{"id":21828,"date":"2026-06-30T10:11:20","date_gmt":"2026-06-30T10:11:20","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=21828"},"modified":"2026-06-30T13:23:17","modified_gmt":"2026-06-30T13:23:17","slug":"us-manufacturer-security-risk","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/","title":{"rendered":"Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">For a US automotive manufacturer working with more than 200 active vendors, supplier file intake had become a growing security and cost challenge. That pressure is especially high in manufacturing, where SOC teams carry an <strong>average workload 18% higher<\/strong> than teams in other industries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By introducing <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">behavioral sandboxing<\/a> and <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">threat intelligence<\/a>, the company made triage <strong>2x faster<\/strong>, achieved an <strong>MTTD of 20 seconds<\/strong>, <strong>improved MTTR<\/strong> and detection, and analyzed hundreds of supplier files every week without adding headcount.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A US Automotive Manufacturer Built Around a Large Supplier Ecosystem&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The company is a US-based automotive manufacturer&nbsp;operating&nbsp;within a highly interconnected supply chain. Its daily operations depend on&nbsp;continuous collaboration with more than 200 active vendors and third-party&nbsp;contractors.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These external partners regularly exchange files with the organization to support ongoing manufacturing, technical, and business processes. This makes supplier communication essential to keeping operations moving, but it also creates a large and&nbsp;constantly changing entry point for risk.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The SOC&nbsp;is responsible for&nbsp;protecting the company\u2019s environment while ensuring legitimate supplier activity is not delayed. As the volume of incoming files grew, the team needed a way to&nbsp;analyzesubmissions&nbsp;consistently, improve detection and response speed, and reduce third-party exposure without increasing staffing costs.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Challenge: Supplier Files Were Entering Without a&nbsp;Consistent Analysis Process&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before ANY.RUN, the company had&nbsp;no systematic process for&nbsp;analyzing&nbsp;files&nbsp;received from vendors and third-party&nbsp;contractors.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"470\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-1024x470.png\" alt=\"US Manufacturer\u2019s security challenges \" class=\"wp-image-21829\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-1024x470.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-300x138.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-768x353.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-1536x706.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-2048x941.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-370x170.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-270x124.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/A-US-Manufacturers-Supplier-Security-Challenge-2-740x340.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>US Manufacturer\u2019s security challenges&nbsp;<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Existing security controls could flag a submission as suspicious, but they did not always show what the file would actually do after execution. Without behavioral evidence, analysts were left with incomplete indicators and uncertain verdicts.<\/p>\n\n\n\n<figure class=\"wp-block-pullquote has-text-align-center\"><blockquote><p>\u201cThe volume itself was not the only challenge. The bigger issue was that analysts did not have enough&nbsp;context&nbsp;to quickly decide which supplier files were safe and which&nbsp;required&nbsp;further action.\u201d&nbsp;<\/p><cite><strong><em>Head of SOC, US automotive manufacturer<\/em><\/strong>&nbsp;<\/cite><\/blockquote><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This created several problems for the SOC:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A Security Gap in Supplier File Intake&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Files could enter the environment without passing through a dedicated behavioral analysis layer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This limited the company\u2019s ability to identify threats that appeared harmless during static inspection but revealed malicious activity only after execution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The risk was especially significant in a large supplier ecosystem. A compromised vendor account or mailbox could turn a trusted communication channel into an indirect route into the organization. With <strong>more than 47%<\/strong> of attacks on manufacturing companies originating from email, supplier messages and attachments represented a critical part of the company\u2019s third-party attack surface.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">High Escalation Rates&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Tier 1 analysts often lacked enough&nbsp;context&nbsp;to&nbsp;confidently close suspicious submissions.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result,&nbsp;the majority of&nbsp;these files were escalated to more experienced analysts. Senior team members had to spend time reviewing cases that could have been resolved earlier with clearer evidence.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Rising Investigation Costs&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The supplier network&nbsp;continued to generate a high volume of files. Handling that growth&nbsp;through manual investigation would have&nbsp;required&nbsp;more analyst hours and, eventually,&nbsp;additional&nbsp;headcount.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without a more scalable process, the company risked paying more just to maintain the same level of protection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This pressure is especially high in manufacturing, where SOC teams carry an average workload <strong>18% higher<\/strong> than security teams in other industries. For companies managing large supplier ecosystems, that makes manual investigation increasingly difficult to sustain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Longer Exposure to Potential&nbsp;Threats&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Every delay in&nbsp;validating&nbsp;a suspicious file extended the period during which the organization could not&nbsp;confidently allow, block, or&nbsp;contain&nbsp;it.