Skip to main content

CSCOs seize the agenda: tariff recovery and cyber risk while seeking resilience

Voice of the CSCO | Insight Series

Confronted by relentless trade volatility and escalating third-party cyberattacks, chief supply chain officers are moving beyond defense. They’re forging high-impact alliances, hardening supply chain networks, and redefining the ROI of resilience.

Chief Supply Chain Officers (CSCOs) are steering their organizations through a business landscape defined by perpetual volatility. The era of predictable trade and isolated disruptions has given way to structural shifts that demand a fundamental rethink of supply network architecture.

Supply chain leaders are moving beyond reactive crisis management to embed long-term resilience, agility, and risk-adjusted decision-making directly into their core operating models. This analysis examines three defining priorities dominating the supply chain agenda.

First, leaders are moving from tariff recovery tactics to strategic realignment, transforming into sourcing overhauls, nearshoring initiatives, and risk-adjusted total cost models. Second, it analyzes cybersecurity and multi-tier supplier risk as the newest front line, where leaders are confronting AI-driven threats while also actively co-defending vulnerable suppliers. Finally, it addresses resilience, exploring how organizations balance costly redundancy against strategic partnerships while establishing pragmatic financial frameworks to prove the enterprise value of risk management.

On the CSCO agenda:

From tariff recovery tactics to strategic realignment

A clear strategic pivot is underway.

Global trade policy in 2026 is dynamic and often unpredictable, forcing supply chain leaders to move beyond tariff recovery efforts to fundamentally realign their sourcing and supplier strategies. This shift is creating a clear divergence in how organization are managing tariff-related costs.

A chief supply chain officer with a multinational pharmaceutical company reported 85-90 percent success with tariff recovery. The key is the company’s standard customs and duty drawback findings. They’re approved and reimbursed without any pushback.

To create clarity, a utility company CSCO documents tariff reimbursement as separate line items in their POs upfront, which make negotiations much cleaner.

Other companies are encountering blockers with their tariff recovery efforts. Tactics vary, from manual invoice-scraping to the more assertive demand letter approach. Success varies as well with some firms only reclaiming 10-15 percent of the passed-along costs.

As tariff recovery efforts ebb and flow, the tariff environment is driving a strategic shift in sourcing. This chameleon-like business climate is ushering in a strategic evolution in sourcing. A commercial services CSCO, for example, is pressuring its suppliers to lean in and be creative, leading some suppliers to nearshore their operations.

The CSCO of a technology company is actively multi-sourcing or transitioning critical materials completely out of China due to geopolitical risks and cost volatility. This marked a clear shift from short-term cost management to long-term structural de-risking.

For the supply chain leader of an oil company, their de-risk strategy entailed forming a strategic alliance with a key supplier.

“Instead of using multiple suppliers, we decided on one strategic alliance. Even with the market supply side of risk, it gives us a better relationship and access to capacity.”

Elevating a key vendor to a single strategic alliance unlocks transparency, enables capacity, and promotes collaborative problem-solving on issues like tariff recovery. Given higher risks and volatile cycles, an ongoing partnership also creates an open door to regular health assessments.

Supply chain leaders are also shifting away from evaluating suppliers on a piece-price variance alone. The goal is a risk-adjusted total cost of ownership that integrates duty risk, the carrying cost of buffer stock, and cyber-qualification costs rolled into a baseline supplier score.

“Supply chain leaders are realizing that trade and tariff risk isn’t just an import/export function buried in the back office. It also drives vendor selection, product design, and capital allocation.”

Andrew Siciliano, KPMG partner, SALT Trade & Customs

Cybersecurity and multi-tier risk

CSCO’s new front line

Supply chain leaders have witnessed cybersecurity escalating from a routine check-the-box compliance activity to a primary, board-level risk that dwarfs operational concerns. Suppliers have a target on their backs for cyber-criminal activity, and, by extension, CSCOs who are being drafted into cyber defense actions.

For many CSCOs, the best defense is picking the right suppliers to work with. Cybersecurity has become a hard qualifier.

“If a supplier fails our cyber security check, we will not move forward and work with them,” remarked the CSCO with an oil company.

This sentiment was echoed by another supply chain leader who integrated cyber due diligence directly into the supplier qualification process. The company categories suppliers by risk level and marks high-risk vendors for continuous monitoring.

The era of deep fakes that can clone voices, for example, makes cyber-criminal activity personal and insidious. The CSCO of a utility company highlighted the danger of third-party impersonation where the deep fake makes it difficult to determine if a supplier’s consultant is real or actually a hostile foreign actor. Another CSCO is evaluating biometric and anti-impersonation verification tools to combat these deep fakes.

