Abstract
This work is devoted to exploring information security management in supply chains. It focuses on assessing cyberthreat risks. Particular stress is given to cyber resilience strategies that enable organizations to enhance their ability to detect, contain, react to, and recover from cyber incidents involving external or internal actors. The study’s objective is to create suggestions for building secure and resilient digital supply chains, accounting for current technological advancements. The scientific investigation employed broad scientific methods of cognition, encompassing analysis and synthesis, induction and deduction, comparative approaches, a systems approach, and modeling methods. The findings of the study show that digital interdependence in supply chains substantially elevates cyber risks; thus, effective information security management demands the execution of dynamic trust models, consistent monitoring, and thorough cyber resilience strategies. The idea of supply chains within digital transformation is examined. The central perils to digital interdependence between supply chain entities are structured, considering the multilayered architecture of supply ecosystems. Trust models are examined as the basis for information interaction in digital chains. Vulnerable aspects in supply chains, which may function as cyberattack vectors, are pinpointed, analyzing the “critical areas” amongst service and software vendors. The notions of cyber resilience in supply chains are discussed for shared actions from all stakeholders. Cyber resilience tactics in supply chain management are identified, specifically the concepts and principles of cyber resilience in supply chains. Approaches for identifying, reacting to, and recovering from cyber incidents are explored. To structure managerial and technical responses to reduce cyber threats in complex digital supply chains, recommendations for enhancing cyber risk management in supply chains founded on adaptive security models and cyber resilience plans are proposed. The practical advantage of this research permits us to construct a comprehensive view of current cyber risks, devise effective protection strategies within digital interdependence, and strengthen the cyber resilience of supply ecosystems.
References
1. Kotliarov, V. (2024). Stratehichne upravlinnia informatsiinoiu bezpekoiu Ukrainy [Strategic management of information security of Ukraine]. Kyivskyi ekonomichnyi naukovyi zhurnal – Kyiv Economic Scientific Journal, (6), 66–69. https://doi.org/10.32782/2786-765X/2024-6-9 (in Ukrainian)
2. Bondar-Pidhurska, O. V., & Khomenko, I. I. (2022). Naukovo-metodychni zasady otsinky efektyvnosti protsesu upravlinnia informatsiinoiu bezpekoiu pidpryiemstv maloho ta serednoho biznesu: kiberbezpeka ta intelektualna vlasnist [Scientific and methodological principles for assessing the effectiveness of the information security management process of small and medium-sized businesses: cybersecurity and intellectual property]. Problemy ekonomiky – Problems of the Economy, 2(52), 108–116. https://doi.org/10.32983/2222-0712-2022-2-108-116 (in Ukrainian)
3. Mashchenko, M. A., & Ippolitov, Ye. M. (2024). Formuvannia stratehii posylennia informatsiinoi bezpeky pidpryiemstva [Formation of a strategy to strengthen the enterprise’s information security]. Ekonomika ta suspilstvo – Economy and society, (70). https://doi.org/10.32782/2524-0072/2024-70-147 (in Ukrainian)
4. Yasinska, A. (2023). Informatsiina bezpeka pidpryiemstva: kontseptualni zasady efektyvnoho zakhystu informatsii [Enterprise information security: conceptual principles of effective information protection]. Ekonomika ta suspilstvo – Economy and society, (56). https://doi.org/10.32782/2524-0072/2023-56-118 (in Ukrainian)
5. Osokin, H. V. (2024). Tsyfrovizatsiia lantsiuhiv postachannia yak faktor transformatsii biznes-modelei [Digitalization of supply chains as a factor in transforming business models]. Ekonomika ta suspilstvo – Economy and society, (64). https://doi.org/10.32782/2524-0072/2024-64-62 (in Ukrainian)
