Supply Chain Security Audit
Supply Chain Security Audit

Vertrouw op leveranciers die uw productie niet kwetsbaar maken.

Trust suppliers that do not put your production at risk.

Met de Supply Chain Security Audit van OranjeRaksha beoordelen we de beveiliging van uw belangrijkste toeleveranciers – met name EMS- en elektronicafabrikanten die hardware, modules en assemblies voor u produceren.

We kijken naar governance, productieprocessen, logistiek, informatiebeveiliging, fysieke beveiliging en derde-partij risico’s. Onze ervaring omvat audits in Europa, Azië en de Amerika’s bij leveranciers van netwerkapparatuur, automotive, navigatie en consumentenelektronica.

With the Supply Chain Security Audit from OranjeRaksha we assess the security of your key suppliers – especially EMS and electronics manufacturers producing hardware, modules and assemblies for you.

We review governance, shop-floor processes, logistics, information protection, physical security and third-party risk. Our experience covers audits across Europe, Asia and the Americas for networking, automotive, navigation and consumer electronics brands.

EMS & elektronicafabrikanten Productie, logistiek & warehousing Informatiebeveiliging & IP-bescherming NIS2 · ISO 27001 · TISAX · CTPAT EMS & electronics manufacturing Production, logistics & warehousing Information security & IP protection NIS2 · ISO 27001 · TISAX · CTPAT

Wat is een Supply Chain Security Audit?

What is a Supply Chain Security Audit?

Een Supply Chain Security Audit onderzoekt hoe goed uw belangrijkste leveranciers omgaan met de beveiliging van uw producten, data, IP en materialen.

A Supply Chain Security Audit evaluates how well your key suppliers protect your products, data, IP and material flows.

We kijken naar beleid, processen en maatregelen bij de leverancier: hoe is security georganiseerd, hoe worden productielijnen en magazijnen beveiligd, en hoe wordt omgegaan met uw tekeningen, stuklijsten, firmware en klantdata?

We look at policies, processes and controls at the supplier: how security is governed, how production lines and warehouses are protected, and how your drawings, BOMs, firmware and customer data are handled and shared.

Het resultaat is een concreet beeld van de security-volwassenheid van uw leveranciers, inclusief verbeterpunten, risico’s per domein en praktische aanbevelingen om uw supply chain aantoonbaar veiliger te maken.

The result is a concrete view of your suppliers’ security maturity, including improvement areas, risks per domain and practical recommendations to demonstrably strengthen your supply chain.

Waarom is dit zo belangrijk?

Why does it matter?

Uw productie, levering en merk zijn zo sterk als de zwakste schakel in uw supply chain. Een incident bij een leverancier kan direct leiden tot productiestops, vertraagde leveringen of reputatieschade.

Your production, delivery capability and brand are only as strong as the weakest link in your supply chain. An incident at a supplier can immediately trigger production stops, delivery delays or reputational damage.

In de praktijk zien we leveranciers met gedeelde accounts, beperkte fysieke beveiliging, gebrekkige incidentprocessen, onduidelijke IP-afspraken en weinig inzicht in derde partijen die zij zelf inschakelen.

In practice we see suppliers with shared accounts, weak physical security, immature incident processes, unclear IP arrangements and poor visibility of their own subcontractors and third parties.

Een Supply Chain Security Audit helpt u gericht eisen te stellen, verbeterplans af te spreken en een aantoonbaar veiligheidsniveau te realiseren bij leveranciers – steeds vaker vereist door klanten, toezichthouders en normen zoals NIS2, ISO 27001, TISAX en waar relevant CTPAT-principes.

A Supply Chain Security Audit helps you set clear requirements, agree remediation plans and achieve a demonstrable security level at suppliers – increasingly required by customers, regulators and frameworks such as NIS2, ISO 27001, TISAX and, where relevant, CTPAT principles.

Voor wie
Who Is This For?

Voor wie is dit?

Who is this for?

Een Supply Chain Security Audit is relevant voor elke organisatie die afhankelijk is van externe leveranciers voor productie, logistiek of technologie.

A Supply Chain Security Audit is relevant for any organisation that depends on external suppliers for production, logistics or technology.

