Abstract
Increasing interconnections between critical infrastructure operators and their (sub)suppliers make digital supply chains/trees (DSCs) crucial for cyber resilience. Compromised suppliers may introduce security compromise propagation and cascading effects that impact critical grid functions. While regulations emphasize supplier verification, optimal allocation of limited verification resources remains an open challenge. To address this challenge, we first investigate DSC cybersecurity challenges in the Norwegian power sector through expert interviews. Insights from the interviews inform a network-based abstraction of DSC security, in which supplier verification is modeled as a resource-constrained allocation problem. Building on this abstraction, we develop an empirically informed Discrete Event Simulation (DES) model incorporating cyberattacks, compromise propagation, and detection mechanisms. Simulation results demonstrate that the allocation of verification effort substantially influences compromise propagation and the resilience of the supply chain.