Digital Service Chains: Evolving Beyond the Software Supply Chain

0
1

Key Takeaways

  • Service chains mirror software supply chains but operate in the live, multi‑owner environment of today’s digital services, creating complex, often hidden supplier‑consumer relationships.
  • Interconnectedness expands attack surface: cloud, edge, storage, networks, datasets, and remote functions are woven together, enabling lateral movement across providers.
  • Cybersecurity processes have not kept pace with the speed and dynamism of service chains; information sharing remains slow, reactive, and fragmented.
  • Empirical data show that 97 % of organisations suffer at least one supply‑chain breach, and the trend is expected to worsen with 5G/6G verticals, IoT, and massive connectivity.
  • The MIRANDA project introduces a Cybersecurity Digital Twin (CDT) – a live, federated model that continuously mirrors the security state of interconnected systems and can predict attack evolution.
  • By feeding the CDT with real‑world security events and threat intelligence, providers can collaboratively improve detection, analysis, protection, and response capabilities.
  • Technology alone is insufficient; the current NIS2‑based regulatory regime is largely static, reactive, and fragmented, limiting the adoption of proactive, cooperative defenses.
  • A forthcoming NIS3‑style framework should encourage dynamic, adaptive, and autonomous collaborative models, supported by confidentiality‑ and privacy‑aware CDTs.
  • Legal evolution that incentivises investment and clarifies responsibilities is essential to close the normative gap and realise the full security potential of interconnected digital services.

Introduction to Service Chains and Interconnected Digital Services
Service chains are the operational counterpart of software supply chains. While a supply chain follows code from development through build and deployment, a service chain describes how live digital services—computing infrastructure, storage, networking, data feeds, and remote functions—are stitched together to deliver an application. In today’s hyper‑connected world, these chains span multiple owners, creating a web of recursive, often invisible supplier‑consumer links that together form Digital Service Chains (DSCs).

What is Interconnectedness?
Interconnectedness arises when an application leans on external services supplied by third parties. Typical building blocks include public‑cloud or edge compute, block/object storage, wired/Wi‑Fi/cellular/long‑range networks, sensor‑derived datasets, timetables, georeferenced maps, and remote procedure calls such as AWS Lambda functions. Each of these components introduces its own security posture, and the act of chaining them together produces a DSC that can stretch across clouds, telcos, IoT platforms, and specialised verticals like smart cities or autonomous vehicles.

Why Security Lags Behind
The rapid adoption of software‑defined infrastructures lets organisations spin up, scale, or redeploy DSCs in minutes. Unfortunately, cybersecurity operations have not achieved comparable agility. Information exchange between disparate security teams remains a slow, manual process—often limited to periodic incident reports or threat‑intelligence feeds that only surface after an attack has already propagated. This lag leaves defenders reacting to symptoms rather than anticipating the underlying kill chain.

Supply‑Chain‑Style Threats Are Real
Empirical surveys confirm the severity of the problem: roughly 97 % of organisations report at least one breach originating in their supply chain. As DSCs grow denser—fuelled by high‑bandwidth links, massive IoT deployments, virtualisation, and multi‑tenancy—the opportunity for lateral movement between Digital Service Providers (DSPs) expands. Even when a chain currently involves only a handful of providers (e.g., a cloud vendor plus a sensor network), the underlying factors that enable rapid scaling also make the chain a fertile ground for sophisticated, AI‑powered attacks.

The Core Problem: Fragmented Visibility
Many organisations outsource security to their suppliers, trusting that the provider’s controls cover the entire chain. This reliance creates blind spots: vulnerabilities that sit at the interface of two domains are often invisible to either party, and no single actor has a holistic view of the evolving risk landscape. Consequently, the collective defence capability is merely the sum of isolated parts, far short of what a coordinated, real‑time response could achieve.

MIRANDA’s Vision: Cybersecurity Digital Twin
To bridge this visibility gap, the MIRANDA project proposes a Cybersecurity Digital Twin (CDT). A CDT is a live, continuously updated model that captures the security properties—configuration, topology, vulnerabilities, and defensive controls—of an interconnected ICT system. Unlike a static diagram, the CDT evolves in lockstep with the real world, enabling security teams to run assessments, simulate attack scenarios, and test defence strategies without disrupting production services.

Structure and Function of the MIRANDA CDT
The MIRANDA CDT is not a single monolith but a federation of bidirectional models. Each model abstracts a specific facet of the DSC: service composition, network topology, asset inventory, and security posture (e.g., patch levels, misconfigurations, access controls). These models are kept synchronized through a constant feed of security events (IDS alerts, log anomalies) and known vulnerability feeds (CVE databases, vendor advisories). By running predictive analytics on this shared data—augmented with threat‑intelligence feeds—the CDT can forecast how an attack might propagate, estimate the likelihood of various kill‑chain stages, and suggest optimal mitigation steps before the threat materialises in the live environment.

From Prediction to Collaborative Response
Beyond forecasting, the MIRANDA framework turns insight into action. Existing detection, analysis, protection, and response (DAPR) processes are enhanced through collaborative playbooks that are jointly authored and executed by all participating DSPs. When the CDT predicts a probable lateral move, it triggers coordinated containment actions—such as temporary network segmentation, credential rotation, or targeted patch deployment—across the relevant providers. This collective response capacity exceeds the simple aggregation of individual defences because it leverages shared situational awareness and synchronized counter‑measures.

The Normative Gap: Why Technology Alone Isn’t Enough
While the CDT offers a powerful technical foundation, its adoption is hampered by the existing regulatory landscape. The current implementation of the EU NIS2 Directive in Member States tends to be:

  • Identification of suppliers via manual, yearly‑updated registers.
  • Narrow scope, focusing only on operators of critical or essential services.
  • Hub‑and‑spoke topology, where national authorities sit at the centre and interact separately with each operator.
  • Cyber‑incident notification and risk management obligations that are largely reactive and static.

This approach worked when threats were slower and less interconnected, but it falls short against today’s AI‑driven, fast‑moving campaigns that exploit the very dynamics NIS2 ignores.

Towards a NIS3‑Style Future
To close the normative gap, a forthcoming NIS3 (or equivalent) framework must shift from reactive compliance to proactive, dynamic, adaptive, and autonomous collaboration. Key elements include:

  • Mandating real‑time sharing of sanitized security telemetry via trusted conduits (e.g., CDT feeds).
  • Requiring operators of digital service chains to maintain and continuously validate a Cybersecurity Digital Twin.
  • Encouraging the use of privacy‑preserving techniques (homomorphic encryption, secure multi‑party computation) so that CDTs can be shared without exposing confidential business data.
  • Providing clear liability models and incentives—such as reduced premiums or tax credits—for organisations that invest in collaborative CDT‑based defences.
  • Establishing sector‑specific information‑sharing organisations that operate under a common governance model, moving away from the hub‑and‑spoke silo toward a mesh of trusted peers.

By aligning legal expectations with the technical capabilities of the MIRANDA CDT, regulators can create an environment where interconnected digital services are not only innovative but also resilient against the next generation of cyber threats.


In summary, the MIRANDA project recognises that the security of modern digital service chains cannot be ensured by isolated, reactive measures. Its Cybersecurity Digital Twin offers a living, predictive view of risk and a platform for coordinated defence. However, without a supportive, forward‑looking regulatory framework—akin to a prospective NIS3—such technology will struggle to achieve widespread adoption. Bridging the normative gap is therefore as crucial as the technical innovation itself.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here