Skip to content

Reducing Cybersecurity Risk In 2025: Consider A Supply Chain Strategy

By Edward Tuorinsky

DTS CEO, Edward Tuorinsky, shares his insights with Forbes Business Council, on reducing cybersecurity risk in 2025: consider a supply chain strategy.

Despite increased cybersecurity budgets, the landscape for U.S. businesses continues to be hazardous. Breaches are up 72%, costing businesses an average of $4.88 million. Government mandates for contractors to meet minimum cybersecurity standards went into effect in December 2024, lagging behind private-sector efforts. Companies of all kinds and sizes are looking for new ways to defend against threats—and lower the temperature of risks.

There’s a new strategy to consider: Creating a safer supply chain.

How will your company handle skyrocketing cybersecurity risks in the year ahead?

Mitigating Risk

The traditional approach to risk mitigation is to assess and prioritize risks and then tackle each, starting from the top. For cybersecurity risk, that often includes tactics such as employee training, strong network access controls and multifactor authentication. These moves strengthen a company’s defenses.

The supply chain strategy takes a different approach. By agreeing to uphold higher standards for cybersecurity, companies can create a safer operating environment for their business and that of their partners, vendors and suppliers.

The Supply Chain Strategy

Increasingly, U.S. companies view cybersecurity as a business problem, not just a technical one. Every business process or connection is being reexamined with a zero-trust mindset, which assumes all users, devices and connections are untrustworthy until verified.

In practice, a supply chain risk mitigation strategy includes:

• Defining the network of companies and people involved in the production and delivery of your products or services.

• Identifying those with whom you share systems, applications or proprietary information.

• Establishing policies around minimum cybersecurity standards and secure standard operating procedures.

• Advising each connection of your policies and requirements.

• Verifying the cybersecurity posture of each trusted connection.

• Minimizing exposure with noncompliant companies or replacing them within your network.

Cybersecurity vetting of new and existing supply chain connections is the modern equivalent of asking for a business’s credit rating—an objective data point reflecting business health. However, unlike a credit score, those asking will need to verify the information that partners provide, which may require a nondisclosure agreement and the need for cybersecurity expertise or legal counsel.

Proof-based cybersecurity verification includes System Security Plans and/or third-party certifications, including ISO, SOC, CMMC or other audit-based standards.

Read the full article here: Reducing Cybersecurity Risk In 2025: Consider A Supply Chain Strategy

Consult with DTS today to strengthen your cybersecurity, reduce risks, prevent breaches, and enhance your business resilience for the future.

About DTS

Share this Article
More Insights
  • Baseline Safeguards for a Cross-Framework Security Foundation
    Team DTS April 27, 2026

    Organizations often operate under multiple frameworks, including NIST Cybersecurity Framework, NIST 800-171, ISO 27001, and SOC 2. While each uses different terminology, their foundational safeguards share…

  • Enforcing Authorized User and Device Controls for CMMC-Aligned Security
    Team DTS April 15, 2026

    Controlling who can access systems and what devices they use is one of the most fundamental principles in federal cybersecurity standards. NIST SP 800-171,…

  • Establishing an Operating Rhythm for Security Excellence
    Team DTS March 26, 2026

    Security is not a one-time project. Federal guidance and industry frameworks consistently reinforce that the effectiveness of security controls depends on continuous operation. A…

  • Building an Organized Evidence Kit for a Strong and Defensible Security Program
    Team DTS March 17, 2026

    A security program is only as strong as its ability to demonstrate outcomes. Federal frameworks such as NIST SP 800-171 and the CMMC assessment…

  • Scope What Matters: Building a Focused and Sustainable Security Program
    Team DTS February 23, 2026

    A security program becomes repeatable only when it focuses on the systems and processes that truly matter. Federal guidance such as NIST SP 800-171…

  • Information Governance and CUI: Establishing Structure for CMMC Compliance
    Team DTS February 18, 2026

    February is recognized as Information Governance Month, with February 19 marking Global Information Governance Day. For organizations supporting federal contracts, information governance defines how…

  • 8 Essential Data Privacy Practices for Federal Contractors
    Team DTS January 27, 2026

    A clear, actionable guide to protecting sensitive information and preparing for evolving privacy expectations Introduction Data Privacy Week arrives at a time when organizations…

  • Strengthening Identity Integrity and MFA Controls to Prevent Credential Theft
    Team DTS December 4, 2025

    Identity is the core of modern cybersecurity. Federal frameworks, including NIST SP 800-171 and CMMC, consistently emphasize maintaining traceable, unique identities and enforcing multi-factor…

  • A Practical Starting Point for CMMC Readiness
    Jamie Repesh November 24, 2025

    CMMC requirements are now being incorporated into Department of Defense (the Department) contracts following the November 10 effective date of DFARS 252.204-7021. With the…

  • “Are you certified?” may become the most used phrase in business this year.
    Edward Tuorinsky January 11, 2025

    DTS CEO, Edward Tuorinsky, shares his insights with Intelligent CXO, on a pivotal growth opportunity for businesses in 2025: cybersecurity compliance and supply chain risk…

  • Building A Motivated Team: Hiring Advice For The Workforce You Need Next
    Edward Tuorinsky December 26, 2024

    It’s not often that you get business advice from the Pat McAfee Show, but a few weeks ago, college football coaching great Nick Saban…

  • Budget Considerations for Cybersecurity
    Edward Tuorinsky December 23, 2024

    We’ve entered an era of new business risk. Our fast-evolving IT landscape comes with even faster-evolving cybersecurity threats. Companies understandably want to protect their…