We know from the avalanche of year-end reports, surveys, and predictions that supply chain risk is top of mind for Boards of Directors and senior business executives all over the world and in every industry.
A few examples:

We have also seen a huge uptick in regulatory oversight paying attention to third-party and supply chain risk:

These are only some of the reasons why boards and senior executives are rightly paying attention to third-party and supply chain risk. But to be blunt, knowing something is important and knowing why it’s important are very often very different things. And in my experience (I’ve spoken to dozens of boards, hundreds of board members, and thousands of cybersecurity leaders that engage with their boards) these senior executives know they need to pay attention to supply chain risk, but don’t always know why.
A sample question guaranteed to freeze people in their tracks is: “if a critical partner in your supply chain (physical or digital) got hit with ransomware and were down for a week, how long would you be impacted?” Compare this to “one of our partners doesn’t do a good job of patching, has open ports to the Internet, and doesn’t use MFA.” As I always say, focus on the business impact and not on the technical issues.

The time has come to help your board and executives really understand why cybersecurity is a critical element of supply chain risk management.
Focus on operational and financial impacts – even if you can’t come up with hard numbers, you can ask questions about operational impact if any element within your supply chain got hit with ransomware, or was breached and lost critical data.