Between incidents like water utilities in a handful of states targeted by coordinated cyberattacks and the latest threats from deep fakes, CSCOs are starting to see cybersecurity through a bigger lens.

CSCOs are realizing that just as they’ve upped their cyber defenses, their companies need to circle the wagons around their suppliers that are also at risk. The consensus is that suppliers shouldn’t be left to fend for themselves.

For example, the CSCO for an automotive company funds an internal supplier cybersecurity support team that performs vulnerability analyses and helps under-resourced partners upgrade their security. The proactive stance is critical in protecting the enterprise.

Some CSCOs are softening their hard qualifier rule of not working with a supplier that fails the test on cybersecurity to deliver a more helping hand. Companies are increasingly pairing assessments with clear remediation roadmaps. Instead of immediate, permanent disqualification, procurement and infosec teams work with prospective vendors to define specific milestones required to reach compliance. To illustrate, moving suppliers away from open email communications to managed, zero-trust vendor portals.

“Cyber risk is starting to dwarf traditional risks because hackers are advancing their tactics with AI.” -- Supply chain executive, logistics and services sector

Building resilience through redundancy

Does redundancy create value or unnecessary cost?

CSCOs are engaged in a complex debate over the best way to build resilience, weighing the costs of redundancy against the benefits of consolidating with fewer, more strategic partners. Either way, the one-size-fits-all approach is gone, replaced by a highly segmented, category-specific strategy.

According to the CSCO for a company that supplies building materials, the central challenge is determining when redundancy creates value vs. unnecessary cost.

For other CSCOs, dual sourcing remains a viable strategy for mitigating risk across thousands of raw materials. This is especially true if a single sourced material, if missing, would bring the assembly line to a halt at great expense. The risk outweighs the cost of redundancy.

However, dual sourcing is not a universal solution. The difficulty lies in quantifying the ROI of resilience. The CSCO for a technology company described how their procurement function aligns its contributions directly with the corporate P&L, which provides a clearer financial narrative. Resilience-driving sourcing decisions tied to tangible financial outcomes resonate with the C-suite.

Another popular approach with CSCOs seeking resiliency is pursuing a segmented, risk-based approach that is highly tailored.

“We segment risks based on longevity of that risk and stickiness rather than treating all disruptions equally,” commented the CSCO of a manufacturer.

With the only certainty being uncertainty, many supply chain leaders are moving in the direction of a smaller supply base and trying to be more strategic with fewer suppliers.

That’s a view shared by Christopher McCarney, KPMG National Supply Chain and Procurement Leader. “In a constrained or volatile market, being a top-tier customer to one strategic partner often buys you far more capacity and resilience than spreading your volume across four vendors where you hold no leverage.”

A major takeaway from our conversations with supply chain leaders is that resilient companies no longer let engineering/R&D departments design products in a vacuum and hand the bill of materials to procurement.

Companies are designing for trade and tariff efficiency, as well as factoring in risk-adjusted total cost of ownership. Sourcing, trade, and engineering are coordinating at the product specifications stage to help avoid tariff classifications or geopolitical bottlenecks.

“Resilience has a price tag, and every executive team must define their own tolerance. The question is whether the business is willing to accept the margin trade-off in calm times to ensure survival during the disruption.”

Christopher McCarney, KPMG National Supply Chain and Procurement Leader

Next Moves for Supply Chain Leaders

  • Shift from rebate recovery to contract-level tariff transparency. CSCOs should consider requiring suppliers to list tariff costs as separate line items on purchase orders. Establishing contract-level visibility could help prevent suppliers from pocketing shared drawback refunds and create baseline data for negotiating alternatives.
  • Raise the alarm on cyber risk. Third-party cyber vulnerabilities and AI deep fakes are supply chain threats. Collaborate with the Chief Information Security Officer on a defense strategy that includes providing under-resourced suppliers with pre-approved security roadmaps, anti-impersonation tools, and access to zero-trust data portals.
  • Build the business case for resilience with verifiable metrics. Bridge the gap between procurement and the corporate P&L by demonstrating hard, auditable returns—such as labor-hour reductions from workflow automation, guaranteed capacity allotments through single strategic alliances, or direct material cost reductions from geopolitical decoupling.

View additional insights from the Voice of the CSCO

A recurring conversation with CSCOs on supply chain priorities and challenges

Meet our team

Image of Chris McCarney
Chris McCarney
Principal, Supply Chain & Procurement Leader, KPMG LLP
Image of Andrew Siciliano
Andrew Siciliano
Partner, Trade & Customs, U.S. National Practice Leader, KPMG US

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline