
We are seeing examples of Supply Chain disruptions all around us these days – wars that block shipping chokepoints and close off entire regions’ airspace, sanctions that cut off suppliers, pirates that hijack container ships, droughts that reduce the capacity of crucial waterways, pandemics that bring economies to a standstill. Such events are often labelled “Black Swans”, implying they were rare and thus surprising, but in fact many of these disruptions could have well been anticipated. For example, a global pandemic outbreak had been predicted with high confidence by experts, and even played out in two major Hollywood movies.
Many of these risks are driven by geopolitical events, by state and non-state actors, and by now we all should have recognized that our world has changed, increasing the risk levels for disruptions of all kinds. It seems wishful thinking that we are going back to quieter, more predictable times anytime soon.
As Supply Chain professionals, we must react to this increased risk level, by anticipating risks and making our Supply Chain more resilient. When a disruption happens, we should not be making excuses (“Nobody thought this would happen…”), but instead we must continue to deliver products to our customers, at sustainable costs, making sure our business survives, and maybe even thrives, if ability to supply becomes a competitive advantage.
In the past, we have focused our supplier risk assessments on financial stability, and on site specific risks such as fires, earthquakes etc. Now we need to look at geography and politics related risks and operational threats, too. The first step is to draw a Supply Chain Map – your facilities and your first- and lower tier suppliers facilities are the nodes, the shipping routes are the links between them. You need to ensure that any critical components that are not easily replaced, are mapped, no matter what tier they correspond to. Shortage of one component could even affect multiple supply chains at once. For example, during the COVID pandemic, one of the major issues I came across was the supply of specific filters used in the manufacturing process, that suddenly were in high demand for vaccine production, too. A relatively mundane (but, crucially, not totally mundane) consumable suddenly became critical, and multiple pharmaceutical companies found their production at risk of stoppage due to shortage of these same filters.
Out of a systematic risk analysis along your supply chain map, assessing every node and link with a suitable framework (eg, the PESTLE methodology for external risks), you can create a risk matrix that classifies all identified risks according to probability and impact. Then, you develop risk mitigation for those risks that have a too high probability or impact, or both.
One category of risk that deserves specific attention is Cyber Risk. A cyberattack can be just as devastating as a physical event, and arguably harder to anticipate. Just consider the impact when your ERP system goes down because of a ransomware attack: Suddenly, you cannot process purchase orders, you have no visibility on inventory, your warehouse management system is offline, and your planning team is effectively blind; you are forced to switch back to manual, Excel based processes, and later painfully update your ERP once it is operational again. This is not hypothetical; in 2017, the NotPetya attack hit Maersk and brought their entire operations to a standstill for weeks, at an estimated cost of $300 million.
Cyberattacks can also target the shared infrastructure that your supply chain depends on. Port operating systems, customs platforms, air cargo booking systems all are single points of failure, that affect hundreds of companies simultaneously. A cyberattack on a major port’s terminal operating system can shut down container handling, immediately creating a chokepoint. The attack on the Port of Nagoya in 2023 demonstrated exactly this, halting container operations at Japan’s largest port for several days.
Cyber risk therefore needs to be explicitly included in your supply chain risk map, both at the node level (your own and your key suppliers’ IT systems) and at the infrastructure level (shared platforms that multiple supply chain actors depend on). You need to understand the cyber resilience of the critical systems around you, as our digital assets become more and more interconnected.
In practice, many external risks are outside your control, so risk mitigation leads you logically towards a Resilience framework. Resilience means ensuring that your Supply Chain continues to function, after any disruption has eg disabled suppliers or blocked shipping lanes – regardless of whether that disruption had been anticipated or not. Setting up an alternate shipping lane is relatively easy and quick, working together with your forwarders, and ideally using this alternate lane regularly, to make sure the process, documents etc are functional and compliant. Dual Sourcing for products, intermediates and critical components is essential for mid to longer term resilience against disruptions that impact their supply, but this is more challenging to achieve than new shipping lanes.
Often, there is no Dual Sourcing in place; eg, in Pharmaceutical Supply Chains, there is often only one single site globally that makes a given product or intermediate. It is often a long and expensive undertaking to develop and qualify alternative suppliers, and it will typically also lead to higher operational expenses. Todays Supply Chains were built in an era that was relatively stable and orderly, and therefore cost reduction by economies of scale was a key objective, ie concentrating production in few, or even one, factory globally. However, as the world has become a more unstable and risky place, we need to revisit our Supply Chains, to increase resilience.
You should proactively, regularly assess your supply chain resilience, by conducting simulations, ideally by deploying digital tools. In addition, AI tools can even enable rapid changes to operations, if a disruption happens.
Scenario planning is one of the classical approaches, where you develop different scenarios such as the unavailability of a key supplier, and evaluate the supply situation short, mid and long term. If your Advanced Planning System is capable of scenario planning, you can project the inventory development and detect shortages, testing whether your Supply Chain would still be functional, or where it breaks down. And with a Digital Twin of your Supply Chain, you can go further, for example simulate a port closure or failure of a supplier, and explore the dynamics of inventory after that event, determining the recovery time and other key indicators. Such Digital Twins are more challenging to build (think Master Data quality, systems integration etc) and need to be kept up-to-date by feeding actual data into them, but they enable you to assess your resilience much better. Even more advanced, and more challenging to implement, are decision intelligence systems that could use AI agents to eg change purchase order and routings, if a disruption arises.
These are very promising digital and emerging AI enabled systems, but the basis must be in any case that you have done the structural homework and established alternatives throughout your supply chain, using a resilience framework, before a disruption happens. Otherwise, there’s nothing these systems could adjust and reschedule in the first place.
While resilience is business critical, the resources that a company can invest for this, are finite. You should therefore develop a prioritized proposal, giving the company leadership transparency on how much money will achieve what amount of resilience and for which products, so they can make a decision, and accept residual risks of disruption for what is not covered by the investment. Typically, a resilience program will stretch over multiple years, as resources are constrained, and individual steps take time.
Practically speaking, I would recommend to map your supply chain, immediately establish alternate shipping routes, and work on dual sourcing for your priority products with urgency. You should establish scenario planning capabilities, ideally with a planning system. If you also build a Digital Twin of your Supply Chain, then in my opinion you are “leading edge” and have achieved important proactive risk analysis and Supply Chain simulation capabilities. Going further, eg implementing AI driven decision engines, might be “bleeding edge” at this point, but if you are able to implement such systems, it would add important response capabilities. The foundation, in any case, is Dual Sourcing for those products your company wants to build resilience for.
Attend now 