6. Lisitsa, V. V., Mykhailenko, O. M., & Rotenberh, O. V. (2023). Tsyfrovi lantsiuhy postavok: tekhnolohii, tendentsii ta napriamy rozvytku [Digital supply chains: technologies, trends and development directions]. Ekonomika ta upravlinnia pidpryiemstvamy – Economics and Business Management, (81), 99–106. https://doi.org/10.32782/bses.81-17 (in Ukrainian)
7. Prydybailo, O. B., Prydybailo, R. V., Yaskevych, V. O., & Yaskevych, Yu. V. (2024). Arkhitektura nulovoi doviry: lohichni komponenty ta pidkhody zaprovadzhennia [Zero Trust Architecture: Logical Components and Implementation Approaches]. Zviazok – Communication, (3), 7–11. https://doi.org/10.31673/2412-9070.2024.030711 (in Ukrainian)
8. Kulikovskyi, A. V. (2019). Tekhnolohiia blockchain yak skladova informatsiinoi bezpeky [Blockchain technology as a component of information security]. Kiberbezpeka: osvita, nauka, tekhnika – Cybersecurity: education, science, technology, 4(4), 85–89. https://doi.org/10.28925/2663-4023.2019.4.8589 (in Ukrainian)
9. Halushko, O., & Selivorstova, T. (2022). Kiberbezpeka v upravlinni lantsiuhamy postachan (SCM) [Cybersecurity in Supply Chain Management (SCM)]. Naukovyi visnyk Dnipropetrovskoho derzhavnoho universytetu vnutrishnikh sprav – Scientific Bulletin of the Dnipropetrovsk State University of Internal Affairs, 2(121), 537–542. https://doi.org/10.31733/2078-3566-2022-6-537-542 (in Ukrainian)
10. Pohrebniak, A. T., Nemish, Yu. V., Pavlovski, H., Shevchenko, S. H., & Tyrkalo, Yu. Ye. (2022). Bezpeka ta osoblyvosti funktsionuvannia lantsiuhiv postavok v umovakh ryzyku [Security and features of supply chains functioning under risk conditions]. Naukovi zapysky Lvivskoho universytetu biznesu ta prava – Scientific Notes of Lviv University of Business and Law. Seriia Ekonomichna. Seriia Yurydychna, (35), 10–18. https://nzlubp.org.ua/index.php/journal/article/download/641/588 (in Ukrainian)
11. Reznikova, N. V., Vovk, V. A., & Ptashchenko, L. V. (2025). Formuvannia mizhnarodnoi konkurentospromozhnosti IT-sektoru: stratehichni chynnyky ta kiberryzyky [Shaping the international competitiveness of the IT sector: Strategic factors and cyber risks]. European Scientific Journal of Economic and Financial innovation, 1(15), 439–449. https://journal.eae.com.ua/index.php/journal/article/view/494 (in Ukrainian)
12. Smerichevska, S. V. (2021). Stratehichni trendy rozvytku lantsiuhiv postavok novoho pokolinnia v epokhu tsyfrovizatsii ekonomiky [Strategic trends in the development of new generation supply chains in the era of digitalization of the economy]. In Proceedings of the II International Scientific and Practical Conference Business, Innovation, Management: Problems and Prospects (pp. 282–283). Kyiv: Vydavnytstvo “Politekhnika”. https://confmanagement-proc.kpi.ua/article/view/230866 (in Ukrainian)
13. Hirna, O. B. (2025). Tsyfrovi tekhnolohii v upravlinni lantsiuhamy postachannia [Digital technologies in supply chain management]. Ekonomichnyi prostir – Economic space, (199), 20–25. https://doi.org/10.30838/EP.199.20-25 (in Ukrainian)
14. Matsyshyna, O. V., & Smerichevska, S. V. (2022). Intehrovanyi pidkhid do stratehichnoho upravlinnia lantsiuhamy postachannia v umovakh tsyfrovoi ekonomiky [An integrated approach to strategic supply chain management in the digital economy]. In Proceedings of the III International Scientific and Practical Conference Business, Innovation, Management: Problems and Prospects (pp. 78–79). https://confmanagement-proc.kpi.ua/article/view/271608 (in Ukrainian)
15. Kupershtein, L., & Krentsin, M. (2024). Model nulovoi doviry dlia hibrydnoi pirynhovoi merezhi [Zero Trust Model for Hybrid Peer-to-Peer Network]. Vymiriuvalna ta obchysliuvalna tekhnika v tekhnolohichnykh protsesakh – Measuring and computing equipment in technological processes, (3), 236–242. https://doi.org/10.31891/2219-9365-2024-79-31 (in Ukrainian)