🏭
Supply Chain Manager
Supply Chain Manager

Wil inzicht in de securitypositie van kritieke leveranciers en aantoonbare verbetering van de keten.

Wants insight into the security posture of critical suppliers and demonstrable improvement across the chain.

🛒
Inkoop & Procurement
Procurement Team

Wil leveranciersrisico’s objectief beoordelen en security opnemen in aanbestedingen en contracten.

Wants to objectively assess supplier risks and embed security requirements in tenders and contracts.

🛡️
CISO / Security Manager
CISO / Security Manager

Wil third-party risico’s in kaart brengen en een basis leggen voor NIS2- en ISO 27001-compliance.

Wants to map third-party risks and build a foundation for NIS2 and ISO 27001 compliance.

📋
Compliance Officer
Compliance Officer

Heeft auditwaardige documentatie nodig voor NIS2, ISO 27001, TISAX, CTPAT-gerelateerde eisen of sectorspecifieke regelgeving.

Needs audit-grade documentation for NIS2, ISO 27001, TISAX, CTPAT-related requirements or sector-specific regulatory requirements.

🔧
Maakindustrie & OEM
Manufacturing & OEM

Produceert hardware via EMS-partners en wil zekerheid over beveiliging van ontwerpen, firmware en materialen.

Produces hardware via EMS partners and wants assurance on the security of designs, firmware and materials.

🌐
Multi-regio organisaties
Multi-region organisations

Heeft leveranciers in Europa, Azië en de Amerika’s en wil consistent inzicht in ketenrisico’s per regio.

Has suppliers in Europe, Asia and the Americas and wants consistent insight into chain risks per region.


Praktijkvoorbeelden
Real-world Cases

Praktijkvoorbeelden uit de keten

Real-world supply chain scenarios

Onderstaande voorbeelden zijn gebaseerd op publiek bekende incidenten. Ze laten zien hoe snel een leverancierincident kan doorslaan naar productie, logistiek en merkvertrouwen.

The examples below are based on publicly known incidents. They show how quickly a supplier incident can cascade into production, logistics and brand impact.

Scenario 1 – Jaguar Land Rover leverancier (2025)
Scenario 1 – Jaguar Land Rover supplier (2025)
Productiestop door cyberincident bij toeleverancier
Production halt caused by supplier cyber incident

In 2025 werd een belangrijke toeleverancier van Jaguar Land Rover geraakt door een cyberincident dat de beschikbaarheid van systemen verstoorde. Hierdoor konden onderdelen niet op tijd worden geleverd en moest JLR productieplannen aanpassen en lijnen tijdelijk stilleggen. Het incident vond plaats bij de leverancier, maar de impact was direct voelbaar in de productie- en planningsketen van JLR.

In 2025, a key supplier of Jaguar Land Rover suffered a cyber incident that disrupted system availability. As a result, parts could not be delivered on time and JLR had to adjust production schedules and temporarily halt certain lines. The incident took place at the supplier, but the impact was immediately felt across JLR’s production and planning chain.

Dit laat zien dat continuïteit niet alleen afhangt van de eigen fabriek, maar ook van de cyberweerbaarheid van leveranciers en de interfaces die hen verbinden met uw productie- en planningssystemen.

This shows that continuity does not only depend on your own plant, but also on the cyber resilience of suppliers and the interfaces connecting them to your production and planning systems.

Scenario 2 – SolarWinds supply chain aanval (2020)
Scenario 2 – SolarWinds supply chain attack (2020)
Kwaadaardige code via vertrouwde softwareleverancier
Malicious code delivered via trusted software supplier

Bij de SolarWinds-aanval werd kwaadaardige code verborgen in een legitieme software-update die door duizenden organisaties wereldwijd werd geïnstalleerd. Aanvallers kregen zo toegang tot netwerken van overheidsinstanties, techbedrijven en kritieke sectoren – via een vertrouwde toeleverancier in de softwareketen.

In the SolarWinds attack, malicious code was hidden inside a legitimate software update that thousands of organisations worldwide installed. Attackers gained access to networks of government agencies, technology companies and critical sectors – through a trusted supplier in the software supply chain.

Dit incident illustreert waarom ook softwareleveranciers, cloudproviders en toolingpartners deel uitmaken van uw supply chain risico en periodiek beoordeeld moeten worden op hun security-volwassenheid.

