BMW-targeted concept demonstration. Operational entities, suppliers, parts, inventory, production, financial values and incident conditions are synthetic and do not represent BMW systems, performance or current exposure.
Containment tradeoff
Each option is a cyber decision with a production consequence. Nothing here is free.
| Option | Cyber exposure | Production effect | Implement | Authority | Reversible | Deadline | |
|---|---|---|---|---|---|---|---|
Maintain connection Keeps an active data path to an environment with an unresolved ransomware incident. Lateral movement and poisoned master data both remain possible. | Higher | No immediate interruption. Order and shipment confirmation continue. | 0h | Cyber + Operations | Immediate | Immediate review | |
Restrict connection Inbound supplier traffic is allowed for a narrow message set only, with all writes to master data blocked. | Moderate | Manual confirmation required for every shipment. Adds roughly 2 hours of clerical work per shift. | 2h | Cyber + Operations | Immediate | Two hours | |
Isolate connection Recommended Terminates the supplier EDI and ERP connection. Removes the exposure path completely while the supplier incident is unresolved. | Lower | Shipment and order confirmation for 27A-1000 is interrupted. Inbound material must be confirmed physically at the gate. | 1h | Cyber + Operations | Hours | Now | |
Disable supplier credentials Recommended Revokes supplier user and service accounts in the manufacturer identity provider. | Lower | Supplier planners lose portal access. Release schedules must be sent manually. | 0.5h | Cyber | Immediate | Now | |
Suspend EDI transaction processing Recommended Stops automated ingestion of supplier EDI messages into ERP. | Lower | Inventory advices and shipment notices stop updating. Records go stale within one shift. | 1h | Cyber + Operations + Supply chain | Hours | Now | |
Shift to manual processing No network change. Reduces reliance on supplier data rather than removing exposure. | Moderate | Receiving, confirmation and reconciliation are performed by hand. The procedure has not been tested at this volume. | 4h | Operations + Supply chain + Quality | Hours | Four hours |
Maintain connection
Rejected: continuing to accept data from a compromised environment would contaminate the inventory and schedule records this decision depends on.
- · Documented executive risk acceptance
Restrict connection
Credible fallback if isolation cannot be staffed. Leaves residual exposure because the supplier network still reaches manufacturer systems.
- · Firewall rule change record
- · Manual confirmation procedure named and staffed
Isolate connection
Recommended: it is the only option that removes the exposure path, and its production consequence is addressable by the transfer decision below.
- · Isolation confirmation from network operations
- · Gate-side receiving procedure activated
Disable supplier credentials
Recommended alongside isolation. Low production cost, removes an independent access path.
- · Identity provider revocation log
Suspend EDI transaction processing
Recommended: this is what keeps compromised quantities out of the calculation. It is also what makes the data-trust question unavoidable.
- · EDI queue suspension record
- · Last clean message identified
Shift to manual processing
Required to make isolation survivable, but untested at this volume. Treated as a precondition, not a containment substitute.
- · Manual procedure document
- · Staffing confirmation
- · Volume test result
Selecting containment does not resolve production. Suspending EDI is what keeps compromised quantities out of the calculation, and it is also what removes the confirmation path the plant relies on. The production consequence is handled on the decision-window screen.