Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Manufacturing

Security risk in the suppliers that keep production moving.

F Creative Studio 360 helps manufacturers and operators in any country see which suppliers can affect a product, a plant or a customer’s data, and what evidence they can actually produce.

A supplier is part of the system.

NIST SP 800-161 is a usable way to write supply-chain cyber risk. It is not a certification. Where a customer or a regulator names a different method, that method is used instead.

The work covers technology suppliers and the parties who can reach operational systems. It is not a legal review of the contract. Counsel owns that.

Evidence, not a questionnaire score
A returned spreadsheet is the start. The review asks what sits behind the answer.
Software and services
Libraries in the product, and firms that maintain the plant, are both suppliers.
Concentration
One firm that every site depends on is a different risk from a long list of small ones.
We do not audit the supplier for you by surprise
Contact with a supplier happens only if you ask for it and the supplier agrees.

What the review covers

The suppliers you depend on for the product or the plant in scope.

Who matters
Parties whose failure or compromise would stop production or expose data.
What you hold
Contracts, reports and access lists, and how old they are.
How they connect
Remote access, software updates and data feeds.
What you will do
If the evidence is thin, or if the supplier will not provide it.

How an engagement runs

Suppliers can sit in any country. The review follows the dependency, not the headquarters.

  1. 1

    List the dependencies

    Product, plant and data. You set the cutoff.

  2. 2

    Read the evidence

    What you already have, before anyone is contacted.

  3. 3

    Rank the gaps

    By the effect on production or on a customer.

  4. 4

    Hand back an oversight rhythm

    What to ask again, and when.

What you receive

  • A ranked view of suppliers in scope.
  • The evidence you have, and the evidence you do not.
  • A suggested oversight rhythm.
  • No legal opinion on a contract, and no certificate.

What this is not

This is not a penetration test of a supplier, and it is not a promise that a supplier is safe because they answered a form.

Common questions

Will you contact our suppliers?+

Only when you ask, and only the suppliers who agree. The default is a review of the evidence you already hold.

Who is this for?+

Manufacturers and operators in any country. Suppliers can sit anywhere. A local rule is added only when it applies to you.

Where do you deliver this?+

For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.

How much does it cost, and how long does it take?+

It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Rank the suppliers who can stop the line.

F Creative Studio 360 will look at the dependencies you name, then say what the review includes.