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a manufacturing environment, a missed&nbsp;threat&nbsp;can affect more than an individual endpoint. It can disrupt operations, expose sensitive data, and weaken trust across the supplier network.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Building a Scalable Supplier File Triage and Analysis Process with ANY.RUN&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The manufacturer introduced a&nbsp;consistent process for&nbsp;analyzing&nbsp;files received from vendors and third-party&nbsp;contractors.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By combining&nbsp;behavioral&nbsp;analysis with&nbsp;threat&nbsp;intelligence, the SOC gained both the evidence needed to understand what a file&nbsp;does&nbsp;and the&nbsp;context&nbsp;required&nbsp;to assess the wider&nbsp;threat&nbsp;behind it.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>\u201cWe have over 200 active vendors sending files into the environment. ANY.RUN gave us a scalable way to analyze that volume and make triage much faster without adding headcount\u201d<\/p><cite>Head of SOC, automotive manufacturer<\/cite><\/blockquote><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of relying on isolated alerts or incomplete indicators, analysts could detect malicious submissions more accurately, reach verdicts faster, resolve more cases at Tier 1, and reduce the amount of senior analyst time spent on routine reviews.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This improved detection quality while&nbsp;contributing to lower MTTD and MTTR across supplier-related investigations.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Reaching Faster Verdicts with&nbsp;Behavioral&nbsp;Evidence&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The SOC reduced triage time by giving analysts direct visibility into what suspicious supplier files did after execution.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Files were safely&nbsp;analyzed&nbsp;in ANY.RUN\u2019s cloud-based&nbsp;<a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive&nbsp;Sandbox<\/a>, where the team could review process activity, network&nbsp;connections, system changes, commands, and other&nbsp;behavior&nbsp;without exposing the production environment.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"570\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1024x570.webp\" alt=\"\" class=\"wp-image-21830\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1024x570.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-300x167.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-768x427.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1536x854.webp 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-370x206.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-270x150.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-740x412.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-23-at-11.08.07-2048x1139.png.webp 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Full chain of a complicated&nbsp;EvilTokens&nbsp;attack on US companies&nbsp;analyzed&nbsp;in&nbsp;just 1 minute<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This&nbsp;replaced incomplete indicators with&nbsp;clear evidence&nbsp;of whether a submission was malicious and how it could affect the business.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>\u201cWe no longer&nbsp;have to&nbsp;spend time piecing together what a supplier file might do. The&nbsp;behavior&nbsp;is visible in one place, which makes decisions faster and easier to defend.\u201d<\/em>&nbsp;<\/p><cite><strong><em>Head of SOC, US automotive manufacturer<\/em><\/strong>&nbsp;<\/cite><\/blockquote><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Structured and visual results also helped Tier 1 analysts move from alert to verdict with fewer manual checks. Instead of reconstructing file&nbsp;behavior&nbsp;across disconnected tools, they could&nbsp;validatesuspicious submissions faster and make more&nbsp;confident decisions.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The faster path from alert to&nbsp;confirmed verdict&nbsp;contributed to improved MTTD, while clearer evidence and fewer&nbsp;repeated checks helped reduce MTTR.&nbsp;<\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Cut investigation time<\/span> with clear behavioral evidence<br>Help analysts reach <span class=\"highlight\">faster decisions. <\/span>\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-manufacturer-security-risk&#038;utm_term=300626&#038;utm_content=linktoenterprise#contact-sales\" target=\"_blank\" rel=\"noopener\">\nAccelerate triage now &nbsp;\n<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h3 class=\"wp-block-heading\">Connecting Supplier Files to Wider&nbsp;Threat&nbsp;Activity&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Behavioral analysis showed the team what each suspicious file did. <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat intelligence<\/a> helped reveal whether the submission was connected to a larger risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Indicators uncovered during analysis could be linked to malicious infrastructure, related samples, known campaigns, and attacker activity. This gave analysts a clearer view of whether they were dealing with an isolated file or broader activity involving the company\u2019s supplier ecosystem.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"383\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg-1024x383.webp\" alt=\"\" class=\"wp-image-21831\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg-1024x383.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg-300x112.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg-768x287.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg-370x138.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg-270x101.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg-740x277.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/img68.jpg.webp 1252w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN\u2019s Threat Intelligence used to explore broader threat context<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The SOC also used this context to uncover additional indicators and behavioral patterns, strengthening internal detection controls beyond the original submission.