Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
blog

Supply Chain Incident Response Starts Before the Incident

Published

Sep 15, 2026

Introduction

Every incident response plan I have reviewed in 30+ years tells the same story, and they invariably start too late. I’ve also been involved in hundreds of tabletop exercises and they always start off with, ‘OK, something bad happened … now what?

Something bad happens. Whether it’s a vendor ransomware attack, a supplier going down, a bunch of critical files are encrypted, or a bad actor rides right into your network across a so-called ‘trusted’ network connection.  The help desk gets inundated with calls and emails, someone opens a ticket, another someone else opens a bridge call, and a room full of smart people scrambles to work out what happened, who is affected, and what to do next.

That chaotic scramble has a name. We call it incident response. What it usually is, in practice, is herding cats and mass chaos.

By the time an organization responds, the attacker has already played their opening moves. They picked the target, the timing, and the method, and they had days or weeks of access before anyone noticed. Mandiant's M-Trends 2026 report found attackers exploiting vulnerabilities an average of seven days before public disclosure, which means the exploitation window has flipped - bad actors are acting badly for a week before defenders know they have an exposure.

The 2026 Supply Chain Vulnerability Report from the Black Kite Research Group™ tracked what happens after that initial access. The median handoff from the actor who breaks into a vendor environment to the ransomware operator who monetizes it is now 22 seconds. In 2022 it was eight hours.

And then there is the notification gap. Black Kite’s 2026 Third-Party Breach Report found an  an average delay of 117 days to before they know a vendor has been breached. Twenty-two seconds on their side, four months on ours - a factor of 459,49. Most response plans still run on the clock that existed five or more years ago.

Traditional Supply Chain Incident Response Starts in the Wrong Place

An incident triggers an alert (or set of alerts); detection triggers the workflow; workflow triggers communication; communication triggers decisions that should have been made months earlier.

That sequence puts an organization on its back foot before the end of the first conference call ends. It is reactive by design, not by accident.

Flip the sequence and everything changes. The decisions, the automation, and the communication paths get built, tested and validated in advance; when something happens the team executes a well tested and fully socialized plan instead of flying by the seat of their pants.

Doing more tabletop exercises will not fix this, and neither will a thicker dust covered binder. The fix is changing the foundation of the plan.

Start With Risk. Threats Are Only Context.

Most response planning starts with threats: ransomware groups, exploited CVEs, nation-state activity.

Threats are useful. They are also external and almost entirely out of your hands. Nobody negotiates with a threat actor's roadmap.

Risk is the variable you control. Risk is what happens to the business when a threat meets a vulnerability, and it is the part of the equation your organization gets a vote on.

I say this all the time: your executives care about three things. 

  1. Money coming in,
  2. Money going out,
  3. And if something goes bad, who gets in trouble

While that may sound like a dramatic oversimplification (and maybe it is). It is also the core of the risk conversation at the executive level, and a far better starting point than any threat feed.

The increasingly complex ecosystem of third-parties, vendors, and suppliers adds risk, both known and unknown, and forces conversations that are necessary for managing business and resilience risk. A supplier's incident becomes your incident the moment it touches your data, your operations, or your obligations to customers and regulators. Build the plan on threat intelligence alone and it answers what could happen to them. It never gets to what happens to us, and what that costs.

Work Backward From the Loss

Start from the outcome you are trying to prevent, then build backward toward the controls.

  • Start from the data you cannot afford to lose, then work backward to which suppliers touch it. Most teams find the list is longer and stranger than their vendor tiering suggests, because tiering usually tracks spend rather than access.
  • Start from the fines and penalties attached to a compliance failure, then work backward to the contractual obligations that create the exposure. Legal already knows. Ask them before the incident rather than during it.
  • Start from the cost of downtime, then work backward to which vendors, if compromised, would actually stop the business. Cyber risk quantification puts that number in dollars, which is the only unit a board hears clearly.
  • Start from the conversation you will have with the board, then work backward to the evidence you need ready before that conversation happens. You will not assemble it in the first 48 hours.

This inverts the traditional model, which starts from everything that could go wrong and hopes the response scales to match. Working backward from business impact produces a plan proportional to what matters, instead of one that assigns every vendor and every alert the same generic urgency.

Force people out of their seats into someone else's shoes

When I ran incident response workshops, I gave everyone somebody else's job. You are the CFO? Not today. Now you are the CIO. Now you are general counsel. It rarely went the way we planned, but nearly every session ended with someone saying “we never thought about that before.” And that is the win!

That sentence is the point. Decisions made in advance only hold up if the people making them can see the incident from more than one perspective. IR is a group effort and we cannot act properly in a group without understanding everyone's perspective and objectives. Imagine trying to run a play in football when the O-Line doesn't know the back is running through the 3 hole.

Automating Supply Chain Incident Response Without Going Blind

None of this works if "before the incident" just means more planning meetings.

The goal is automation that moves fast without moving blind. Three things make that real.

  • Playbooks aligned to the risk of the relationship, rather than one generic runbook applied to 4,000 vendors as though they all carry identical weight. A payroll processor and a landscaping contractor do not warrant the same escalation path.
  • Automated triggers for containment, communication, and escalation that fire the moment a risk threshold is crossed, so nobody is waiting on a human to notice first. FocusTags® do this by surfacing which vendors are exposed to an active event instead of leaving a team to audit the whole portfolio by hand.
  • Communication paths that already exist when you need them. The slowest part of most third-party incidents is rarely the technical work. It is vendor outreach during a crisis event, and The Bridge™ replaces that email-and-spreadsheet scramble with a channel that is open before the call comes.

Where judgment still belongs

Real incidents never unfold the way tabletops do, which is exactly why the automation has to be simple, steerable by people who understand the intent behind the plan and not just the steps in it, we need to identify the human in the loop. Comprehensive does not equal rigid or inflexible. The strongest programs have already made the hard decisions, automated the fast ones, and left room for judgment where judgment earns its keep.

The Payoff Is Speed

An organization that has already settled what matters, who is accountable, and what triggers action can execute clearly when a supplier gets hit. Everyone else convenes a meeting.

Deciding in advance rather than in the moment is the entire advantage this shift creates. Against adversaries whose clock keeps compressing, it is the advantage that counts.

The old model asks what happened and what we do now. Try a better question: what can we afford to lose, and what have we already built to keep it?

Which one is your organization answering today? If the honest answer is the first one, vendor risk response is where to start closing the gap. Book a demo and see which of your suppliers would be the first call.