CYBER DEFENSE MODEL FOR THE SUPPLY CHAIN

Authors

  • Petya Petrova

Keywords:

cybersecurity, supply chain, cyber defense, information systems, software supply chain, SBOM, cyber risk, Defense in Depth

Abstract

The increasing dependence of modern information systems on external suppliers, cloud services, software libraries, updates and managed services makes the supply chain a critical component of cybersecurity. The compromise of a single supplier or software component may provide an entry point into multiple interconnected information systems and result in cascading cyber impacts.

This study proposes a multi-layer cyber defense model for supply chains consisting of seven interconnected protection layers: supplier verification, component integrity control, access protection, dependency monitoring, threat detection, propagation control, and incident response and recovery. A distinctive element of the proposed model is the propagation control mechanism, which aims to isolate a compromised external component before the compromise reaches critical information assets.

Downloads

Download data is not yet available.

References

[1] European Union Agency for Cybersecurity (ENISA). (2025). ENISA Threat Landscape 2025.

[2] Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2024). Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. NIST SP 800-161 Rev. 1, Update 1.

[3] European Parliament and Council. (2022). Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2).

[4] Reichert, B. M., & Obelheiro, R. R. (2024). Software supply chain security: a systematic literature review. International Journal of Computers and Applications, 46(10), 853–867.

[5] Cybersecurity and Infrastructure Security Agency (CISA). (2024). Securing the Software Supply Chain: Recommended Practices for Software Bill of Materials Consumption.

[6] Gokkaya, B., Aniello, L., & Halak, B. (2023). Software supply chain: review of attacks, risk assessment strategies and security controls.

[7] Ladisa, P., Ponta, S. E., Sabetta, A., Martinez, M., & Barais, O. (2023). Journey to the Center of Software Supply Chain Attacks.

[8] National Institute of Standards and Technology. (2026). Cybersecurity Supply Chain Management: Due Diligence Assessment Quick-Start Guide. NIST SP 1326.

[9] ENISA. (2023). Good Practices for Supply Chain Cybersecurity.

[10] Shourya, R., Kumagai, Y., Ashokkumar, C., Yamazaki, H., & Nakakoji, H. (2023). Proposal of Vulnerability Assessment Tool for Software Supply Chain Security. Journal of Information Processing, 31, 842–850.

Published

2026-08-24

Issue

Section

Computer Science and Communications - Reviewed Publications. ISSN: 1314-7846

How to Cite

CYBER DEFENSE MODEL FOR THE SUPPLY CHAIN. (2026). COMPUTER SCIENCES AND COMMUNICATIONS, 15(1), 40-54. https://csc.bfu.bg/index.php/CSC/article/view/301

Most read articles by the same author(s)