Pharmaceutical Market Europe • July/August 2026 • 36-37

SUPPLY CHAIN MANAGEMENT

Supply chain management evolves to curb converging risks in pharma

How regional conflicts, tariffs, cybercrime and other issues are compounding risks for the pharmaceutical sector

By David Weeks

Image
Image

Pharmaceutical companies that take a more unified and proactive approach to supply-chain management may be more resilient as new threats emerge and risks increasingly interact and amplify each other amid pressures including geopolitical conflicts, cybercrime and manufacturing failures.

Geopolitics and tariffs can reshape access to essential materials. Events in one region may affect many others. This year’s conflict with Iran contributed to disruptions in the supply of Indian-sourced active pharmaceutical ingredients. During the US-China tariff escalation in 2025, a proposed 25% pharmaceutical import tariff led to double-digit cost increases for staple molecules such as amoxicillin, acetaminophen and metformin. Such effects cascaded, pushing up prices of drug imports in other countries worldwide.

Other developments and regulatory actions may also pose a threat. A facility shutdown or a regulator’s warning letter about drug quality may take an essential plant offline overnight, removing capacity and disrupting the global pharmaceutical supply chain for product classes that rely on a handful of qualified sites. And while digitalisation has transformed pharmaceutical operations, improving coordination across manufacturing, regulatory submissions, distribution and reimbursement, it has created new dangers. Many cyber risks can originate from third-party platforms, claims processors, logistics providers, distributors and IT vendors, whose systems are tightly coupled to the continuity of drug supply.

The implication is clear – a traditional strategy to manage supply chains with an emphasis on just-in-time delivery, based on lean inventories and manufacturing where it is cheapest, may prove costly if it means that companies fail to anticipate problems and mitigate risks. Pharmaceutical supply chains may benefit by shifting from a model designed primarily to minimise immediate costs to one built to identify threats at an early stage and increase resilience. Real-time monitoring combined with diversification of sources, alternative routing and regionalised production may help companies adapt quickly to changing circumstances.

‘In 2023 alone, cyber incidents reportedly compromised 133 million health records in the US’

To assess risks and make plans to mitigate them in the event of regional conflict, natural disaster or other cause typically requires access to good, current data. This may include information on individual companies, entire regions, geopolitical developments, laws and the latest media reports. Appropriate tools can offer valuable insights through scenario testing, bottleneck analysis and other approaches relevant to supply chain risk management.

Costs of cybercrime

The growth of cyber threats and the rapid adoption of AI across the pharmaceutical sector is extending risk exposure in ways that may not be fully mapped. Companies are deploying AI across drug discovery, manufacturing quality control, regulatory documentation and supply chain optimisation, often at speed and in some cases without commensurate investment in AI-specific risk frameworks.

In 2023 alone, cyber incidents reportedly compromised 133 million health records in the US, with an average of about two major health data breaches per day. The average cost of a breach has been estimated to exceed $5m and organisations took about 257 days on average to detect and contain each incident.

According to research by Moody’s affiliate Bitsight, the majority of cyber breaches including protected healthcare information since 2022 involved compromised vendors, partners or other third parties – a finding that reinforces why supply chain integrity and third-party oversight are important for managing enterprise cyber risks.

Organisations are increasingly adopting a unified approach to risk management to gain better insights into threats, earlier warnings and a clearer picture of how risks may interact and escalate. Aggregating risk signals into a single unified view may also improve efficiency by breaking down silos of risk assessment and management that were previously in individual functions such as IT, procurement and supply chain control.

Companies that view disruptions as isolated incidents may be more exposed. Those that treat them as broader warning signals – indicating stress in critical routes, suppliers or policy assumptions – may be better positioned to take actions such as diversifying suppliers, or building more buffer stocks, before shocks fully materialise.

Red Sea attacks

The Red Sea shipping crisis of 2023-24 is an example of why this approach may be valuable. Houthi attacks on commercial vessels forced six of the ten largest container carriers to halt or sharply reduce passage through the Red Sea. Traffic through the Suez Canal collapsed by two-thirds. Ships rerouted around the Cape of Good Hope, adding close to two weeks and roughly 4,000 miles to each voyage.

For pharmaceutical manufacturers, especially those in India exporting generic medicines to Europe, the effect of this disruption was that shipping costs more than doubled, lead times stretched and the just-in-time model that governs much of generic drug production left limited margin to absorb the delay. Global financial services firm J.P. Morgan estimated that the crisis cut global container capacity by close to a tenth and added 0.7 percentage points to global core goods inflation in the first half of 2024. A regional conflict had choked the route on which most Indian generics depend, exposing how little buffer the industry had built into its logistics backbone.

Years of cost-driven consolidation had concentrated the production of active pharmaceutical ingredients in China and India and funnelled global logistics through a handful of maritime bottlenecks. Those decisions created some efficiencies, but they also built structural exposure to geopolitical tension, trade policy and transport disruption. The result was a system where events unfolding thousands of miles away could rewrite manufacturing schedules overnight.

Lessons from history

Many pharmaceutical supply chain failures follow patterns that can be traced back to months, or sometimes years, before the disruption became visible. Breaches of regulations may accumulate, financial ratios weaken and operational performance slip.

In the US, the Food and Drug Administration (FDA) issues hundreds of drug recall events every year and many are rooted in quality failures with identifiable precursors.

In the gap between the first warning signs and a full crisis, there may be insufficient visibility or monitoring. Financial pressures may offer an example of how difficulties start and then snowball. When margins tighten, investments that support performance, workforce stability, quality controls and process improvements are often reduced. In turn, morale declines, problem-solving capacity weakens and production difficulties follow. By the time these pressures surface through delivery failures or quality problems, the deterioration may have been developing for months.

Early detection is critical. Proactive monitoring can help organisations to identify and address risks before localised issues evolve into systemic failures. It also helps to increase transparency by mapping supplier relationships and dependencies across multiple tiers.

Coverage is a significant challenge. A pharmaceutical company with hundreds of direct suppliers and thousands more across Tier 2 and beyond, is unlikely to be able to track this network manually. Advances in analytical and AI tools may speed up this work, supporting more timely information and faster analysis and decision-making.
The entities most likely to cause disruption may sometimes be the least visible, such as contract manufacturers and raw material providers that are several steps removed from the buying organisation, with no obligation to reveal financial or operational stress until it is advanced.

What data do you need?

Organisations in the value chain may have different combinations of risk factors – from cybersecurity to human rights, physical climate risk to sanctions and credit to geopolitical pressure.

For pharmaceutical companies, access to accurate, current data is key to identifying the risk signals that matter most. This information may include public and private databases, media reports, legal filings and companies’ own customer records. Typical data includes:

• Financial indicators (liquidity ratios, leverage, liens, signs of distress)
• Operational signals (quality issues, missed delivery deadlines, premium freight incidents)
• Compliance alerts (regulatory findings, safety violations, negative media coverage)
• Geopolitical and environmental risks (trade restrictions, export bans, natural disasters)
• Cybersecurity vulnerabilities (third-party vendors targeted in ransomware attacks).

With the right tools and processes in place, when any of these signals deteriorate, they may be quickly flagged – enabling further analysis for insights into how the risks may develop and interact. This, in turn, may give organisations more time to take actions to mitigate potential harm – such as building stockpiles, rerouting deliveries, qualifying alternative suppliers or taking other steps before the supply chain is badly affected.


David Weeks is Director, Supply Chain Risk Management Solutions at Moody’s