Supply Chain Management: Dhaval Desai Of Microsoft Corporation On How To Ensure Product Security in Collaboration with External Vendors and Partners

Supply Chain Management: Dhaval Desai Of Microsoft Corporation On How To Ensure Product Security in Collaboration with External Vendors and Partners

Vendor Assessments — Before entering into a collaboration, thoroughly assess the security practices of potential vendors. This includes evaluating their data protection measures, physical security protocols, cybersecurity policies, adherence to industry standards and incident response plans. Utilize questionnaires, audits, and site visits to ensure a comprehensive understanding of their security posture. Implement a secure supply chain management process to ensure the integrity of the products.


In an increasingly interconnected world, maintaining the security of products while working with external partners and vendors presents a crucial challenge. How do product security managers ensure this vital aspect of supply chain management? What best practices, technologies, and strategies do they employ to guarantee the safety of products throughout their lifecycle, especially when these goods may pass through multiple external entities? As a part of this series, we had the pleasure of interviewing Dhaval Desai.

Dhaval Desai is Group Engineering Manager (Senior Director) at Microsoft and is responsible for SAP applications that power internal supply chains. He has 15+ years of progressive experience in design, development, and adoption of Supply Chain solutions across industries and organizations. He has successfully led some of the biggest transformations at organizations with innovative solutions, deep expertise, customer focus and leadership. He is a published author, patent recipient, APICS certified and a regular speaker at Supply Chain events.

Thank you so much for joining us in this interview series! Before we dig in, our readers would like to get to know you. Can you tell us a bit about how you grew up?

I grew up in a town in Western India. My parents highly encouraged me and my sister to focus on studies; they inspired us by sharing successful stories of individuals who achieve great things in life by creating a strong foundation through academic excellence. In those days, my dad ran a factory which manufactured cotton-based garments e.g., Sarees, Salwar Kameez, Kanga, and Kitenge. This gave me more exposure to supply functions at an early age and I found it fascinating how people, processes and tools come together to manufacture a product in one region and is consumed in other regions of the world.

Is there a particular story that inspired you to pursue a career in this field? We’d love to hear it.

My professional introduction to supply chain was my chance! When I joined Verizon, I was offered a role within the supply chain transformation team. During that time, Verizon was investing heavily in laying the fiber optic network throughout the United States, and Supply Chain was key to its success. When I started working on supply chain projects leveraging process-centric solutions from SAP, many of the supply chain aspects that I had an opportunity to observe as a child were relevant and were being adopted in my professional life, too! This helped me to have a deeper connection with my profession. I started enjoying what I was learning & doing, and this spiked further interest. From then on, the more I got engaged, the more I learned! My interests and curiosity kept fueling my desire and passion to develop a niche in the supply chain.

Are you working on any exciting new projects now? How do you think that will help people?

Generative AI is a significant opportunity and has the potential to revolutionize the way businesses plan, manage, and optimize their supply chains. At Microsoft, we are working on AI-assistants that optimize key supply chain functions like product design, planning, forecasting, and repairs. These AI-assistants offer natural language interfaces and data analysis that can enhance visibility, sustainability, productivity, and collaboration.

Ok, thank you. Let’s now move on to our main topic. Can you share a few reasons why it is so critical to ensure product security in collaboration with external vendors, in today’s environment?

Ensuring product security in collaboration with external vendors is critical in today’s environment to protect sensitive data, mitigate cybersecurity risks, maintain operational continuity, safeguard intellectual property, comply with regulations and build trust with customers and partners.

  • Supply Chain Risks and Continuity — Today, many organizations rely on a complex network of external vendors in its supply chain. These vendors not only perform edge functions but are deeply integrated in its supply chain functions and operations, from design to deliver to operate. If a vendor or its product is compromised, it can impact the entire supply chain. Security incidents can disrupt businesses processes and lead to costly downtimes. Ensuring product security with external vendors helps mitigate these supply chain risks and protects your organization from disruptions and potential breaches.
  • Data Privacy and Compliance — With the increasing number of data privacy regulations and legislations such as GDPR, CCPA and UFLPA, organizations are legally obligated to protect their customers’ data and report end-to-end traceability of the products that it manages. When you collaborate with external vendors, they may have access to sensitive customer information or deal with restricted entities. If they fail to secure it properly or don’t comply with legislations, organization could face significant legal and financial consequences.
  • Trust and Reputation — Security breaches and data leaks can have a significant impact on an organization’s reputation and erode customer trust. Data leaks can also lead to legal implications which can prove fatal as it hampers organizations ability to further sell its products and services.
  • Cost — Fixing security issues after a product has been deployed can be costly and time-consuming.
  • Competitive Advantage — Organizations that can demonstrate a strong commitment to security can use it as a competitive advantage. Customers and partners are more likely to choose vendors and collaborators who prioritize security.

How do emerging technologies like AI and machine learning augment the collaborative efforts between organizations and external vendors in securing the supply chain, and could you share a case where leveraging technology markedly enhanced product security?

Emerging technologies like AI and machine learning could play a significant role in augmenting collaborative efforts between organizations and external vendors to secure the supply chain. These technologies provide advanced capabilities for threat detection, anomaly identification, predictive analysis, and automated vulnerability assessment thus enhancing the overall security posture.

A manufacturer leveraged machine learning to analyze historical data related to its supply chain. The model identified patterns that indicated a higher risk of delays and disruptions during specific seasons from suppliers in a given region. By anticipating these risks, the company adjusted its inventory management and collaborated with vendors to ensure alternative sourcing, minimizing the impact on production schedules.

How do you identify and mitigate risks to product security when working with external vendors and partners in the supply chain, and could you share an instance where a proactive approach averted a significant security breach?

Processes and systems that enable continuous monitoring and telemetry can help you provide insights for the product’s lifecycle that is managed by external vendors and partners. These insights can be leveraged to enable threat detection and alert mechanism to ensure security breaches are identified early on in a proactive manner and thus mitigate them before the damage occurs.

A manufacturer inadvertently missed to apply a critical security patch that was released 2 weeks ago on a smart device. Organization had a process in place to collect the telemetry data from the product testing tools. Based on these insights, the organization was to swiftly identify the security patch was missing and quickly notify its partner. The partner acknowledged the missed and security patch was applied before it was shipped to its consumers. This averted a significant security breach for the organization.

What are some strategies and frameworks you employ in third-party vendor management to uphold product security, possibly highlighting a partnership that stands as a benchmark in industry practices?

Effective third-party vendor management is crucial for upholding product security and mitigating risks associated with external collaborations. Comprehensive vendor risk assessment, clear security requirements in contracts, ongoing monitoring, telemetry and audits, regulatory compliance and certification, secure manufacturing and testing practices, regular training, and awareness, etc. are the key strategies that are employed in the supply chain industry to upload product security.

As Industry 4.0 and smart factories gain traction, how are strategies and approaches evolving to foster product security within the supply chain?

Strategies and approaches to foster product security within the supply chain are evolving to adapt to the challenges and opportunities presented by Industry 4.0 and smart factories. With the integration of shop floor systems in smart factories to the enterprise stack which are increasingly hosted in Cloud environments, operational systems are at risk of cyberthreats. Strategies now focus on securing the convergence of IT and shop floor environments to prevent disruptions and ensure the integrity of both digital and physical processes. Organizations are implementing comprehensive security measures that include network segmentation, secure communication protocols, and robust access controls to protect against cyber threats that can impact physical processes. As data is exchanged between connected devices and systems in smart factories, there is an increased emphasis on end-to-end encryption and secure communication channels to protect sensitive information from interception or tampering. Secure communication protocols such as TLS (Transport Layer Security) and MQTT (Message Queuing Telemetry Transport) can safeguard data exchanged between devices and systems. These approaches emphasize the integration of cybersecurity measures into the fabric of connected systems, collaborative efforts, and proactive measures to ensure the security and resilience of products throughout their lifecycle.

What are your “5 Best Practices for Ensuring Product Security in Collaboration with External Vendors and Partners”?

1. Vendor Assessments — Before entering into a collaboration, thoroughly assess the security practices of potential vendors. This includes evaluating their data protection measures, physical security protocols, cybersecurity policies, adherence to industry standards and incident response plans. Utilize questionnaires, audits, and site visits to ensure a comprehensive understanding of their security posture. Implement a secure supply chain management process to ensure the integrity of the products.

A technology company producing smartwatches collaborated with a semiconductor manufacturer. Before finalizing the collaboration, the company conducted thorough assessments of the semiconductor vendor’s facilities, ensuring that they followed secure manufacturing processes, supply chain security, had robust access controls, and implemented secure procedures for sensitive components. They review the vendor’s track record in producing secure hardware components for similar applications and ensure compliance with industry standards.