This incident illustrates why software suppliers, cloud providers and tooling partners are also part of your supply chain risk and should be periodically assessed for their security maturity.

Scope & Dekking
Scope & Coverage

Wat is typisch in scope?

What is typically in scope?

Scope wordt altijd vooraf afgesproken. Onderstaand overzicht toont wat een standaard audit dekt – en wat buiten scope valt.

Scope is always agreed upfront. Below is what a standard audit covers – and what falls outside it.

Typisch in scope
Typically in scope
EMS- en elektronicafabrikantenEMS and electronics manufacturers
Governance & securitybeleid leverancierSupplier governance & security policy
Productievloer, magazijnen & logistiekShop floor, warehouses & logistics
CTPAT-gerelateerde fysieke, transport- en seal-controles waar relevantCTPAT-related physical, transport and seal controls where relevant
Informatiebeveiliging & netwerksegmentatieInformation security & network segmentation
IP-bescherming, data & cryptomateriaalIP protection, data & cryptographic material
Toegangsbeheer, accounts & vendor-toegangAccess control, accounts & vendor access
Incidentrespons & business continuityIncident response & business continuity
Third parties van de leverancier (op verzoek)Supplier’s own third parties (on request)
Typisch buiten scope
Typically out of scope
Officiële CTPAT-certificering of validatie door overheidsinstantiesOfficial CTPAT certification or government validation
OT/SCADA-systemen – zie OT Security AuditOT/SCADA systems – see OT Security Audit
Penetratietests – zie Penetration TestingPenetration tests – see Penetration Testing
Destructief testen of actieve exploitsDestructive testing or active exploits
Externe SaaS-platforms buiten eigendom leverancierThird-party SaaS not owned by supplier
Systemen buiten overeengekomen scopeSystems outside agreed scope

Auditdomeinen
Audit Domains

Scope van de Supply Chain Security Audit

Scope of the Supply Chain Security Audit

De audit is gebaseerd op praktijkervaring en best practices uit ISO 27001, NIST, TISAX en waar relevant CTPAT-richtlijnen voor logistieke en fysieke supply chain security. We richten ons op zes kerngebieden die samen een compleet beeld geven van security in de keten.

The audit draws on field experience and best practices from ISO 27001, NIST, TISAX and, where relevant, CTPAT guidance for logistics and physical supply chain security. We cover six core domains that together provide a complete picture of supply chain security.

1. Governance, risk & compliance

1. Governance, risk & compliance

Hoe is security georganiseerd bij de leverancier? We kijken naar beleid, verantwoordelijkheden, risicomanagement en compliance met relevante normen.

How is security organised at the supplier? We review policies, responsibilities, risk management and compliance with relevant standards.

  • Informatiebeveiligingsprogramma, rollen & verantwoordelijkheden.
  • Securitybeleid, standaarden en procedures.
  • Risico-analyse, interne audits en compliance-rapportage.
  • Information security programme, roles & responsibilities.
  • Security policies, standards and procedures.
  • Risk assessment, internal audits and compliance reporting.

2. Manufacturing & operations security

2. Manufacturing & operations security

Bescherming van materialen, IP en producten in de fabriek: van inbound-materialen tot scrap-management en counterfeit-preventie.

Protection of materials, IP and products on the shop floor: from inbound material to scrap management and counterfeit prevention.

  • Tracking & traceability van materialen en orders.
  • Beveiliging van inventory en handling van proprietary items.
  • Segregation of duties, scrap-beheer en anti-counterfeit maatregelen.
  • Tracking & traceability of materials and orders.
  • Security of inventory and handling of proprietary items.
  • Segregation of duties, scrap management and anti-counterfeit controls.

3. Informatie- & infrastructuurbeveiliging

3. Information & infrastructure protection

Bescherming van uw data, ontwerpen, firmware en systemen bij de leverancier – inclusief netwerkbeveiliging en logging.

Protection of your data, designs, firmware and systems at the supplier – including network security and logging.

  • Dataclassificatie, handling en encryptie (rust & transit).
  • Toegangsbeheer, netwerkbeveiliging en configuratiemanagement.
  • Logging & monitoring, back-ups, retentie en veilige vernietiging.
  • Data classification, handling and encryption (at rest & in transit).
  • Access control, network security and configuration management.
  • Logging & monitoring, backups, retention and secure disposal.

