<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Nicolas BLOCH, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/nicolas-bloch/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 15 Jan 2026 14:08:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Nicolas BLOCH, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>TPCRM for OT: managing cyber risks across the supply chain</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/01/tpcrm-for-ot-managing-cyber-risks-across-the-supply-chain/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/01/tpcrm-for-ot-managing-cyber-risks-across-the-supply-chain/#respond</comments>
		
		<dc:creator><![CDATA[Nicolas BLOCH]]></dc:creator>
		<pubDate>Thu, 15 Jan 2026 14:08:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=28832</guid>

					<description><![CDATA[<p>In a highly interconnected industrial environment, operational performance relies on an extended ecosystem of partners: critical suppliers, system integrators, maintenance providers, software vendors, IT and OT service providers, and others. While this ecosystem is essential to the company’s operations, it also represents one...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/01/tpcrm-for-ot-managing-cyber-risks-across-the-supply-chain/">TPCRM for OT: managing cyber risks across the supply chain</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-contrast="auto">In a highly interconnected industrial environment, operational performance relies on an </span><b><span data-contrast="auto">extended ecosystem of partners</span></b><span data-contrast="auto">: critical suppliers, system integrators, maintenance providers, software vendors, IT and OT service providers, and others. While this ecosystem is essential to the company’s operations, it also represents one of the </span><b><span data-contrast="auto">primary vectors of cyber risk</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Cyberattacks no longer target only internal information systems. They increasingly exploit external dependencies, where governance, visibility, and control are often weaker. A vulnerability affecting a third party can now lead to direct impacts on production, personnel safety, regulatory compliance, or the organization’s reputation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The attack suffered by Jaguar Land Rover in 2025 illustrates this reality: the shutdown of systems paralyzed the production chain and its partners, preventing the manufacture of more than 25,000 vehicles and resulting in estimated losses of nearly one billion pounds.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="auto">Managing third-party cyber risks</span></b><span data-contrast="auto"> is therefore no longer a peripheral issue. It is a central component of any industrial cybersecurity strategy, commonly referred to as </span><b><span data-contrast="auto">TPRM</span></b><span data-contrast="auto"> (Third-Party Risk Management) or </span><b><span data-contrast="auto">TPCRM</span></b><span data-contrast="auto"> (Third-party Cyber Risk Management). These concepts cover the overall management of third-party risks and its specific application to cyber risks.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1>Third parties driving the industrial value chain </h1>
<p><span data-contrast="auto">The concept of a “third-party” refers to any external entity or individual that collaborates with an organization and interacts with its systems, data, or processes. These actors contribute directly or indirectly to the company’s activities and collectively form what is known as the supply chain.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">In industrial environments, third parties can generally be grouped into five major categories, reflecting the diversity of roles they play in the operation and maintenance of industrial systems:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img fetchpriority="high" decoding="async" class=" wp-image-28833 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en1-1.png" alt="" width="806" height="563" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en1-1.png 1087w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en1-1-273x191.png 273w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en1-1-56x39.png 56w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en1-1-768x537.png 768w" sizes="(max-width: 806px) 100vw, 806px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Mapping third parties across the supply chain</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:200,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">To ensure seamless operational continuity, industrial organizations rely heavily on external service providers. This dependency, driven by the outsourcing of critical activities and regulatory requirements, </span><b><span data-contrast="auto">turns each supplier into an essential link</span></b><span data-contrast="auto"> in the chain. A single compromise affecting a third-party can be enough to halt production, disrupt operations, and expose the organization to major risks.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1>An extended supply chain: difficult to manage and vulnerable </h1>
<p><span data-contrast="auto">The diversity and number of third parties present several major challenges for organizations. First, the third-party ecosystem is often </span><b><span data-contrast="auto">extremely large</span></b><span data-contrast="auto">: a single organization may rely on hundreds or even thousands of partners.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This scale is compounded by </span><b><span data-contrast="auto">significant complexity</span></b><span data-contrast="auto">, as the supply chain does not stop with direct third parties, but also includes their own service providers, which are essential to their business continuity. As one moves down these successive levels (fourth parties, n-parties and beyond), the client organization’s visibility into its third parties decreases sharply:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img decoding="async" class=" wp-image-28818 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en2.png" alt="" width="773" height="527" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en2.png 1023w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en2-280x191.png 280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en2-57x39.png 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en2-768x523.png 768w" sizes="(max-width: 773px) 100vw, 773px" /></span><i><span data-contrast="none">An illustration of supply chain complexity </span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:200,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">This combination of breadth and depth makes it particularly difficult to maintain </span><b><span data-contrast="auto">overall control of the ecosystem</span></b><span data-contrast="auto">. For example, it is estimated that only 3% of organizations have full visibility across their entire supply chain (Panorays, 2025). This lack of visibility creates a </span><b><span data-contrast="auto">broad and difficult-to-manage risk surface</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1>Third party risks: a growing threat under regulatory pressure </h1>