16. Werbach, K. (2018). Trust, but Verify: Why the Blockchain Needs the Law. Berkeley Technology Law Journal, 33(2), 487–550. https://www.jstor.org/stable/26533144
17. Babenko, K. Ye. (2018). Blokchein v ekonomitsi ta biznesi [Blockchain in the economy and business]. Ekonomika i suspilstvo – Economy and society, (15), 924–932. https://economyandsociety.in.ua/journals/15_ukr/142.pdf (in Ukrainian)
18. Panchenko, V., & Reznikova, N. (2022). Vid vrazlyvosti lantsiuhiv postavok do yikh hnuchkosti ta stiikosti dlia MSP [From supply chain vulnerability to flexibility and resilience for SMEs]. INDUSTRY4UKRAINE. https://www.industry4ukraine.net/publications/vid-vrazlyvosti-lanczyugiv-postavok-do-yih-gnuchkosti-ta-stijkosti-dlya-msp (in Ukrainian)
19. ESET. (2021). Kilkist atak na lantsiuh postachannia zrostaie: khto pid prytsilom ta yak protystoiaty [Supply chain attacks are on the rise: Who is being targeted and how to counter them]. https://surl.li/dvzpuy (in Ukrainian)
20. Havrysh, B. M., Tymchenko, O. V., Borzov, Yu. O., & Kobevko, A. T. (2022). Klasyfikatsiia shkidlyvoho prohramnoho zabezpechennia ta osnovni metody zakhystu [Malware classification and basic protection methods]. Kompiuterni tekhnolohii drukarstva – Computer Printing Technologies, 2(48), 142–154. http://doi.org/10.32403/2411-9210-2022-2-48-142-154 (in Ukrainian)
21. ISSP Training Center. (2021). Shcho potribno znaty pro audyt kiberbezpeky [What you need to know about cybersecurity auditing]. https://www.issp.training/post/scho-potribno-znaty-pro-audyt-kyberbezpeky (in Ukrainian)
22. Kovalenko, S. V., Smoliev, Ye. S., & Barhylevych, O. A. (2021). Tekhnolohiia audytu kiberbezpeky korporatyvnoi informatsiinoi systemy za metodykoiu ISO/IES: 27001 [Corporate information system cybersecurity audit technology according to ISO/IES: 27001 methodology]. Suchasnyi zakhyst informatsii – Modern Information Protection, 3(47), 29–35. http://doi.org/10.31673/2409-7292.2021.032935 (in Ukrainian)
23. B2B Cyber Security. (2025). Zakhyst lantsiuzhka postachannia prohramnoho zabezpechennia vidpovidno do zakonu pro kiber-stiikist [Protecting the Software Supply Chain Under Cyber Resilience Act]. https://b2b-cyber-security.de/uk/software-lieferkette-fuer-den-cyber-resilience-act-absichern (in Ukrainian)
24. Yashchuk, V. I. (2024). Rol ta mistse stratehii kiberbezpeky Ukrainy u zabezpechenni informatsiinoi bezpeky derzhavy [The role and place of Ukraine’s cybersecurity strategy in ensuring the state’s information security]. In Moderní aspekty vědy: XLII. Díl mezinárodní kolektivní monografie (pp. 259–286). Mezinárodní Ekonomický Institut s.r.o. https://sci.ldubgd.edu.ua/jspui/handle/123456789/13824 (in Ukrainian)
25. Tsekhmeister, R. D., Platonenko, A. V., Vorokhob, M. V., & Cherevyk, V. M. (2025). Doslidzhennia metodiv zabezpechennia informatsiinoi bezpeky u virtualnomu seredovyshchi [Research on methods for ensuring information security in a virtual environment]. Kiberbezpeka: osvita, nauka, tekhnika – Cybersecurity: Education, Science, Technology, 3(27), 63–71. http://doi.org/10.28925/2663-4023.2025.27.703 (in Ukrainian)
26. Progress Community. (2022). Is MOVEit vulnerable to CVE-2021-44228 (Log4j)? https://community.progress.com/s/article/Is-MOVEit-vulnerable-to-CVE-2021-44228-Log4j
27. Koval, M. A., Bobrovskyi, O. V., Herashchenko, I. O., & Nykytiuk, A. P. (2025). Stratehii kiberstiikosti: upravlinnia ryzykamy ta bezperervnist biznesu [Cyber Resilience Strategies: Risk Management and Business Continuity]. In Materials of the All-Ukrainian Scientific and Practical Internet Conference Cyber Resilience Strategies: Risk Management and Business Continuity (pp. 19–25). Educational and Scientific Institute of Cybersecurity and Information Protection, State University of Information and Communication Technologies. https://duikt.edu.ua/uploads/p_2779_46212583.pdf (in Ukrainian)