2. Establish Clear Security requirements in vendor contracts — Clearly define security requirements in contracts and service level agreements (SLAs) with external vendors. Specify expectations for data encryption, access controls, regular security audits, and incident reporting. Establish consequences for non-compliance to incentivize vendors to prioritize security. Provide security awareness training to personnel from external vendors who will have access to your systems or data. This training should cover the best practices, potential security threats, and the importance of maintaining a secure environment. Regularly update vendors on emerging security trends and threats.

In the contractual agreement with the external vendor, the home automation company explicitly outlines security requirements for the smart door lock components. This includes specifications for secure firmware development, encryption protocols for communication between the lock and the mobile app, and guidelines for securely storing user authentication data. The contract includes clauses that mandate immediate notification of any security incidents and stipulates penalties for non-compliance.

3. Embed security in Product Design — Integrate security features directly into the hardware design to protect against physical and cyber threats. This includes hardware-based encryption, secure boot processes, and tamper-resistant components. Collaborate closely with hardware design partners to ensure that security is considered from the early stages of product development.

A company developing IoT-enabled home security cameras worked closely with a hardware design partner to embed security features in the camera’s chipsets. This included hardware-based encryption for stored footage and secure authentication processes, reducing the risk of unauthorized access to the device. In an outsourced manufacturing model like this, the company may also provide, and control factory infrastructure related to product testing to ensure that the security aspects are available in each product before it’s shipped to the consumers.

4. Monitoring, Telemetry, and Incident Response Planning — Implement continuous monitoring of vendor activities, collect telemetry of vendor operations/activities, and establish a robust incident response plan. Regularly review logs, conduct security audits, and monitor any unusual or suspicious behavior. Develop a coordinated incident response strategy to quickly address and mitigate security incidents.

The smart watch manufacturer implements continuous monitoring of the production line to detect any anomalies or deviations from the established security standards. They also develop a comprehensive incident response plan that outlines the steps to be taken in the event of a security incident, including communication protocols, containment measures, and post-incident analysis. This proactive approach helps minimize the impact of potential security breaches.

5. Regular Security Audits and Penetration Testing — Conduct regular security audits and penetration testing on the products and services provided by external vendors. Identify and address vulnerabilities before they can be exploited. Ensure that vendors have mechanisms in place to address and remediate identified security issues promptly.

Periodic security audits and penetration tests are conducted on the smart door lock components to identify and address potential vulnerabilities. The manufacturer engages third-party security experts to perform thorough assessments of the device’s firmware, hardware, systems, and communication protocols. Any identified vulnerabilities are addressed promptly through firmware updates or modifications to the manufacturing process, ensuring that the smart door lock maintains a high level of security.

You are a person of enormous influence. If you could inspire a movement that would bring the most amount of good to the most amount of people, what would that be? You never know what your idea can trigger. :-)

Zero Trust Security Model should be adopted by organizations to ensure robust product security in supply chain. This model assumes that no entity, whether inside or outside the network, should be trusted by default.

How can our readers further follow your work online?

LinkedIn is my preferred way to communicate and learn from the industry peers. You can follow me at https://www.linkedin.com/in/dhaval-desai-119a9a33/.

This was very inspiring and informative. Thank you so much for the time you spent on this interview!

About The Interviewer: David Leichner is a veteran of the Israeli high-tech industry with significant experience in the areas of cyber and security, enterprise software and communications. At Cybellum, a leading provider of Product Security Lifecycle Management, David is responsible for creating and executing the marketing strategy and managing the global marketing team that forms the foundation for Cybellum’s product and market penetration. Prior to Cybellum, David was CMO at SQream and VP Sales and Marketing at endpoint protection vendor, Cynet. David is a member of the Board of Trustees of the Jerusalem Technology College. He holds a BA in Information Systems Management and an MBA in International Business from the City University of New York.

TechVIP InterviewsMicrosoft
DL
Written by

David Leichner

Editor & Journalist · Authority Magazine

Editor and journalist at Authority Magazine, sharing in-depth executive interviews, leadership insights, and empowering stories from world-class founders and creators.

Authority Magazine
Published inAuthority MagazineTop Lessons, Top Authorities · 42K Followers

Exclusive, curated interviews with the leaders and changemakers shaping tomorrow. Leadership lessons, industry deep dives, and executive profiles.