Non classé
The Critical Role of Provenance in Cybersecurity and Supply Chains
Published
1 an agoon
By
The Power Inverter Kill Switch Story Underlines The Importance Of Provenance in Cybersecurity and the Supply Chain
Do you really know what your production assets contain?
If you’ve ever bought antiques, you’re probably familiar with the concept of provenance. I have relatives that own a dresser that was gifted from George Washington to a family friend when he was a lieutenant in the colonial army. How do we know this? Because of the authenticated documentation that came with the dresser proving its origin. This is provenance – proving and documenting where something came from, what it contains, and the path it took before it wound up in your possession.
Heavy assets in industrial automation are a lot more complex than antiques, and the stakes are a lot higher, as we saw recently with the story about cellular powered kill switches found in Chinese manufactured power inverters used in solar and wind farms. In addition to being used around the world for renewable power applications, these inverters are also used in batteries, heat pumps, EV chargers, and other assets.
It’s typical for these products to have remote access capabilities, but these connections are normally handled through firewalls. You may have read the story about Chinese manufactured cranes that have remote connectivity capabilities but are largely unsecured. Many end users were not even aware of these remote communication capabilities, or if they were, they were improperly secured. If your assets come with features and functions that present a potential cybersecurity risk to your enterprise and you don’t address it or are not aware of it even though it is documented, that’s ultimately your responsibility, not the vendor’s.
The Problem of Rogue Components
It’s not always obvious what all the components are in an asset, be they hardware or software. The more complex the asset, the more complicated the issue becomes. In the case of the power inverters, the communication devices were undocumented, and asset owners did not even know they were there. The devices were found by a US-based team of experts whose job was to strip these assets down and identify their components. According to the Reuters article referenced in the above link, the “rogue components provide additional, undocumented communication channels that could allow firewalls to be circumvented remotely, with potentially catastrophic consequences.”
What is Provenance in Cybersecurity?
In the world of cybersecurity, provenance is more than just the source of origin. According to NIST, provenance is “The chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include personnel and processes used to interact with or make modifications to the system, component, or associated data.” So, it’s more than just where the product came from, it includes all the associated data about what the asset or “component” contains from both a hardware and software standpoint.
Large Power Transformers In a Storage Yard: Source: IEEE SpectrumSBOMs: What’s in Your Software?
The concept of software bills of materials (SBOM) has emerged as an important element of cybersecurity. In simple terms it contains the details and supply chain relationships of various components used in building software. Those who produce, purchase, and operate software use it to improve their understanding of what components are in the systems. This in turn has multiple benefits, most notably the potential to track known and newly emerged vulnerabilities and risks. This concept applies to all systems, including those used for manufacturing operations and control.
SBOMs are becoming increasingly mandated in new regulations across a wide range of industries. Thee White House’s 2021 Executive Order on Improving the Nation’s Cybersecurity mandated that federal agencies receive SBOMs for software they purchase. The EU’s Cyber Resilience Act (CRA) requires manufacturers of digital products sold in the EU to produce a top-level SBOM.
HBOMs: What’s in Your Hardware?
Unfortunately, SBOMs don’t do much to identify the various hardware components in an asset or system and where they come from. For that, you need an HBOM or hardware bill of materials, which should provide a detailed inventory of the hardware components included in an asset or system. CISA has its own Hardware Bill of Materials Framework for Supply Chain risk Management that you can review here and download.
HBOMs are relevant to any hardware asset, from a DCS controller or a field device like a pressure transmitter all the way up to large transformers. The larger and more complex the asset is, the more important it is to have a complete HBOM and SBOM. Take the example of large power transformers (LPTs), which again are largely sourced from China, are often custom built, and contain many hardware and software components. Many times, we don’t even know what’s in these large assets until we completely tear them down. A Chinese power transformer was sent to Sandia National Laboratory (SNL) for inspection in 2020, but even those results are classified.
End Users Need to Take Supply Chain Cybersecurity Seriously
SBOMs and HBOMs are all part of the larger issue of supply chain cybersecurity. Compiling an accurate inventory of installed systems has long been considered as one of the first steps in a cybersecurity program. Simply identifying such assets is no longer sufficient. Potential supply chain related risks can only be addressed if the provenance of all components in those assets is known. When assessing or procuring software systems or hardware it is very important to ask the supplier to list the components in the product. This may take the form of a software or hardware bill of material, but such a formal presentation may not be necessary. If the supplier is unwilling or unable to provide this information, then this should be considered when making buying choices.