28. ESKA. (2024). BCP (Business Continuity Plan) ta DRP (Disaster Recovery Plan) – Suchasni pidkhody do Kiberbezpeky ta Biznes-Zakhystu [BCP (Business Continuity Plan) and DRP (Disaster Recovery Plan) – Modern Approaches to Cybersecurity and Business Protection]. https://eska.global/blog/bcp-business-continuity-plan-ta-drp-disaster-recovery-plan-suchasni-pidhodi-do-kiberbezpeki-ta-biznes-zahistu_1 (in Ukrainian)
29. Vamark. (2025). Zero Trust Architecture: novyi standart u kiberbezpetsi [Zero Trust Architecture: a new standard in cybersecurity]. https://vamark.ua/blog/zero-trust-architecture-novyj-standart-u-kiberbezpeczi (in Ukrainian)
30. Upravlinnia kyberintsydentamy. Versiia 1.1. Posibnyk z dodatkhovykh resursiv CRR [Cyber Incident Management. Version 1.1. CRR Supplemental Resource Guide]. (2016). Carnegie Mellon University. https://cip.gov.ua/services/cm/api/attachment/download?id=62036 (in Ukrainian)
31. Shulha, V. P., Ivanchenko, Ye. V., Vyshnevska, N. S., & Berber, A. S. (2024). Doslidzhennia metodiv ta modelei otsiniuvannia kiberzakhystu krytychnoi infrastruktury derzhavy [Research into methods and models for assessing cyber defense of critical state infrastructure]. Suchasnyi zakhyst informatsii – Modern Information Protection, 3(59), 6–19. http://doi.org/10.31673/2409-7292.2024.030001 (in Ukrainian)
32. Stratehiia informatsiinoi bezpeky [Information Security Strategy]. Decree of the President of Ukraine dated December 28, 2021 No. 685/2021. https://zakon.rada.gov.ua/laws/show/685/2021#Text (in Ukrainian)
33. Prokopenko, O., Bezliudnyi, O., Omelyanenko, V., Slatvinskyi, M., Biloshkurska, N., & Biloshkurskyi, M. (2021). Patterns identification in the dynamics of countries’ technological development in the context of military conflict. Eastern-European Journal of Enterprise Technologies, 2(13(110), 6–15. https://doi.org/10.15587/1729-4061.2021.230236
34. Dovhun, O. S., & Stasiuk, K. Z. (2017). Avtomatyzatsiia lohistyky: suchasni rishennia ta perspektyvy [Logistics automation: modern solutions and prospects]. Naukovyi visnyk Uzhhorodskoho universytetu. Seriia “Ekonomika”, 2(50), 187–191. http://nbuv.gov.ua/UJRN/Nvuuec_2017_2_28 (in Ukrainian)
35. Kudyrko, O. (2022). Avtomatyzatsiia lohistychnykh protsesiv yak suchasnyi trend [Automation of logistics processes as a modern trend]. In Proceedings of the II International Scientific and Practical Internet Conference on Modern Technologies in Commercial Activities and Logistics, November 3, 2022, Kyiv (pp. 56–59). Kyiv National Economic University named after V. Hetman. https://ir.kneu.edu.ua:443/handle/2010/39284 (in Ukrainian)
36. Lomovatskyi, O. V. (2024). Rol audytu informatsiinoi bezpeky v zabezpechenni stiikosti ta nadiinosti informatsiinykh system [The role of information security auditing in ensuring the stability and reliability of information systems]. In Proceedings of the All-Ukrainian Scientific and Practical Conference “Digital Transformation of Cybersecurity” (pp. 75–77). https://duikt.edu.ua/uploads/n_12581_11703414.pdf (in Ukrainian)
37. Zaverbnyi, A. S. (2024). Osoblyvosti formuvannia systemy upravlinnia kiberbezpekoiu pidpryiemstv u voiennyi period: teoretykoprykladnyi aspect [Peculiarities of forming a cybersecurity management system for enterprises during wartime: theoretical and applied aspects]. Innovation and Sustainability, (1), 13–22. https://doi.org/10.31649/ins.2024.1.13.21 (in Ukrainian)
38. National Institute for Strategic Studies. (2022). Ataky cherez lantsiuzhky postachan: formuiuchy stratehichnu vidpovid [Supply Chain Attacks: Shaping a Strategic Response]. https://niss.gov.ua/sites/default/files/2022-06/ad_cyberresill_structure_var8_new_ed_01_gotove_0.pdf (in Ukrainian)
39. Shtelmashuk, M. S. (2024). Tsyfrovizatsiia ta avtomatyzatsiia lohistychnykh protsesiv: suchasnyi stan ta perspektyvy [Digitalization and automation of logistics processes: current state and prospects]. Ekonomika ta suspilstvo – Economy and society, (68). https://doi.org/10.32782/2524-0072/2024-68-193 (in Ukrainian)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Copyright (c) 2025 Inna Ippolitova, Maryna Mashchenko, Yevhenii Ippolitov
