GAIA Society for Self-Sufficiency DE EN

Knowledge & Education

Supply chain security: security starts at the interfaces

Supply chain security: security starts at the interfaces
Herbert Saurugg, saurugg.net

The final episode of the podcast season “Supply Chain Security” (German) takes stock of four conversations about security, processes and digitalisation in companies. The central insight: these topics can no longer be considered separately. Risks arise above all where responsibilities, departments and systems meet – and nobody takes overall responsibility.

Unfortunately, the insights of this summary can also be transferred to many other areas. It surprises me again and again that we are not further along. At the same time, everything does somehow work. How much better could it be if networked thinking became more widely established?

Security is more than a fence and site security

At the outset, a widespread misunderstanding is addressed: a fence, cameras and site security do not yet make a comprehensive security concept. What really matters are questions such as:

  • Who was on site at a given time?
  • How do subcontractors or external service providers get onto the premises?
  • Who makes sure they leave the premises again?
  • What happens to critical knowledge when a shift supervisor or specialist leaves the company?
  • Is security-relevant information anchored in stable processes or merely in the heads of individuals?

Security therefore does not begin at the factory gate but where people, technology and processes interact. It is precisely at these transitions that unclear responsibilities and blind spots often arise.

Four episodes, one shared insight

The season approached the topic from four angles:

  1. From the boss’s business to everyone’s business: Supply chain security is not solely the task of top management or a single security department. It concerns the whole company and must be integrated into business processes.
  2. From silo to interplay: Individual departments are often well set up on their own. The problem lies in the transitions between them. IT, logistics, site security, production, purchasing and controlling each have their own knowledge but do not always work together sufficiently.
  3. From knowledge to implementation: Many companies know perfectly well where their weak points are. What is often missing, however, is a clear mandate: who may initiate a change, make decisions and implement measures bindingly?
  4. From sensors back into the process: Technical systems and sensors supply data. But their value only arises when it is clear which process needs this data, who interprets it and what action follows from it.

The four topics thus turn out not to be independent fields of work. Rather, they are different perspectives on the same challenge: how can security, processes, technology and responsibility be combined into an effective overall system?

The real risk lies between the silos

One of the most important statements of the episode is: security does not necessarily arise at the strongest point of a company, but where several responsibilities meet and nobody feels responsible.

IT knows its technical weak points. Process owners know where workflows stall. Management recognises the effects on costs and business results. But this knowledge often stays within the respective department. This leads to:

  • unclear handovers,
  • conflicting priorities,
  • unused data,
  • duplicated or missing responsibilities,
  • dependence on individual knowledge holders,
  • delayed decisions.

The participants therefore argue for an open review in which the relevant areas come together at one table. Weak points should not be passed back and forth but made visible and worked on together.

This, however, needs more than new organisation charts. A different attitude and a different corporate culture are also required: less departmental thinking, more dialogue, more willingness to experiment and a clear mandate for interdisciplinary cooperation.

Agile budgets instead of rigid large projects

Another focus of the final episode is how budgets are handled. Security and digitalisation projects are often planned as large, multi-year undertakings. This can lead companies to analyse for a long time, apply for extensive budgets and only start implementation late.

As an alternative, a step-by-step approach is proposed:

  • first carry out a review,
  • define concrete goals and a roadmap,
  • start with manageable sub-projects,
  • review results and key figures regularly,
  • continue or adjust investments depending on the actual benefit.

Instead of releasing a large overall budget immediately, companies could, for example, finance individual “sprints”. After each step, it is checked whether the expected benefit is materialising. The return on investment does not have to be measured solely in euros. Shorter lead times, fewer errors, better data quality or clearer responsibilities can also be important indicators of progress.

Ending a project early because the goal has already been achieved should not automatically be regarded as failure. If a process works stably earlier than expected, the company can reprioritise the next development step and deploy resources elsewhere.

Digitalisation and AI need clean foundations

The discussion about artificial intelligence makes it clear that new tools cannot repair bad processes. Anyone who digitalises a deficient process initially just gets a deficient digital process. If unreliable data is used as well, even an AI will not produce reliable results.

The necessary order is therefore:

  1. Capture existing processes.
  2. Clarify weak points and responsibilities.
  3. Improve data quality and data collection.
  4. Select suitable digital tools.
  5. Use AI specifically as support.
  6. Have people check and approve the results.

In the episode, AI is described as a tool and a kind of additional support – not as an autonomous replacement for responsibility. People remain responsible for classifying results, checking plausibility and making decisions. Especially in safety-critical applications, a “human in the loop” remains indispensable.

There is also a warning against uncritical AI euphoria. AI can hallucinate, misinterpret connections and deliver seemingly convincing but useless suggestions. Its performance therefore depends essentially on the underlying processes, data and control mechanisms.

Processes form the connecting level

In the course of the conversation it becomes clear that processes are the connecting level between security, technology and digitalisation. Security is therefore not an isolated discipline but a particular form of processes.

A sensor can, for example, detect whether a gate is open or closed. But this information only becomes really valuable when it is embedded in a higher-level workflow:

  • May a vehicle leave the premises?
  • Is the delivery fully documented?
  • Has a security-relevant approval been granted?
  • Must a particular person be informed automatically in the event of a deviation?

The decisive question is therefore not only “What does the sensor measure?” but “What does the measured state mean for the process, and what action follows from it?”

The first step mainly takes courage

As a practical conclusion, the participants recommend that companies do not wait for the perfect overall concept. The first step can be taken with limited resources:

  • bring the relevant people responsible to one table,
  • carry out a joint review,
  • identify handover points between departments,
  • clarify responsibilities and mandates,
  • check existing technology and data flows,
  • develop a realistic roadmap,
  • implement first measures with clear key figures.

Particularly important are the points where two responsibilities meet but nobody “wears the hat” for the cooperation. That is exactly where companies should start.

The season thus ends with an encouraging message: progress does not have to start with a huge budget. A joint analysis, an open dialogue and a clearly defined first implementation step can already significantly increase a company’s resilience. What matters is no longer treating security as an individual task but as a shared business topic along the entire supply chain.

Conclusion for practice

The season makes clear that supply chain security today is above all a question of attitude and cooperation. Anyone who continues to treat security, processes and digitalisation as separate topics risks new weak points arising precisely at the seams. Companies that are prepared to overcome departmental boundaries, mandate responsibility clearly and invest step by step and measurably can significantly increase their resilience with manageable effort. This brings us full circle to the thesis formulated at the beginning: supply chain security is no longer a one-off matter for the boss but an ongoing business task that must involve all levels and areas.

This article first appeared in German on saurugg.net – with kind permission of Herbert Saurugg. Licence: CC BY-NC-SA 4.0, Herbert Saurugg. Translated from German by GAIA.
Cover image: HunterProducciones / Pixabay

Notes on content provided by authors

Comments

Loading comments …

Become a member to comment publicly. GAIA members write comments in the members' portal — under their nickname, visible to everyone.

Become a member Already a member? Comment in the portal →

Translate

Machine translation by Google Translate. The page address is only sent to Google once you click — privacy.