Correlens

Use case · Supply-chain risk

A supplier breach, resolved to the parts it puts at risk.

When a dark-web actor advertised data allegedly stolen from a large connected-engineering partner, the useful question was never “is this real?” alone. It was “which of our components, ECUs and programs does this supplier touch?” This is how that question gets answered.

1 · The signal arrivesAn actor advertises ~35 GB allegedly stolen from Accenture on a dark-web forum, claiming source code, cloud tokens and credentials. Accenture publicly confirmed an incident; the claimed volume was never verified.
2 · Scored, not amplifiedThe AI weighs the claim against the actor’s track record. This actor has a documented history of exaggerated claims, so the signal lands as medium confidence: reported, not escalated as fact.
3 · Correlated to your graphThe supplier is already in your register, linked to the components it ships you. The platform resolves the breach to the exact shared components, the ECUs they sit on, and the programs at risk, ranked.
4 · A person decidesAn analyst confirms relevance, re-scores for the real vehicle context, and the decision plus its reasoning is recorded. The audit trail writes itself.

The outcome

Decision trail

A vague dark-web boast became a short, ranked list of components and programs with an owner and a recorded decision, in minutes instead of a scramble. The same trail is the evidence an assessor later asks for.

Decision trailsample data
09:41Signal ingested and deduplicated across sourcesSIG-4471
09:41Confidence scored against actor history0.62 · MEDIUM
09:43Resolved to shared components and programs3 COMPONENTS
10:02Analyst confirmed relevance, re-scored for contextANALYST K.M.
10:05Exported as STIX 2.1 to the (V)SOCSTIX 2.1
Every step above is a record: who, when, what changed, and why.

Public cases

Five years of public examples. One shared question.

Publicly reported supplier incidents from automotive and adjacent industries. None of them started as the buyer's breach; every one of them still needed the same answer in hours: which of our components, programs and plants does this supplier touch?

Accenture · 2021 and 2026

In August 2021 the LockBit 2.0 group claimed roughly 6 TB stolen from Accenture and demanded 50 million dollars; confirmation that data had been accessed came only in a later quarterly filing. In July 2026 a different actor advertised source code, cloud keys and credentials on a criminal forum, and researchers pointed at client-branded folders in the leaked tree as the real exposure. Both times the number came from the attacker, and the useful first move was to resolve the claim to what it actually touches.

public reporting 1public reporting 2

Continental · 2022

LockBit exfiltrated internal files from the Tier-1 supplier over roughly a month before detection, then offered the data for sale at 50 million dollars. Continental supplies VW, BMW, Mercedes-Benz and Ford among others, so one supplier's stolen archive is many OEMs' exposure question.

public reporting

Toyota / Kojima Industries · 2022

A cyberattack on a domestic parts supplier took down Toyota's ordering systems. With no buffer in a just-in-time model, Toyota halted 28 lines across 14 plants for a day, an estimated 13,000 vehicles of lost production, without being breached itself.

public reporting

Denso · 2022

The Pandora group claimed 1.4 TB from Denso's German operations in the same month. Denso cut network access on discovery and reported no production impact: same buyer relationships as Kojima, a different blast radius depending on which system is hit.

public reporting

Why this is required, not optional

Every framework asks the supplier question somewhere.

Different regulators, the same underlying ask: know which suppliers touch what, and be able to show it.

21434 · Clause 7 Distributed activities: when cybersecurity work is split between customer and supplier, responsibilities live in a Cybersecurity Interface Agreement, evaluated at supplier selection.
21434 · Clause 15 TARA covers every component in scope, and supplier-sourced components feed the same analysis with a recorded treatment decision.
UNECE R155 The certified CSMS must manage risk across the supply chain: requirements cascaded to suppliers, and cybersecurity evidence flowing back per component.
EU CRA · Art. 13 Due diligence on third-party and open-source components, and a duty to report a vulnerability found in one back to its maker or maintainer.
NIS2 · Art. 21(2)(d) Supply-chain security covering the relationship with each direct supplier, weighed against that supplier's own vulnerabilities and practices.
DORA · Art. 28 Financial entities, including OEM captive finance and leasing arms that are licensed institutions, keep a current register of every ICT third-party arrangement, tagged by criticality and reported to regulators.
TISAX / VDA ISA OEMs require suppliers handling shared data or prototypes to hold a TISAX label at an assessment level matched to data sensitivity.
SBOM practice Born from US EO 14028 and NTIA minimum elements; the federal mandate was rescinded by an OMB policy change in February 2026, but R156 and the CRA still expect component-level bills of materials per release.

The mapping is a navigation aid, not a certification claim. Verify clause numbers and current force against the official texts before an assessment.

Where Correlens fits

The register every incident needed is the one every standard asks for.

Each case above became a downstream problem before the affected supplier finished its own investigation. The artifact that shortens that gap is the same one the frameworks require: a live register of which supplier ships which component on which program. Correlens keeps that register current, resolves a new signal against it, and records the analyst's decision as it is made, so incident response and audit evidence are one artifact, not two chores.

See this run against your own suppliers.

Run this on my suppliers