The Role of Internal Auditing in Managing Cybersecurity Risks in Pharmaceutical Supply Chains for F. Hoffmann-La Roche Ltd
Cyberattacks on suppliers can halt the production of life-saving medicines. This thesis examines how internal auditing can strengthen cybersecurity risk management across Roche's pharmaceutical supply chain in times of geopolitical instability, and delivers an audit checklist and risk matrix.
Shah, Mohammed Ali, 2026
Art der Arbeit Bachelor Thesis
Auftraggebende F. Hoffmann La Roche AG
Betreuende Dozierende Grimberg, Frank
Views: 3
Pharmaceutical supply chains are global, highly interconnected and critical to public health, which makes them an attractive target for cyberattacks. Incidents such as NotPetya at Merck or the 2023 ransomware attack on Sun Pharma show that a compromise at a single partner can disrupt production and patient supply. Geopolitical tensions further amplify these threats through state-aligned activity. Internal auditing provides independent assurance, yet existing frameworks give little guidance on how to audit the cybersecurity maturity of supply chain partners.
The thesis follows a qualitative, design oriented approach. A structured literature review establishes the conceptual basis and compares recognised cybersecurity and internal audit frameworks. Semi structured interviews with practitioners from relevant functions capture current practice, which is analysed thematically. A gap analysis compares practice with the frameworks. On this basis, a practical audit instrument for assessing the cybersecurity maturity of supply chain partners is developed in coordination with the client.
The thesis provides a structured overview of the cybersecurity risks most relevant to pharmaceutical supply chains and explains how geopolitical instability amplifies them. It clarifies the role and limitations of internal auditing in relation to cybersecurity and supplier risk, and compares the guidance offered by recognised governance and audit frameworks. The gap analysis shows where current assurance over supply chain cybersecurity differs from what these frameworks recommend.The central practical outcome is an internal audit instrument: an audit checklist for assessing the cybersecurity maturity of supply chain partners, complemented by a risk assessment matrix that links common supply chain cyber threats to relevant internal audit controls.For the client, the benefit is a practical and proportionate basis for strengthening cybersecurity assurance across the supplier network. The instrument supports a more consistent evaluation of partners, makes supply chain cyber risks more visible to internal audit, and translates governance requirements into controls that can be applied in day to day audit work.
Studiengang: Business Information Technology (Bachelor)
Keywords Managegment Summary Bachelor Thesis
Vertraulichkeit: vertraulich