4. Logistics, storage & physical security

4. Logistics, storage & physical security

Hoe worden goederen opgeslagen, verplaatst en beschermd? We kijken naar magazijnen, transitsecurity, fysieke controlemaatregelen en waar relevant CTPAT-principes.

How are goods stored, moved and protected? We review warehouses, transit security, physical safeguards and, where relevant, CTPAT principles.

  • Fysieke beveiliging van warehouses en productieruimtes.
  • Shipping & receiving, transport-beveiliging en seal-procedures.
  • Afstemming met CTPAT-principes voor transport, seal-controle, toegangsbeheer en fysieke beveiliging waar relevant.
  • Bezoekersbeheer, perimeterbeveiliging en onderhoudsactiviteiten.
  • Physical security of warehouses and production areas.
  • Shipping & receiving, transit security and seal procedures.
  • Alignment with CTPAT principles for transport, seal control, access management and physical security where relevant.
  • Visitor management, perimeter protection and maintenance activities.

5. People, access & incident management

5. People, access & incident management

Medewerkers, awareness en reactie op incidenten zijn cruciaal. We toetsen screening, training, contracten en incidentprocessen.

People, awareness and incident response are critical. We review screening, training, contractual controls and incident handling.

  • Pre-employment checks, NDA’s en contractuele security-clausules.
  • Security-training en awareness voor productie, IT en logistiek.
  • Incidentidentificatie, melding, respons en herstel.
  • Pre-employment checks, NDAs and contractual security clauses.
  • Security training and awareness for production, IT and logistics staff.
  • Incident identification, reporting, response and recovery.

6. Third parties, cloud & security engineering

6. Third parties, cloud & security engineering

Leveranciers werken zelf ook weer met cloud, 3rd tier partners en ontwikkelteams. We beoordelen hoe zij daarmee omgaan en welke eisen zij doorvertalen.

Suppliers in turn rely on cloud, 3rd tier partners and engineering teams. We assess how they manage those dependencies and propagate your security requirements.

  • Contractuele eisen richting onderaannemers en cloudproviders.
  • Secure design & development voor firmware, tools en portals.
  • Toezicht op downstream-risico’s en kwetsbaarheidsbeheer.
  • Contractual requirements for subcontractors and cloud providers.
  • Secure design & development for firmware, tools and portals.
  • Oversight of downstream risks and vulnerability management.

Onze aanpak
Our Approach

Onze aanpak

Our approach

Onze aanpak is ontwikkeld vanuit audits bij leveranciers van netwerkapparatuur, automotive, navigatie en consumentenelektronica. We combineren documentaire review, interviews en rondgangen op de werkvloer.

Our approach is shaped by audits at suppliers of networking equipment, automotive, navigation and consumer electronics. We combine document review, interviews and on-site walkthroughs.

1
Stap 1
Step 1
Scoping & voorbereiding
Scoping & preparation

We bepalen samen welke leveranciers, locaties en productielijnen in scope zijn. We stemmen af met inkoop, supply chain, kwaliteitsmanagement en security.

Together we define which suppliers, sites and production lines are in scope. We align with procurement, supply chain, quality and security stakeholders.

LeveranciersselectieScopebepalingSupplier selectionScope definition
2
Stap 2
Step 2
Documentatie & self-assessment
Documentation & self-assessment

We analyseren beleid, procedures, certificeringen, netwerkdiagrammen, fabriekslay-outs en BCP-plannen. Vaak starten we met een gestructureerde self-assessment.

We review policies, procedures, certifications, network diagrams, factory layouts and BCP plans. Often we begin with a structured self-assessment.

Gap-analyseBest practicesGap analysisBest practices
3
Stap 3
Step 3
On-site audit & walkthroughs
On-site audit & walkthroughs

We spreken met management, IT, security, operations, logistiek en HR, en lopen mee over de productievloer, magazijnen en kritieke ruimtes.

We interview management, IT, security, operations, logistics and HR, and perform walkthroughs on the shop floor, warehouses and critical areas.