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, each investigation&nbsp;contributed to wider&nbsp;threat&nbsp;visibility. The team could resolve the immediate case while also&nbsp;identifying&nbsp;related activity that might otherwise remain hidden across the supply chain.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Resolving More Supplier Files at Tier 1&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before ANY.RUN, suspicious supplier files often moved up the escalation chain because Tier 1 analysts lacked enough evidence to&nbsp;confidently&nbsp;determine&nbsp;whether they were safe or malicious.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With&nbsp;behavioral&nbsp;analysis,&nbsp;threat&nbsp;intelligence, and structured Tier 1 Reports available in the same workflow, first-line analysts received clearer summaries of each case, along with practical recommendations for the next step.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"685\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-1024x685.webp\" alt=\"\" class=\"wp-image-21832\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-1024x685.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-300x201.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-768x514.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-1536x1027.webp 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-370x247.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-270x181.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png-740x495.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-05-12-at-13.53.31.png.webp 1890w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>AI Summary generated inside ANY.RUN\u2019s&nbsp;sandbox&nbsp;for deeper analysis and faster handoff<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This reduced the need to interpret every technical detail manually and helped analysts reach decisions faster. The company recorded a significant reduction in Tier 1 escalations, while Tier 2 received fewer low-context cases.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>\u201cCases that can be resolved at the first level no longer&nbsp;consume Tier 2 time. When escalation is necessary, senior analysts receive the relevant evidence instead of having to restart the investigation.\u201d<\/em>&nbsp;<\/p><cite><strong><em>Head of SOC, US automotive manufacturer<\/em><\/strong>&nbsp;<\/cite><\/blockquote><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The change reduced duplicated work and made better use of specialist&nbsp;expertise. Senior analysts spent less time&nbsp;repeating initial validation and more time investigating complex or high-impact&nbsp;threats.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More supplier files were resolved at the right level the first time, helping investigation queues move faster and lowering the cost of each case.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Analyzing&nbsp;Hundreds of Files Without Adding Headcount&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The company now analyzes hundreds of supplier files every week without hiring additional analysts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the business, this is one of the clearest returns from the new process. The manufacturer increased its triage and analysis capacity while keeping staffing costs stable.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of treating headcount growth as the only solution to rising file volumes, the company gave its existing team a faster and more&nbsp;consistent way to detect malicious activity and reach verdicts.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The SOC now absorbs more supplier activity without creating the same increase in&nbsp;labor&nbsp;costs or investigation backlogs.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This also gives the company a more sustainable foundation for growth. As the vendor network expands or file volume rises, the security team has a triage process that can scale with it.&nbsp;<\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Reduce<\/span> third-party exposure before it affects operations.<br>Increase security capacity  <span class=\"highlight\"> without increasing headcount. <\/span>\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/by-industry\/manufacturing\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-manufacturer-security-risk&#038;utm_term=300626&#038;utm_content=linktomanufacturing#contact-sales\" target=\"_blank\" rel=\"noopener\">\nReduce risk now  &nbsp;\n<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Improving MTTD and MTTR with 2x Faster Triage&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The manufacturer achieved a&nbsp;<strong>2x improvement in alert processing and&nbsp;threat&nbsp;analysis speed<\/strong>,&nbsp;contributing to lower mean time to detect and mean time to respond.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Suspicious supplier files moved through triage twice as fast. Analysts identified malicious behavior sooner, reached confirmed verdicts with less delay, and passed high-risk cases into response with clearer evidence already collected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Legitimate submissions were also cleared faster, reducing the time business teams spent waiting for a security decision.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>\u201cWe cut the time it takes to move from a suspicious supplier file to a clear decision in half. That gave the business faster answers and reduced the time potential&nbsp;threats remained unresolved.\u201d<\/em>&nbsp;<\/p><cite><strong><em>Head of SOC, US automotive manufacturer<\/em><\/strong>&nbsp;<\/cite><\/blockquote><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This faster process also reduced the company\u2019s exposure window. Analysts reached evidence-backed verdicts sooner without sacrificing investigation depth, helping the SOC protect operations while keeping supplier workflows moving.