Cybersecurity Today TV - Ep67 - Supply Chain Risk Management for Small and Medium Size Organizations

Cybersecurity Today TV - Ep67 - Supply Chain Risk Management for Small and Medium Size Organizations

🎙 CybersecurityToday 👥 492 📅 November 11, 2025 ⏱ 29 min 👁 68 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

supply chainrisk managementSMBvendor due diligenceincident response

Summary

The episode of Cybersecurity Today TV focuses on supply chain risk management for small and medium-sized organizations. Host Jim Wiggins introduces the show’s mission and structure, then presents several current cybersecurity news items, including a critical Oracle E-Business Suite vulnerability (CVE-2025-61882) exploited in the wild, a phishing campaign targeting executives, and a breach at F5 Networks affecting BIG-IP products. The main segment features an interview with Shannon Noonan, CEO of HiNoon Consulting and US Global Ambassador for the Global Council for Responsible AI. She discusses the evolving definition of supply chain risk, emphasizing the importance of data as currency and the need for SMBs to understand their dependencies. She advises on vendor due diligence, including asking about security measures, encryption, and multi-factor authentication, and suggests using tools like SOC reports and software bills of materials. She highlights the importance of incident response planning, cyber insurance, and continuous monitoring, and recommends leveraging managed security service providers. The conversation underscores that SMBs often lack awareness of their indirect dependencies and need to build resilience through practical planning and education.

177 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable practical advice for SMBs on supply chain risk management, drawing on the expert’s extensive experience. The argumentation is based on anecdotal evidence and general industry knowledge rather than empirical data or case studies. The expert effectively communicates the importance of understanding supply chain dependencies and offers actionable steps, such as conducting vendor due diligence and creating contingency plans. However, the discussion remains at a high level and lacks specific technical details or concrete examples that would strengthen the argumentation. The advice is sound but not novel, and the lack of citations to authoritative sources reduces its scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The video does not cite specific sources or references, relying instead on the expert’s personal experience and general industry knowledge. The title accurately reflects the content, which is a talk show format with a focus on supply chain risk management for SMBs. The news segment mentions specific vulnerabilities and breaches but does not provide links or further references. The lack of citations and reliance on anecdotal evidence limit the scientific rigor of the content. The title is appropriate and does not overpromise.

199 words

Title / Content Match

The title accurately reflects the content, which focuses on supply chain risk management for SMBs, with a dedicated segment and expert interview.

Quality & Reliability

6/10

The video features an expert with over 20 years of experience, providing practical advice based on anecdotal evidence and general industry knowledge. However, it lacks specific data, citations, or references to scientific studies, and the discussion remains at a high level without deep technical detail.

Key Moments

Concurring Sources

  • NIST Cybersecurity Framework — Provides a framework for managing cybersecurity risks, including supply chain risk management.
  • CISA SBOM Guidance — CISA's guidance on Software Bill of Materials, relevant to the discussion on tracking software assets.

Contribution & Novelties

The video offers a practical, expert perspective on supply chain risk management tailored to SMBs, emphasizing the need for proactive vendor due diligence and resilience planning. It highlights the often-overlooked indirect dependencies and the importance of data as a critical asset. While the advice is not groundbreaking, it serves as a useful primer for SMBs.

Pour aller plus loin :

  • NIST Cybersecurity Framework — Provides a structured approach to managing cybersecurity risks, including supply chain considerations.
  • ISO 28000 — International standard for supply chain security management systems.
  • Software Bill of Materials (SBOM) — CISA’s guidance on SBOMs for managing software supply chain risks.
  • Third-party risk management — Overview of the discipline and its importance.

114 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with a slightly higher score in 'quantite_information' and 'fiabilite_globale' compared to 'niveau_technique'. This indicates a balanced but not highly technical or deeply sourced content, suitable for a general audience.

Reliability 6/10

💬 No comments were provided for analysis.