RISKS WITHIN THE SUPPLY CHAIN

THE CAF’S SUPPLY CHAIN CHALLENGE: PT 3 – THOUGHT LEADERSHIP
This Op-Ed is the third in a four-part series examining how to address critical supply chain challenges that directly impact the Canadian Armed Forces’ operational effectiveness and national security interests.
BY ALLAN MCDOUGALL & DAN DORAN
Why attack a fortress when you can burn the fields that feed it or cut off the supply routes it needs to survive? As harsh as it may sound, this has been the guiding principle behind siege warfare for millennia. The modern theory of supply chain attack follows this same logic: why directly target a multinational business or institution, with all its defences, when you can infiltrate their supply chain—compromising components long before they reach production and use?
We are seeing this scenario play out with frightening regularity across government and industry. Attacks include the theft of proprietary information, the insertion of substandard or counterfeit parts, and the unauthorized inclusion of items that compromise the integrity of critical systems. This modern variation of siege warfare has had profound impacts, compromising ships, aircraft, networks, and communications infrastructure.
While it is true that ensuring every supplier meets a baseline for security and quality is important, it only represents the first step. In concert with this, both government and industry need to build a far deeper understanding of how risk flows within the supply chain—and what happens when something unauthorized, contaminated, or faulty enters the system.
UNDERSTANDING ‘CRITICALITY’
Following initial validation and detailed mapping, the second step is assessing criticality—how essential a component or service is to the mission. In other words, can the job still get done without it? One might be able to put a ship to sea without cutlery for everyone onboard, but that same ship is not going anywhere without fuel or a propellor. Understanding these distinctions means dissecting systems down into their individual parts and assessing each one on its own terms.
As these critical systems are decomposed, the same logic must be applied at every level. Specifically, isolating a single system, breaking it down into its composite sub-system, and then into each individual component. With each step, the user gains clarity on what matters most.
EXAMINATION OF THE PROCESSES
Next, is an examination of the processes that support these systems, sub-systems and components. These are not just technical steps—they involve people, facilities, information systems, and services working together to create something greater than the sum of its parts. These processes vary depending on proximity to the end product or service, but they all contribute to its function—and vulnerability.
In working through the above three step process, there are basic rules that can be used to map and model how risk moves within a supply chain. A non-exhaustive list of these rules include: • A secure activity cannot rely on an insecure one without risk of contamination. • A trustworthy system degrades if it is supported by untrustworthy equipment or services. • A high-reliability system loses assurance if it depends on lower-reliability components. • When different levels of assurance or trust must interact, something must be put in place to manage the gap.
These rules align with the standard industry attributes for supply chain risk, specifically, confidentiality, integrity, and availability. Notwithstanding, these rules should not be seen through a privacy-centric lens, which is to say through a lens of minimizing collection, using only what’s necessary, and enabling user control. Instead, they should be seen as vehicles to better understand how each component or service contributes to the successful delivery of the final product or capability.
Furthermore, this is not about blindly applying standards or ticking boxes. It is about understanding how seemingly minor risks at the component level can cascade—compounding into major vulnerabilities in the finished product. It is about recognizing how small, isolated acts or oversights can converge to undermine entire systems.
For corporations and governments alike, seeing supply chain risk through the above lens is vital to compliance and monitoring. But it also serves a larger purpose: building the case that products or services can be trusted to perform as promised.
Just as a fortress falls not from a breached wall but from severed supply lines, so too can the most advanced systems be undone by weak links in their chains. Guarding the fields and roads that sustain a company, or nation is the surest way to keep the walls standing.
Allan McDougall is Senior Program Manager at ADGA Group, and Dan Doran is Executive Director at KPMG Canada.

