ANALYSIS OF CYBERSECURITY THREATS TO THE SUPPLY CHAIN AND POSSIBLE SECURITY CONTROLS: A BIBLIOMETRIC STUDY AND SYSTEMATIC LITERATURE REVIEW
DOI:
https://doi.org/10.24325/issn.2446-5763.v12i35p54-75Keywords:
Cibersegurança, Segurança da informação, Cadeia de suprimentos, Riscos cibernéticos, Ameaças cibernéticasAbstract
With the increasing complexity and interconnectivity of digital ecosystems, cyber risks have also expanded, particularly in the context of supply chains. In this scenario, vulnerabilities in any link of the chain can be exploited by malicious actors to compromise critical infrastructures, distribute malicious updates, and gain unauthorized access to confidential data. This study aims to analyze the cybersecurity threats affecting the supply chain, characterizing them based on the Supply Chain Threat Report proposed by the European Union Agency for Cybersecurity (ENISA) and identifying their purposes. Furthermore, the research also seeks to understand which technological and strategic solutions are effective in mitigating these risks, characterized based on the C-SCRM control families proposed by the National Institute of Standards and Technology (NIST). The methodology adopted is based on a qualitative literature review, analyzing academic articles and specialized publications, covering the period from 2020 to 2025. The results indicate a wide range of threats that compromise the cybersecurity of supply chains, highlighting deficiencies in practices and controls. This reinforces the need to adopt strategies such as Blockchain, Smart Contracts, cybersecurity frameworks, machine learning (ML), and antimalware solutions integrated with cyber risk management platforms. The study presents that the cyber resilience of the supply chain depends on the ability of organizations to identify, mitigate, and respond to threats present across all links of the chain.
Downloads
References
ADEWUSI, A.; CHIEKEZIE, C.; EYO-UDO, E. Cybersecurity threats in agriculture supply chains: A comprehensive review. World Journal of Advanced Research and Reviews, 2022. Disponível em: <https://www.researchgate.net/profile/Adebunmi-Adewusi/publication/384049365_Cybersecurity_threats_in_agriculture_supply_chains_A_comprehensive_review/links/67001a8df599e0392fb66b83/Cybersecurity-threats-in-agriculture-supply-chains-A-comprehensive-review.pdf> Acesso em 20 jun. 2025.
BAYRAMOVA, A.; EDWARDS, D.; ROBERTS, C. The role of blockchain technology in augmenting supply chain resilience to cybercrime. MDPI, v. 11, n. 7, 2021. DOI: 10.3390/buildings11070283. ISSN 2075-5309. Acesso em 19 jun. 2025.
BHAT, S.A. et al. Agriculture-Food Supply Chain Management Based on Blockchain and IoT: A Narrative on Enterprise Blockchain Interoperability. MDPI, v. 12, n. 1, p. 40, 2022. DOI: https://doi.org/10.3390/agriculture12010040. Acesso em 19 jun. 2025.
BOYENS, J. et al. Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. National Institute of Standards and Technology, 2022. Disponível em: https://doi.org/10.6028/NIST.SP.800-161r1-upd1. Acesso em 20 jun. 2025.
EGGERS, S. A novel approach for analyzing the nuclear supply chain cyber-attack surface. Nuclear Engineering and Technology, 2021. Elsevier. DOI: 10.1016/j.net.2020.08.021. Acesso em: 20 jun. 2025.
ENISA – European Union Agency for Cybersecurity. Threat Landscape for Supply Chain Attacks. ENISA, 2021. Disponível em: https://www.enisa.europa.eu/publications/threat-landscape-for-supply-chain-attacks. Acesso em: 26 jun. 2025.
ETEMADI, N.; GELDER, P.V.; STROZZI, F. An ISM Modeling of Barriers for Blockchain/Distributed Ledger Technology Adoption in Supply Chains towards Cybersecurity. Sustainability, v. 13, n. 9, p. 4672, 2021. DOI: 10.3390/su13094672. Acesso em: 20 jun. 2025.
GUPTA, N. et al. Additive Manufacturing Cyber-Physical System: Supply Chain Cybersecurity and Risks. IEEE Access, v. 8, p. 47322-47333, 6 mar. 2020. DOI: 10.1109/ACCESS.2020.2978815. Disponível em: https://doi.org/10.1109/ACCESS.2020.2978815. Acesso em: 19 jun. 2025.
HASSIJA, V. et al. A Survey on Supply Chain Security: Application Areas, Security Threats, and Solution Architectures. IEEE Internet of Things Journal, [S.l.], v. 8, n. 8, p. 6222-6246, 15 abr. 2021. DOI: 10.1109/JIOT.2020.3025775. Disponível em: https://doi.org/10.1109/JIOT.2020.3025775. Acesso em: 20 jun. 2025.
LADISA, P. et al. SoK: Taxonomy of Attacks on Open-Source Software Supply Chains. IEEE Symposium on Security and Privacy (SP), May 2023, San Francisco, CA, USA. DOI: 10.1109/SP46215.2023.10179304. Acesso em 20 jun. 2025.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Fernanda Lie Matsunaga, Carlos Hideo Arima, Nichols Aron Jasper

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.








