N

News

How Hachette’s Cyber Incident Exposed the Cost of Supplier Disruption

What happens when a cyber incident at a critical supplier makes it harder for other businesses to serve their customers?

On 18 July, Hachette Australia & New Zealand and Alliance Distribution Services (ADS) detected unauthorised activity on their computing systems. More than a month later, restoration work was continuing, and Australian bookshops were still dealing with delayed stock, uncertain book launches and customers waiting for titles.

The incident began inside Hachette ANZ and ADS, but its operational consequences reached the independent booksellers, authors and readers who depend on their distribution services. It shows how quickly a cyber incident can become a customer service and business continuity problem for organisations that were not directly attacked.

The supplier owns the recovery, but its customers inherit the disruption. For businesses that rely on external providers, resilience depends on knowing which suppliers are critical, how long their absence can be tolerated and what alternatives can keep essential operations moving.


An Upstream Incident Became a Bookshop Problem

By late August, independent booksellers were struggling to replenish their shelves. Authors could not be certain that books would be available for events, while booksellers had fewer answers for customers asking when stock would arrive.

Some new releases continued to move through manual processes. Booksellers could also source titles from other retailers or overseas suppliers, although the additional freight came at a cost. In many cases, there was little choice but to wait for normal distribution services to return.

That is what makes this incident relevant beyond publishing. The disruption appeared in one of the most familiar and physical parts of Australian retail: a customer standing in a bookshop, asking for a title that should have been available.

The book existed and the customer wanted to buy it, but the systems needed to move it from warehouse to shelf were no longer working as expected.

For the bookseller, the technical details mattered less than the immediate business problem. Customers still needed to be served while someone else worked to restore the affected systems.


The Supplier Owns the Recovery

Bookshops could not control how quickly ADS restored its systems, but they still had customers to serve.

The same problem arises whenever a distributor, payment service, freight company or other critical provider becomes unavailable. The provider may be responsible for restoring its systems, but its customers still have to manage the interruption.

That is why cyber readiness needs to extend beyond an organisation's own network. Protecting internal systems remains essential, but it does not address every source of operational risk. A business may still depend on external services that it cannot monitor, restore or replace quickly.

Supplier resilience is therefore more than a compliance questionnaire. It requires a practical understanding of which providers support essential operations, how long the business can tolerate their absence and what alternatives are available if normal service stops.


Five Questions Can Expose the Gap

A useful continuity check begins with the suppliers connected to essential products and services. For each one, the business should be able to answer:

  1. Which suppliers could stop us serving customers if their systems went offline?

  2. How quickly would we know that a supplier incident was affecting our operations?

  3. What manual workaround or alternative supplier could keep essential work moving?

  4. Who has authority to activate that workaround and communicate with customers?

  5. How long could we operate before the disruption became commercially serious?

These questions do not require detailed knowledge of a supplier’s security environment. They help establish what the business controls, where it depends on someone else and which decisions need to be made before disruption occurs.

If the answers are unclear, the continuity gap already exists. It simply has not been tested yet.


Security and Continuity Need to Work Together

At Secure ISS, we see this as the point where security and continuity meet. Organisations need the visibility to understand incidents and coordinate an effective response, but they also need plans for situations where the affected systems belong to a supplier.

Through Lumara, our SecOps team helps Australian organisations connect security signals, investigate suspicious activity and respond with clearer information. That visibility supports better decisions when operations are under pressure, although technology remains only one part of resilience.

The Hachette incident shows why those decisions cannot begin after a critical provider becomes unavailable. Organisations need to know which suppliers matter most, what alternatives exist and who has authority to act.

Every business has its own version of the empty bookshelf. Resilience depends on identifying it before a supplier incident puts it there.

Let's talk about strengthening visibility, incident response and resilience across the services your organisation relies on.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.