Other aspects of supply chain cybersecurity include evaluating the cybersecurity posture of your software and service partners. The importance of this was shown in the SolarWinds attack. End users are increasingly reliant on their technology and service partners to keep things running, but if your partners have poor cyber resilience, it can and will directly affect your operations at some point.
The US National Institute of Standards and Technology (NIST) provides guidance for supply chain cybersecurity in the form of a special publication titled “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.” This document describes how to identify, assess, and respond to cybersecurity risks throughout the supply chain at all levels of an organization. It offers key practices for organizations to adopt as they develop their capability to manage cybersecurity risks within and across their supply chains.
The post The Critical Role of Provenance in Cybersecurity and Supply Chains appeared first on Logistics Viewpoints.
You may like
Non classé
The End of the Transportation-Warehouse Divide
Published
1 jour agoon
7 septembre 2026By
A truck arriving early sounds like a transportation success. It may be the opposite if the receiving dock is occupied, the yard is full, the required labor is not scheduled, or the inventory cannot be processed when it arrives. The same problem works in reverse. A warehouse can hit its internal productivity targets and release an outbound wave exactly on schedule, only to discover that trailers, drivers, or carrier capacity are not aligned with the plan. That dependency is exactly why Stop Managing Logistics as a Collection of Functions argued that local functional optimization can degrade the performance of the total logistics system.
These are not edge cases. They reveal a structural problem in logistics: transportation and warehousing are often managed as separate functions even though the physical flow of goods does not recognize the organizational boundary.
Local Optimization Can Create System-Level Waste
Transportation teams are typically measured against transportation outcomes: freight cost, tender acceptance, on-time performance, utilization, and service. Warehouse teams focus on throughput, labor productivity, order accuracy, dock performance, and storage utilization. Each set of metrics is rational. The problem arises when improving one metric shifts cost or delay into the other function.
A carrier appointment optimized for route efficiency can create dock congestion. A warehouse schedule optimized for labor can increase carrier dwell. A decision to consolidate freight may reduce transportation cost while creating inventory or fulfillment consequences downstream. The result is a familiar logistics paradox: every function can report reasonable performance while the end-to-end operation remains inefficient. The loading dock is one of the clearest examples of why the divide is becoming untenable.
A dock door is warehouse capacity, transportation capacity, labor capacity, and time capacity simultaneously. If an inbound trailer arrives outside its expected window, the effect can propagate through receiving, putaway, inventory availability, labor assignments, outbound fulfillment, and subsequent appointments. That makes dock scheduling more than a calendar problem. It is a coordination problem across transportation arrival predictions, yard state, warehouse workload, labor availability, and order priorities. The more volatile the network becomes, the less effective static appointment assumptions become.
The Yard Is Not a Parking Lot
The yard is often treated as the space between transportation and the warehouse. Operationally, it is the interface between them. Trailers waiting in the yard represent inventory, capacity, equipment, and time. Poor visibility into yard state can cause unnecessary moves, lost trailers, excess dwell, dock starvation, and labor inefficiency. Better yard execution can therefore improve both warehouse and transportation performance.
This is why yard management is becoming strategically more important in highly automated facilities. A warehouse capable of moving goods rapidly inside the building still depends on a reliable flow of trailers to and from the doors. Automation can make poor coordination at the boundary more visible, not less important.
Warehouse plans are built on assumptions about what will arrive and when. Transportation volatility continuously challenges those assumptions. If a critical inbound shipment is delayed, the warehouse may need to change receiving priorities, labor assignments, replenishment, or outbound sequencing. If the delay is known early enough, the response can be deliberate. If it becomes visible only when the expected trailer fails to appear, the operation moves into firefighting mode.
This is where transportation visibility becomes warehouse intelligence. Outbound fulfillment is equally connected. Warehouse release schedules, order cutoffs, staging space, trailer availability, carrier pickups, and delivery commitments form one operating chain. Optimizing the warehouse without considering downstream transportation can create staged inventory with nowhere to go. Optimizing transportation without considering warehouse readiness can create trucks waiting for freight.
The economic cost appears in detention, labor, overtime, missed service, congestion, and poor asset utilization. The organizational cause is often a decision that made sense inside one functional boundary.
Shared State Matters More Than Shared Dashboards
Companies have tried to solve this problem with meetings, control towers, shared dashboards, and cross- functional teams. Those mechanisms help, but they do not eliminate the underlying timing problem. Modern logistics decisions increasingly happen too quickly for coordination to depend entirely on humans reconciling separate systems.
Transportation and warehouse applications need access to a sufficiently consistent operating state: expected arrivals, dock availability, yard position, workload, order priority, trailer status, labor constraints, and exceptions. The objective is not to create one giant database. It is to make the information required for a decision available when that decision must be made. Integration will remain superficial if incentives stay siloed.
