Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

Why enterprises aren’t properly addressing supply chain threats [Q&A]

usscmc by usscmc
February 19, 2021
Why enterprises aren’t properly addressing supply chain threats [Q&A]
Share on FacebookShare on Twitter

supply chain

Supply chain threats like the recent SolarWinds attack are becoming more of a concern as businesses are more reliant on smoothly functioning links with suppliers and customers.

A successful attack can have a devastating effect on an organization and its reputation, but by their very nature these are not easy threats to deal with.

We spoke to Gregory Cardiet, security engineering director, EMEA at cybersecurity company Vectra to find out more about what enterprises are missing when detecting and responding to these threats.

BN: Why are supply chain attacks such a problem?

GC: There are multiple types of attack, the ones that involve software vendors can provide directory information and track the environment without them knowing because of the specific partnership.

Take the recent attacks, there’s a piece of software that’s been added into the SolarWinds software so that when it starts is trying to reach out to a third party website that is owned by a hacker group. Once the software reaches out to that kind of structure it scans and starts taking control and uploading some additional pieces of malware, and it will try multiple times. This is difficult for most organizations that will provide software updates and packages maybe once a week or once a month. Once the hackers can get access they can access companies as an insider.

BN: Is the current drive towards digital transformation initiatives leaving companies more open to this kind of attack?

GC: There are cases of this type of attack five, six, 10 years ago, it’s not something new. What is a new indicator is how complex and sophisticated the attack is. We normally expect to have an acceleration of this type of attack because there is financial motivation behind them. If you think about it though you need to get into one of the major software vendors bypass every single protection measure every single detection measure, every single security processes, being able to manage the complexity, time and energy that is required is extremely hard. But we are going to see an increase of that because I expect state sponsored groups to use these techniques in the future to get broad access to many many organizations.

So the push to digital transformation is one potential vector of acceleration. But the complexity and sophistication of these attacks, makes it very unlikely that we see them being broadly used by criminals trying to get some cryptocurrency. In many supply chain attacks there is no financial motive. The target is to get access to critical resource and gain intellectual property. It’s going to be more targeted attacks that you’re likely going to see the most.

BN: So these are more likely to be nation state-type attacks?

GC: The time and energy needed, bypassing these components at each stage means it has to be very, very highly skilled people that have a lot of time and are not waiting for a return on investment.

Also these groups tend to give away some false clues, so they’ll write some stuff in Chinese some stuff in Russian, to make it look as if it’s coming from somewhere else. They will write some poor English just to make you believe they’re not native speakers. So it’s very hard to know the attribution of the attack. When you’re investing three to six months of engineering time you expect some sort of return of investment as an attacker. But in this case it’s probably to get some sort of competitive advantage rather than money.

BN: Are attacks made easier by the COVID effect and the shift to remote working?

GC: I think it was about six years ago that Gartner predicted people will shift to zero trust networks where you cannot rely on or truly trust any sort of endpoint anymore. You have to refocus your energy and effort into finding stuff by looking into what the user does, what is the identity, what is being done with the checkout, and what he’s interested in?

We see both on premises and in the cloud some critical accounts being stolen and use of the Microsoft Azure configurations. We see a very clear shift COVID is a catalyst for this transformation and it’s happened already. I think, if I have one take away, outside of these very sophisticated attacks we have a very different group of hackers that try to target these assets and the identity of users. This kind of leverage of cloud based services like Azure Active Directory to get access to critical data will be happening more this year, no matter what you do. I expect to see the reuse of techniques by all sorts of groups.

BN: What sort of things can businesses be doing to ensure that they are as protected as they can be against this type of attack?

GC: What’s needed is a very tight control of what software is doing inside the organization so that the attacker won’t be able to get into critical areas. But there is a shift that needs to happen at the vendor level too, the user needs to be asking the vendor; what is the policy, how do you scan code and how do you ensure there is separation? That’s the first thing.

The second thing, whenever you get hit because eventually that will happen, right — just to give you a perspective in terms of numbers in 2020, that more than 40 percent of companies have had accounts stolen — you really have to think about what happened during the attack. It’s about the cloud identity and how do you detect many activities in the cloud.

The big problem is that there is a lack of protection capabilities in terms of the Azure AD application. This is really one of the things that companies need to research, how do they secure their cloud plan? Not only providing protection like two-factor authentication and so on, but also detection when something goes wrong. How would you know? I think this is really a massive gap today. It’s too new for most people to know that there is a threat and until they experience it it’s not going to be addressed.

Image Credit: Manczurov/Shutterstock

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2025 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2025 www.usscmc.com