The Risk Between Here and There

A shipment can leave a secure facility, travel in a secured trailer and arrive at another secure facility, and still move through several points where nobody has complete visibility or control.

Those are the points I pay attention to.

Supply chains are built around transitions. A shipment moves from the shipper to a carrier, from a facility to a driver, through yards and distribution points, sometimes between carriers or third-party providers, and eventually to the customer. Every time custody or responsibility changes, there is an opportunity for information, accountability and physical control to become separated.

The problem isn't necessarily that nobody is responsible. More often, several different parties are responsible for different pieces of the movement. The facility knows when the product left. The carrier knows when the driver departed. A tracking system knows where the trailer is supposed to be. The receiving location knows when the shipment arrived. A third-party provider may control another portion of the process.

Each one may have good information, but that doesn't automatically create good visibility across the entire movement. That becomes particularly important when something goes wrong.

If product is missing, one of the first questions in an investigation is deceptively simple: When was the last time we know the product was where it was supposed to be? Where can we actually establish custody and condition? That distinction can dramatically change an investigation.

A seal number may have been recorded, but was it verified at the next handoff? A trailer may have arrived at a yard, but who accepted responsibility for it? A shipment may show as delivered in one system while another record tells a different story. A driver may have followed the required process while the vulnerability existed somewhere entirely outside the driver's control. The longer it takes to establish where the chain broke, the more difficult the response becomes.

Security has to cross organizational boundaries. This is one reason supply chain security can't live entirely inside the security department.

Operations and Transportation each own parts of the process. Facilities may own another piece. Procurement determines which vendors and carriers are being used. Technology supports the systems creating visibility. Legal may become involved when a loss occurs. Customers have their own requirements and expectations.

Then there are outside organizations that the company doesn't directly control at all.

A security leader has to understand how all of those pieces interact because a control that works perfectly inside one company's four walls may mean very little once the product moves outside them.

You cannot eliminate every handoff from a supply chain, nor should you try. The objective is to make sure a transition doesn't also become a loss of accountability.

That means knowing what should happen when custody changes, what confirms that it happened correctly and what causes someone to investigate when it doesn't.

Technology can be extremely useful here. GPS, geofencing, electronic seals, access-control data, video, shipment records and other tools can help establish where something was and when, but technology is most valuable when it supports a well-defined process.

If five systems collect information and nobody is looking at the relationship between them, you may have plenty of data and very little visibility.

Consider This

The people who need to examine handoffs aren't simply “Security.” It should involve the functions that actually own the movement of the product: Security, Operations, Transportation or Logistics, Procurement, Facilities, Technology and, where appropriate, key carriers and third-party providers.

The useful exercise isn't drawing a flowchart for the sake of having one. It's identifying the transitions where responsibility, physical custody and information can become disconnected.

At the important handoffs, I want to know whether we can answer a few basic questions: Who had custody? Who accepted it next? How was that transfer verified? What information was captured? What would tell us the expected transfer didn't happen? And who would know soon enough to do something about it?

If those answers exist only inside separate departments, vendors and systems, the company may not have the visibility it thinks it has. A supply chain is only as secure as its ability to maintain accountability while the product is moving.

Previous
Previous

Insurance Doesn’t Make You Whole

Next
Next

The Security You Can’t See