A network that measures transportation solely on freight cost and the warehouse solely on labor productivity may systematically reward decisions that damage total logistics performance. More useful measures connect the functions: end-to-end dwell, order cycle time, dock-to-stock time, trailer turn time, service recovery, total exception cost, and the time required to resolve cross-domain problems.
The goal is not to eliminate functional accountability. It is to make system performance visible alongside local performance.
From Handoffs to Orchestration
The transportation/warehouse divide will not disappear organizationally. Nor should it. The disciplines require different expertise. What is disappearing is the luxury of slow handoffs between them.
The future model is one in which transportation and warehouse systems remain specialized but exchange events, constraints, and decisions continuously. A changed ETA can trigger a dock reassessment. A warehouse delay can change a pickup sequence. A yard constraint can alter both. That is orchestration: not collapsing functions into one system, but coordinating their decisions around a shared physical reality.
Once logistics starts operating this way, another question becomes unavoidable. If TMS, WMS, YMS, OMS, visibility, and automation systems all remain in place, what coordinates decisions across them? That is where the emerging logistics control layer enters the architecture.
Related Logistics Viewpoints research
The New Architecture of Logistics
Systems Engineering in Logistics
2026 Warehouse Management Systems Market Map
DHL and the Reality of End-to-End Logistics Integration
Previous in this series: Logistics Is Becoming an Operating System
Request The New Architecture of Logistics Client Edition
If your organization is assessing connected execution, orchestration, AI, observability, decision velocity, or selective autonomy, I would be glad to provide the complete client edition and discuss the implications for your logistics operating model and technology architecture.
The post The End of the Transportation-Warehouse Divide appeared first on Logistics Viewpoints.
Non classé
Predictive Fleet Safety: Protecting Drivers and the Bottom Line
Published
5 jours agoon
3 septembre 2026By
Every fleet manager would agree that the primary goal of their fleet safety strategy is the prevention of motor vehicle crashes to protect drivers and the public from injury or death. But increasingly, fleet safety is tied directly to a company’s bottom-line health through compliance, legal, and insurance considerations.
Transportation companies that neglect to champion a proactive fleet safety culture not only put their drivers and vehicles at risk, but they leave themselves open to profit-crushing fines, legal fees, nuclear verdicts, and escalating insurance premiums.
Profit margins under siege
Without a robust fleet safety model, transportation companies risk violating Federal Motor Carrier Safety Administration (FMCSA) regulations, such as Hours of Service (HOS), vehicle technology standards, and rules regarding inspection, maintenance, and repair. These types of FMCSA violations can trigger costly operational disruptions and hefty fines.
In addition to non-compliance penalties, fleets must deal with the bottom-line impact of truck crashes. The FMCSA estimates that fatal large truck crashes cost $13.8 million per crash, with non-fatal crashes costing more than $400,000 per incident.
Motor vehicle accidents create a cost-amplifying ripple effect across the organization, driving costs up through reduced productivity, vehicle repairs, and the need to recruit temporary or new drivers. Plus, the blow to a company’s reputation can compromise new client acquisition and driver retention and recruitment.
The crippling impact of nuclear verdicts
The costliest ramifications of inadequate driver safety programs and increased crash rates stem from legal fees, jury awards, and expensive insurance premiums. A 2025 study of nuclear verdicts—awards greater than $100 million—found that the trucking and automotive industries are among the top targets of nuclear verdicts, mainly in wrongful death and negligence cases. These sectors faced 15 multimillion-dollar verdicts in 2024, totaling more $1.4 billion.
Similarly, an ATRI 2025 report concluded that while the number of awards in trucking litigation are increasing in general, the upper 50% of awards are increasing at a particularly alarming rate. Notably, from 2012 to 2020, the number of cases with verdicts over $1 million increased by 235% compared to the six years prior, with the average size of a crash-related verdict increasing by a staggering 967% between 2010 and 2018—and this upward trend shows no sign of abating.
Insurance premiums pounding profits
While nuclear verdicts can damage a transportation company’s financial health beyond recovery, the fallout extends to insurance premiums. Escalating claim severity, rising 93.5% between 2015 and 2024, is driving insurance premiums to new heights.
Recent ATRI research shows that liability insurance premium costs rose by 18.6% from 2021 to 2024, outpacing consumer inflation by 5.4 percentage points even while heavy-duty truck crash rates fell by 2.6% industry-wide.
Mitigating risk with predictive fleet safety
Facing the costly prospect of nuclear verdicts and climbing insurance rates, many transportation companies are re-evaluating their fleet safety strategies, with a focus on protecting both drivers and the bottom line through a more proactive, predictive approach.