&nbsp;<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-336\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"5\"\n           data-wpID=\"336\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:33.333333333333%;                    padding:10px;\n                    \"\n                    >\n                                        Before ANY.RUN\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:33.333333333333%;                    padding:10px;\n                    \"\n                    >\n                                        Result with ANY.RUN\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:33.333333333333%;                    padding:10px;\n                    \"\n                    >\n                                        Business Impact\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        No systematic process for\u00a0analyzing\u00a0vendor files\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hundreds of supplier files\u00a0analyzed\u00a0weekly\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Greater triage capacity without\u00a0additional\u00a0hiring\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        No\u00a0behavioral\u00a0analysis layer in supplier file intake\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Malicious\u00a0behaviordetected\u00a0through direct execution evidence\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Higher detection rate and lower third-party exposure\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Most suspicious submissions escalated by Tier 1\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Significant reduction in Tier 1 escalations\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        More senior analyst capacity for critical incidents\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Slow,\u00a0context-limited investigations\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        2x faster alert processing and\u00a0threat\u00a0analysis\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Improved MTTD and MTTR with a shorter exposure window\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-336'>\ntable#wpdtSimpleTable-336{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-336 td, table.wpdtSimpleTable336 th { white-space: normal !important; }\n<\/style>\n\n\n\n\n<h2 class=\"wp-block-heading\">A Practical Model for Manufacturing Leaders Managing Third-Party Risk&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For manufacturing leaders, supplier security is not only a SOC issue. It affects operational&nbsp;continuity, staffing costs, executive accountability, and the company\u2019s ability to grow without increasing exposure.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A scalable approach should combine&nbsp;consistent file validation, broader&nbsp;threat&nbsp;context, and measurable outcomes.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Turn Supplier File Intake into a Defined Risk&nbsp;Control&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A&nbsp;consistent&nbsp;triage&nbsp;helps the SOC apply the same standard to files received from vendors and&nbsp;contractors.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With behavioral evidence from the <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> and additional context from <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence<\/a>, teams can replace inconsistent manual checks with a repeatable validation workflow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For leadership, this creates clearer oversight of one of the company\u2019s most exposed third-party risk channels.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Increase Capacity Without Matching Growth with Headcount&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Faster verdicts and fewer unnecessary escalations allow the existing team to handle more supplier submissions.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN reduces duplicated work, protects senior analyst capacity, and helps the SOC process higher file volumes without expanding at the same rate.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result is lower investigation cost and greater value from existing security resources.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Protect Operations Without Slowing Supplier Activity&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Suspicious files can be&nbsp;analyzed&nbsp;in a&nbsp;controlled environment before they reach internal systems, while legitimate submissions move&nbsp;through review faster.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This helps reduce the risk of supplier-borne&nbsp;threats without creating unnecessary delays for manufacturing, procurement, engineering, or other teams that depend on third-party collaboration.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Connect Individual Submissions to Wider Exposure&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A suspicious file may be only one part of a larger campaign.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat&nbsp;Intelligence<\/a>&nbsp;solutions help teams&nbsp;connect indicators to known infrastructure, related samples, active campaigns, and broader attacker activity.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This gives leadership a clearer view of whether the company is dealing with an isolated submission or wider exposure involving suppliers and other external partners.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Demonstrate Measurable Business Value&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The strongest supplier security programs are measured by outcomes, not by the number of files processed.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With ANY.RUN, organizations can track improvements such as lower MTTD and MTTR, higher detection rates, fewer Tier 1 escalations, greater analysis capacity, and shorter exposure windows.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These results make it easier to show how supplier security investments reduce risk, avoid&nbsp;additional&nbsp;staffing costs, and support business growth.&nbsp;<\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">Reach a<span class=\"highlight\"> 20-second MTTD<\/span> and shorten the exposure window.\n<br><span class=\"highlight\">Reduce supplier-driven risk <\/span> before it affects operations.  \n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/by-industry\/manufacturing\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktomanufacturing#contact-sales\" target=\"_blank\" rel=\"noopener\">\nStrengthen supplier security  &nbsp;\n<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For this US automotive manufacturer, supplier file intake had become both a security risk and a growing cost center. More than 200 vendors were sending files into the environment, while analysts lacked a consistent way to validate behavior, add threat context, and reach fast decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With ANY.RUN, the company built a scalable triage process that now supports hundreds of supplier files every week without&nbsp;additional&nbsp;headcount.