Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

Reports had warned about supply chain hacks

usscmc by usscmc
January 12, 2021
Reports had warned about supply chain hacks
Share on FacebookShare on Twitter

WASHINGTON – Twice in the last four years, the national security community warned that hacks through IT suppliers posed grave threats to defense and intelligence agencies. Last month, those warnings proved prescient after suspected Russian hackers infiltrated federal agencies through a contractor’s software.

While intelligence officials said Jan. 5 the hack is an espionage campaign, confirming Russia as the likely source, the two recent reports alerted the community that hackers could disrupt weapons systems by attacking through the supply chain. Those reports suggested the Pentagon must quickly develop methods to reduce risk from its suppliers.

But the steps the department took to strengthen contractor cybersecurity, including its Cybersecurity Maturity Model Certification risk audits, did not come in time to prevent breaches of some DoD offices that media reports have disclosed. The Pentagon says its investigation, expected to take significant time, has not turned up signs so far that hackers entered through SolarWinds software that was compromised at various federal offices and large companies.

Despite the warnings and a budding audit system, government agencies had difficulty fending off the latest intrusion. The problem was not a case of identifying the Pentagon’s vulnerabilities. Instead, the difficulty came in part because military leaders haven’t figured out a comprehensive plan to gauge and eliminate risks from contractors, experts said. The solution isn’t simple.

The U.S. Department of Defense faces a tough challenge assessing its networks after suspected Russian hackers may have had access for months. (Aislan13/Getty Images)

Now, some of the department’s former IT leaders and industry officials suggest that the DoD has to do more with the tools it has, as well as seek new ones. For example, lawmakers recently told the Pentagon in the annual defense policy law to explore the possibility of a threat-hunting program with the defense industrial base.

“It’s been a focus area for us for some time,” said Jan Tighe, former commander of 10th Fleet/Fleet Cyber Command and deputy chief of naval operations for information warfare. “I think both the public and the private side have not completely solved for how we’re going to deal with hardening our supply chain.”

The recent breach allowed hackers to access networks and move laterally, posing a heightened threat if network connections don’t have comprehensive security controls to prevent burrowing into sensitive systems. To mitigate supply chain risk, experts told C4ISRNET that the Department of Defense and other government agencies need greater insight into potential risks from vendors and stronger tools to defend against these types of attacks.

Know all the coolest acronyms

Sign up for the C4ISRNET newsletter about future battlefield technologies.

By giving us your email, you are opting in to the C4ISRNET Daily Brief.

C4ISRNET Logo

As the DoD relies more on third-party suppliers for many IT needs and supply chain attacks are likely to continue to increase, the need for fixes increases. The New York Times reported in early January that Russia “exploited multiple layers of the supply chain” to access more networks than previously thought.

“Even if you’re buying things as a service, it doesn’t excuse your responsibility in security and assurance,” said Jennifer Bisceglie, CEO of Interos, a supply chain risk management company. “You will still remain responsible for the risk posture in your operation. And so what are you doing about that, especially if you are sharing or outsourcing the responsibility for a service? What are you doing to make sure that that service doesn’t introduce harm or risk in a way that you weren’t watching for?”

For several years, government commissions have warned about the risk of supply chain attacks. In 2017, the Defense Science Board warned that attacks through software could disrupt weapons systems. In 2019, the National Counterintelligence and Security Center advised that malicious actors were increasingly using the avenue to breach networks.

“Software supply chain attacks are particularly bothersome and insidious because they violate the basic and assumed trust between software provider and consumer,” the NCSC report stated.

Two years later, what does persistent engagement and defend forward mean? (Patrick Semansky/AP)

One challenge for the department is that risks differ for each vendor, meaning there’s no one-size-fits-all solution. To improve visibility, the department should require vendors to assess and document any risks before it awards contracts, experts suggest. That would give the department more information to make purchasing decisions and to review if a compromise happens.

“It is possible for every vendor to know something about the risks that are present in its supply chain,” said Robert Metzger, a member of the Defense Science Board’s 2017 study on supply chain vulnerabilities. He added, “This idea that we expect each supplier to assess and describe their own supply chain risks and to present their plans for mitigating that risk, that’s a sound idea, I believe, even if it is a new and potentially difficult burden.”

For a variety of reasons, including a shortage of IT and cybersecurity talent and cost savings, the government relies on vendors for IT needs. But the way in which the companies are interconnected poses further unknowns for managing risks.

“We stop at understanding who our supplier is, and we don’t really give a thought to who their customers are, who are their suppliers, where they’re reliant around the world, what countries that they’re relying on, what other companies are relying on,” Bisceglie said.

The Cybersecurity Maturity Model Certification, an audit system to evaluate the strength of contractors’ cybersecurity, will improve the DoD’s knowledge of its suppliers but focuses more on cybersecurity on an organization’s perimeter. CMMC is a solid foundation to build on, Metzger said.

“We will need to examine carefully what attributes of the CMMC control set should be emphasized or even changed, in order to address this kind of supply chain delivered threat,” he said.

What will it take to be secure?

Advanced persistent threats, like Russian hackers, will always have an interest in the DoD. The difficulty for the department is that many suppliers don’t have the skillsets or resources to defend against nation-state hackers.

“It’s a really tough problem to figure out how you’re going to design resiliency against those kinds of attacks,” said retired Rear Adm. Danelle Barrett, former deputy Navy CIO and cybersecurity division director.

However, Barrett said that the suppliers and the department can still improve safeguards against advanced actors through consistent penetration testing, threat modeling and monitoring, as well as establishing a cybersecurity baseline, the posture when the network is fully secured.

Other steps could include increased behavioral analysis on networks to look for people acting unusually and a more collective approach to network defense by the government.

Photo credit: Petty Officer 2nd Class James K. Lee/Defense Department

“If you look across multiple networks and correlate anomalous network behavior across the whole government, you might have seen this if you could see across everybody and can sort between what is just anomalous and what is actually malicious,” Tighe said. “If you see anomalous that all looks the same across the whole of government … and potentially even with the private sector, I think that you increase your ability, you use the power of a collective defense to our advantage.”

Today the government doesn’t have the real-time ability to search across networks for early warning signs, Tighe added. However, the 2021 National Defense Authorization Act contains several measures that could eventually improve supply chain security.

Besides a feasibility study on a defense industrial base threat-hunting program, the law directs the department to assess possible programs to share information with the defense industrial base and place commercial off-the-shelf sensors on contractors’ public-facing attack surfaces. The law designates the department’s principal cyber adviser as the top official responsible for DIB cybersecurity issues.

Even with the best visibility into supply chain risks, advanced hackers will still search for new openings, making teamwork key.

“The positive lesson that should be taken from SolarWinds is that supply chain risk is everybody’s problem,” Metzger said. “It is a very large and complex problem, and it will not accommodate anything like a business-as-usual approach.”

Mark Pomerleau contributed to this report.

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2025 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2025 www.usscmc.com