On the legal front, plaintiff attorneys are increasingly evaluating whether a fleet can show a pattern of proactive risk identification, coaching, and intervention before an incident occurs. Similarly, juries are influenced by whether fleets can prove they took reasonable, documented steps to prevent foreseeable risk.
Consequently, it’s no surprise that fleets operating with reactive or inconsistent driver safety practices face significantly higher exposure. Preventing nuclear verdicts is no longer solely a legal strategy; it’s a safety strategy, and one that requires a proactive approach to risk mitigation.
Insurance premiums are influenced by similar considerations. Moving forward, the affordability and availability of insurance will be determined by data transparency and the ability to use data in insurance costing. Indeed, insurers are beginning to reward fleets that can show measurable reductions in risky driving behavior using predictive safety models.
Protecting the bottom line with data
In today’s transportation landscape, forward-thinking fleets recognize that reactive driver safety that typically rely on lagging indicators (e.g., compliance violations, incidents, claims) and in-cab cameras and video telematics is no longer sufficient for reducing risk and curtailing costs.
Profitable fleets are thinking beyond simple scorecards, arbitrary weighting, and reactive training. They’re building a proactive safety culture underpinned by a data-driven predictive driver safety program that integrates data from a wide range of sources: cameras, telematics, electronic logging devices (ELDs), FMCSA, customer feedback, training, dispatch, HR systems, and accidents and claims.
Using predictive analytics and machine learning to analyze billions of miles of driving data and hundreds of thousands of historical crashes across the industry, AI-enabled fleet safety programs can identify elevated risk earlier, prioritize interventions, and demonstrate continuous improvement. Fleet leaders can use these safety insights to proactively manage risk, intervening with at-risk drivers to provide meaningful coaching before a crash occurs.
In this era of nuclear verdicts, eye-watering insurance premiums, and razor-thin margins, safety has become a competitive cost advantage. By shifting from reactive safety models to investment in predictive analytics, driver development, and documented preventive practices, fleets can better safeguard drivers from crash risk while protecting themselves from costly litigation and strengthening their insurance position to keep premiums under control.
Hayden Cardiff, VP Safety Solutions at Descartes
The post Predictive Fleet Safety: Protecting Drivers and the Bottom Line appeared first on Logistics Viewpoints.
Non classé
Stop Managing Logistics as a Collection of Functions
Published
5 jours agoon
3 septembre 2026By
Calling logistics a network is accurate, but it is not sufficient. A network describes connections; it does not explain how independently managed transportation, warehousing, fulfillment, yard and dock operations, last-mile delivery, technology, partners, and people combine to produce one customer outcome. The more useful model is a system of systems.
The practical consequence is important. You cannot understand logistics performance by looking at any one component in isolation.
Every Function Is Rational. The System Still Can Be Wrong.
A warehouse is optimized around throughput, storage, labor, service requirements, and physical constraints. A transportation operation is optimized around modes, routes, carrier capacity, cost, service, and variability. A yard operation is optimized around appointments, dwell, doors, and trailer flow. None of those perspectives is wrong. The difficulty appears when they are connected.
None of those perspectives is wrong. The difficulty appears when they are connected.
Consider a seemingly simple promise to offer later customer order cutoffs. Commercially, it may be attractive. Operationally, it can change picking waves, labor schedules, carrier tender timing, dock congestion, linehaul departure, delivery commitments, and exception management. The decision spans multiple systems, and the value appears only if those systems can absorb the change together.
A system-of-systems view forces the organization to see that dependency before the change is made.
The Network Does Not Report to You
Traditional engineering often assumes a designer has meaningful control over the system being built. Logistics networks rarely offer that luxury.
Carriers have their own network economics. 3PLs optimize their facilities and labor. Parcel providers manage sort capacity and delivery density. Ports and terminals manage gates, berths, yards, and appointments. Customers change ordering behavior. Software providers determine product road maps. Regulatory agencies change requirements. Labor markets move independently of corporate plans.
These entities participate in the same operating system without being subordinate to a single designer. That is one of the defining characteristics of a system of systems. Its components can operate independently, evolve independently, and still affect the performance of the whole.
This helps explain why seemingly small external changes can create disproportionate logistics effects. A carrier-capacity shift can alter fulfillment strategy. A missed linehaul departure can invalidate an otherwise efficient warehouse wave. A new customer cutoff can create technology and process work across order release, picking, staging, tendering, and delivery.
Logistics is not simply complicated. It is adaptive.
