICS AND TRANSPORTATION REVIEW, 2024, 189
  • [9] What are the strategies to manage megaproject supply chains? A systematic literature review and research agenda
    Stefano, Gustavo
    Denicol, Juliano
    Broyd, Tim
    Davies, Andrew
    [J]. INTERNATIONAL JOURNAL OF PROJECT MANAGEMENT, 2023, 41 (03)
  • [10] Sustainable Food Supply Chains: Is Shortening the Answer? A Literature Review for a Research and Innovation Agenda
    Chiffoleau, Yuna
    Dourian, Tara
    [J]. SUSTAINABILITY, 2020, 12 (23) : 1 - 21