Verificatie ter plaatseSteekproevenOn-site verificationSampling
4
Stap 4
Step 4
Technische & procesmatige checks
Technical & process checks

Waar mogelijk beoordelen we configuraties, toegangsrechten, logging, back-upprocedures en de manier waarop IP, data en cryptomateriaal worden opgeslagen.

Where feasible we review configurations, access rights, logging, backup procedures and how IP, data and cryptographic material are stored and shared.

Accounts & networkBCP & IR
5
Stap 5
Step 5
Rapportage & risicobeeld
Reporting & risk picture

U ontvangt een rapport met scoring per domein, concrete bevindingen, risico-inschatting en prioriteiten per leverancier of site.

You receive a report with domain scores, concrete findings, risk ratings and priorities per supplier or site.

NIS2 & ISO 27001TISAX & CTPATRoadmap
6
Stap 6
Step 6
Follow-up & begeleiding
Follow-up & guidance

Na de audit blijven we betrokken. We lichten bevindingen toe aan uw teams en aan de leverancier en kunnen een her-audit uitvoeren.

After the audit we stay engaged. We explain findings to your teams and to the supplier and can perform a re-audit to validate improvements.

DebriefRe-audit optioneelDebriefRe-audit optional

Gevoelige informatie wordt met de grootst mogelijke zorgvuldigheid behandeld en veilig vernietigd na de retentieperiode.

Sensitive information is handled with utmost care during the assessment and securely destroyed after the retention period.

Wat u ontvangt
What You Receive

Wat ontvangt u?

What you receive

Elke Supply Chain Security Audit levert een compleet, auditklaar pakket op – bruikbaar voor inkoop, supply chain, security en audit.

Every Supply Chain Security Audit delivers a complete, audit-ready package – usable by procurement, supply chain, security and audit teams.

📄
Managementsamenvatting
Executive Summary

Boardklaar overzicht van supply chain risicopositie, kernbevindingen en aanbevolen prioriteiten per leverancier.

Board-ready overview of supply chain risk posture, key findings and recommended priorities per supplier.

🔍
Technisch bevindingsrapport
Technical Findings Report

Gedetailleerde documentatie per bevinding: beschrijving, bewijs, risiconiveau en herstelstappen per domein.

Detailed per-finding documentation: description, evidence, risk level and remediation steps per domain.

📊
Domain scoring per leverancier
Domain scores per supplier

Scoringsoverzicht per auditdomein – bruikbaar voor leveranciersvergelijking en opvolging.

Score overview per audit domain – usable for supplier comparison and follow-up tracking.

🗺️
Verbeteringsroadmap
Remediation Roadmap

Gefaseerd actieplan: quick wins, kortetermijnfixes en structurele verbeteringen per leverancier.

Phased action plan: quick wins, short-term fixes and structural improvements per supplier.

🤝
Debrief & teamsessie
Debrief & Team Session

Live walkthrough met inkoop, supply chain en leveranciersteams – vragen beantwoord, prioriteiten afgestemd.

Live walkthrough with procurement, supply chain and supplier teams – questions answered, priorities aligned.

🔁
Optionele re-audit
Optional Re-audit

Na implementatie bevestigt een re-audit dat kritieke bevindingen bij de leverancier effectief zijn opgelost.

After implementation, a re-audit confirms that critical findings at the supplier have been effectively resolved.

Wilt u meer zekerheid over de security van uw leveranciers in Europa, Azië of de Amerika’s? Deel kort uw leverancierslandschap en wij helpen u de scope te bepalen.

Want greater assurance about the security of your suppliers in Europe, Asia or the Americas? Share a short overview of your supplier landscape and we will help define the scope.

Vraag uw Supply Chain Security Audit aan Request Your Supply Chain Security Audit

Geen verplichtingen. Wij reageren doorgaans binnen 1 werkdag. No commitment. We typically respond within 1 business day.


Veelgestelde vragen
Frequently Asked Questions

Veelgestelde vragen

Frequently Asked Questions


Gerelateerde diensten
Related Services

Heeft u ook dit nodig?

You might also need

Een Supply Chain Security Audit is vaak onderdeel van een bredere securitystrategie. Deze diensten vullen elkaar goed aan.

A Supply Chain Security Audit is often part of a broader security strategy – these services complement it well.