Complexity Raises the Price of Weak Architecture
When systems are relatively simple, coordination can rely heavily on experience and informal processes. As complexity increases, that becomes less reliable.
Architecture provides structure.
Process architecture defines how work moves across the enterprise. Data architecture defines how information is created, governed, shared, and interpreted. Decision architecture defines who or what makes decisions, what inputs are used, how quickly decisions must be made, and when escalation is required. Technology architecture provides the applications, integration, analytics, and automation that support those processes and decisions.
These architectures overlap. They should.
The mistake is to allow one of them, usually technology architecture, to become the de facto operating model. When that happens, organizations begin designing work around system capabilities instead of designing systems around business requirements. The result may be technically integrated while remaining operationally fragmented.
Treat Every Handoff as a Design Decision
In a system of systems, interfaces are not plumbing. They are part of the product.
The interface between order management and fulfillment determines whether customer promises are executable. The interface between a shipper and a carrier determines whether capacity commitments are reliable. The interface between an optimization engine and a TMS or WMS determines whether a recommendation can actually be executed. The interface between an AI agent and a human determines whether automation accelerates decisions or simply creates another queue of suggestions.
These interfaces should have explicit requirements.
What information must cross the boundary? At what frequency? With what latency? Who owns data quality? What happens when the message is incomplete? Which decisions can be automated? What happens when two systems disagree?
Organizations frequently discover these questions during implementation. Systems engineering argues that they should be part of design.
Measure the Enterprise Outcome, Not the Local Win
A system-of-systems view also changes performance measurement.
Functional metrics remain necessary, but they are insufficient. A warehouse can hit its productivity target while order cycle time gets worse. Transportation can reduce cost per shipment while dock dwell or delivery variability increases. A parcel operation can lower rate per package while missed cutoffs rise. The larger question is whether the total logistics system is improving service, cost, flow, and responsiveness together.
The larger question is whether the total system is producing the outcomes the business requires.
That means metrics should connect across levels. Local operating measures should roll into end-to-end logistics measures such as on-time delivery, perfect-order performance, order cycle time, cost per shipment or order, dock dwell, capacity utilization, responsiveness, resilience, and decision speed. The organization needs to understand where local gains create system gains and where they simply move cost, delay, or risk somewhere else.
Change the Question, Change the Design
The system-of-systems idea may sound theoretical, but it is a useful operating model for logistics leaders. It explains why local optimization is dangerous, why interfaces matter, why technology integration alone does not create end-to-end performance, and why transformation requires architecture across organizational boundaries.
The practical shift is straightforward: stop asking whether each function is performing well in isolation and ask whether the combined system is producing the outcome the enterprise needs. In 1.3, that system view becomes operational: we move from understanding the whole to defining what the whole must actually do before technology enters the discussion.
Related Logistics Viewpoints research
Systems Engineering in Logistics
The New Architecture of Logistics
2026 Supply Chain Decision Intelligence Market Map
Guest Commentary: Control Tower 2.0 – Managing Logistics Costs in a Risky and Volatile World
Previous in this series: Why Logistics Needs Systems Engineering
Request the Systems Engineering in Logistics Client Edition
If your organization is evaluating a logistics transformation, technology strategy, automation program, or operating-model redesign, I would be glad to provide the complete client edition and discuss how the framework applies to your priorities, constraints, and operating environment.
The post Stop Managing Logistics as a Collection of Functions appeared first on Logistics Viewpoints.
The End of the Transportation-Warehouse Divide
Predictive Fleet Safety: Protecting Drivers and the Bottom Line
Stop Managing Logistics as a Collection of Functions
Freightos Global Freight Outlook – September 2026
Container rates jump another $1k/FEU – but is demand peaking? – July 8, 2026 Update
Walmart and the New Supply Chain Reality: AI, Automation, and Resilience
Trending
- Non classé7 jours ago
Freightos Global Freight Outlook – September 2026
- Non classé2 mois ago
Container rates jump another $1k/FEU – but is demand peaking? – July 8, 2026 Update
-
Non classé1 an agoWalmart and the New Supply Chain Reality: AI, Automation, and Resilience
-
Non classé5 mois agoWhy Sulfuric Acid Is Emerging as a Supply Chain Constraint in Copper
- Non classé3 mois ago
Container rates starting to spike on peak season rush – June 2, 2026 Update
- Non classé1 an ago
13 Books Logistics And Supply Chain Experts Need To Read
- Non classé11 mois ago
Ex-Asia ocean rates climb on GRIs, despite slowing demand – October 22, 2025 Update
- Non classé2 mois ago
LCL Shipping Cost Calculator: Calculate Air and Sea Shipping Freight Rates