&nbsp;Threat&nbsp;analysis became 2x faster, MTTD and MTTR improved, detection increased, and fewer cases required Tier 2 escalation.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result is a stronger security model for a complex supplier ecosystem: lower third-party exposure, better use of analyst time, and faster decisions that keep business operations moving.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN, a leading provider of interactive malware analysis and&nbsp;threat&nbsp;intelligence solutions, helps SOC teams, MSSPs, and enterprises investigate cyber&nbsp;threats faster and make evidence-based security decisions.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its cloud-based <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> enables teams to safely analyze suspicious files, URLs, and emails in real time, observe malicious behavior as it unfolds, and collect clear evidence for triage and response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat&nbsp;Intelligence<\/a>&nbsp;solutions provide&nbsp;additional&nbsp;context&nbsp;around indicators, malicious infrastructure, emerging campaigns, and attacker activity. Together, these capabilities help organizations improve&nbsp;threat&nbsp;detection, reduce investigation time, and manage growing security demands without adding unnecessary operational costs.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For a US automotive manufacturer working with more than 200 active vendors, supplier file intake had become a growing security and cost challenge. That pressure is especially high in manufacturing, where SOC teams carry an average workload 18% higher than teams in other industries. By introducing behavioral sandboxing and threat intelligence, the company made triage [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":21835,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[79],"tags":[57,10],"class_list":["post-21828","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-customer-success","tag-anyrun","tag-cybersecurity"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How a US Manufacturer Reduced Supplier Risk and Doubled SOC Triage Speed<\/title>\n<meta name=\"description\" content=\"See how a US automotive manufacturer secured supplier file intake, cut Tier 1 escalations, doubled SOC triage speed, and scaled without adding headcount.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed\",\"datePublished\":\"2026-06-30T10:11:20+00:00\",\"dateModified\":\"2026-06-30T13:23:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/\"},\"wordCount\":2397,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Supply-Chain-Security-with-ANY.RUN_-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\"],\"articleSection\":[\"Customer Success Story\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/\",\"name\":\"How a US Manufacturer Reduced Supplier Risk and Doubled SOC Triage Speed\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Supply-Chain-Security-with-ANY.RUN_-scaled.png\",\"datePublished\":\"2026-06-30T10:11:20+00:00\",\"dateModified\":\"2026-06-30T13:23:17+00:00\",\"description\":\"See how a US automotive manufacturer secured supplier file intake, cut Tier 1 escalations, doubled SOC triage speed, and scaled without adding headcount.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Supply-Chain-Security-with-ANY.RUN_-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Supply-Chain-Security-with-ANY.RUN_-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"Supply Chain Security with ANY.RUN\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/us-manufacturer-security-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Customer Success Story\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/customer-success\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How a US Manufacturer Reduced Supplier Risk and Doubled SOC Triage Speed","description":"See how a US automotive manufacturer secured supplier file intake, cut Tier 1 escalations, doubled SOC triage speed, and scaled without adding headcount.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed","datePublished":"2026-06-30T10:11:20+00:00","dateModified":"2026-06-30T13:23:17+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/"},"wordCount":2397,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Supply-Chain-Security-with-ANY.RUN_-scaled.png","keywords":["ANYRUN","cybersecurity"],"articleSection":["Customer Success Story"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/","url":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/","name":"How a US Manufacturer Reduced Supplier Risk and Doubled SOC Triage Speed","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Supply-Chain-Security-with-ANY.RUN_-scaled.png","datePublished":"2026-06-30T10:11:20+00:00","dateModified":"2026-06-30T13:23:17+00:00","description":"See how a US automotive manufacturer secured supplier file intake, cut Tier 1 escalations, doubled SOC triage speed, and scaled without adding headcount.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Supply-Chain-Security-with-ANY.RUN_-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Supply-Chain-Security-with-ANY.RUN_-scaled.png","width":2560,"height":1243,"caption":"Supply Chain Security with ANY.RUN"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/us-manufacturer-security-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Customer Success Story","item":"https:\/\/any.run\/cybersecurity-blog\/category\/customer-success\/"},{"@type":"ListItem","position":3,"name":"Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/21828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=21828"}],"version-history":[{"count":15,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/21828\/revisions"}],"predecessor-version":[{"id":21856,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/21828\/revisions\/21856"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/21835"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=21828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=21828"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=21828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}