<p><span data-contrast="auto">In recent years, there has been a significant increase in cyberattacks involving third parties. This trend is particularly pronounced in industrial environments, where </span><b><span data-contrast="auto">third parties are often involved in critical and vulnerable processes</span></b><span data-contrast="auto">: remote access to systems, physical access on site, identity and access management, and the integration of software or hardware components.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img decoding="async" class=" wp-image-28816 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en3.png" alt="" width="777" height="385" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en3.png 1386w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en3-385x191.png 385w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en3-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/01/tpcrm_en3-768x381.png 768w" sizes="(max-width: 777px) 100vw, 777px" /></span><span data-contrast="auto">These figures highlight two key observations. First, third-party risks are very real and represent a </span><b><span data-contrast="auto">growing threat</span></b><span data-contrast="auto"> to the cybersecurity ecosystem. Second, </span><b><span data-contrast="auto">the maturity level of organizations remains globally insufficient</span></b><span data-contrast="auto">, even as TPCRM emerges as a strategic lever for risk reduction.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">These findings are now reflected in regulatory frameworks. The European NIS 2 Directive, currently being transposed into national laws across EU Member States, requires affected organizations to manage risks related to their supply chains. Managing cyber risks linked to third parties is thus becoming a full-fledged regulatory requirement, with potential penalties of up to €10 million or 2% of global annual turnover in the event of non-compliance.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1>Adapting third party risk management to  industrial needs </h1>
<p><span data-contrast="auto">In light of these challenges, how can organizations structure effective third-party cyber risk management? While approaches vary, several key principles consistently emerge:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Cross-functional stakeholder involvement</span></b><span data-contrast="auto">: Third-party risk management cannot be the sole responsibility of IT or cybersecurity teams. Procurement, operational teams, and business units must be fully involved, as third parties operate across all levels of the organization.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Lifecycle-based approach</span></b><span data-contrast="auto">: Risk must be considered from supplier selection through to the end of the commercial relationship. Each phase (contracting, onboarding, operations, and offboarding) should be governed by appropriate security requirements.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Clear contractual requirements</span></b><span data-contrast="auto">: Contracts should formally define and include explicit cybersecurity obligations to ensure a consistent level of protection throughout the collaboration.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Third-party prioritization</span></b><span data-contrast="auto">: Security efforts must be proportional to the criticality of partners (e.g., level of system integration, operational dependency, sensitivity of exchanged data, relationship history). Assessing their operational role and cyber maturity helps focus resources on the most critical third parties.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Collaboration and information sharing</span></b><span data-contrast="auto">: Supply chain resilience depends on the ability of stakeholders to share information and coordinate responses in the event of an incident.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Tooling and automation</span></b><span data-contrast="auto">: Given the volume of third-parties, automation, continuous assessment, and the use of specialized tools are becoming essential enablers.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p><span data-contrast="auto">To support organizations in this approach, several authoritative references exist, including NIST SP 800-161 Rev. 1 </span><i><span data-contrast="auto">“Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations”</span></i><span data-contrast="auto"> (2022) and ENISA’s </span><i><span data-contrast="auto">“Good Practices for Supply Chain Cybersecurity”</span></i><span data-contrast="auto"> (2023).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1>TPCRM: strengthening industrial resilience </h1>
<p><span data-contrast="auto">In an industrial context where </span><b><span data-contrast="auto">cyber risks are becoming systemic</span></b><span data-contrast="auto">, supply chain security can no longer be addressed through a purely technical lens. It is now a </span><b><span data-contrast="auto">strategic issue of governance and resilience</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">A mature TPCRM approach not only supports </span><b><span data-contrast="auto">regulatory compliance</span></b><span data-contrast="auto"> but, more importantly, enables organizations to better </span><b><span data-contrast="auto">anticipate crisis scenarios</span></b><span data-contrast="auto">, limit operational impacts, and </span><b><span data-contrast="auto">strengthen trust across their partner ecosystem</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">By combining governance, processes, technologies, and collaboration with the wider ecosystem, TPCRM establishes itself as a key strategic lever for sustainably securing industrial environments</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/01/tpcrm-for-ot-managing-cyber-risks-across-the-supply-chain/">TPCRM for OT: managing cyber risks across the supply chain</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/01/tpcrm-for-ot-managing-cyber-risks-across-the-supply-chain/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
