Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

Supply Chain Cyber-Dangers for Small Government

usscmc by usscmc
February 5, 2021
Supply Chain Cyber-Dangers for Small Government
Share on FacebookShare on Twitter


By now, everyone on the planet has probably heard about the massive supply chain breach that occurred when network management software from SolarWinds had malware inserted into a trusted software update. This attack has exposed over 18,000 of their customers who used the affected software, which includes Federal government agencies like the Commerce Department and Homeland Security to potential breaches.

The SolarWinds supply chain hack of late 2020 has rocked large government agencies and Fortune 500 companies to their core. It will be many years before all the effects of this mega-hack become known and cleaning up and securing things fully will take even longer. Many state and local governments might be hoping they were not targeted, as the Russian state hackers are generally not interested in small fish. And small cities and towns don’t tend to use the more complex enterprise-grade software, like SolarWinds, to manage their networks. However, just because these organizations tend to be small and unsophisticated, IT-wise, it doesn’t mean they aren’t susceptible to supply chain dangers of their own.

Small governments beware

Being small does have some advantages. You don’t tend to attract the attention of the serious, well-funded hacking groups like the Russian SVR intelligence group that was allegedly behind the SolarWinds hack. But they are plenty attractive to criminal hacking gangs like the ones who took down 22 Texas cities simultaneously in what has been called the first “mass ransomware” attack in 2019. They know that residents of even the smallest towns depend on critical government services such as law enforcement, court services, and utilities. And as evidenced by the many small towns and cities that have paid handsome ransoms to get their data and services back online after successful ransomware attacks, it can be highly profitable for hackers.

And national information security standards such as the Criminal Justice Information Standard (CJIS) still apply to data handling by these local organizations, so it’s not as if they’re exempt from needing good cybersecurity in place. And for good reason. Hacking into a small, local law enforcement department might allow a hacker to access sensitive federal government databases at agencies like the FBI. And even the smallest town might still have an EU citizen living in it, so international data privacy standards like GDPR would still apply to them.

Manage your IT properly, whether it’s in-house or a vendor

While they may have many of the requirements of larger governments, they do not have the staff or budgets to handle them like the big guys. Often these small entities have very small IT departments with no dedicated security personnel. Or in many cases, they may have no in-house IT staff, outsourcing it to Managed Service Providers (MSPs). Sophisticated hacking organizations know this and have targeted MSPs in recent years as a “force multiplier for their efforts. The “hack once, breach many” strategy has been used to great effect, notably on the Texas city hack mentioned above.

Also, smaller government organizations are just as susceptible to supply chain attacks on more mainstream software that everybody uses. Microsoft’s source code was accessed as an offshoot of the SolarWinds attacks, and while no code was supposed tampered with, it is only a matter of time before this happens (or may have already happened and we just don’t know). They also use many of the same IoT devices that big cities do, like IoT cameras, door locks, and other common IoT tech.

Many millions of devices were affected in the exploits discovered in Treck IP software and smaller IT departments have a hard time keeping up with the patches that are issued for these holes. Small governments are also more likely to use smaller providers of software that do specific functions such as utility billing. These software providers are often “mom and pop” shops, which can include poor security practices and infrequent patching. And even when patches are available, many small towns have to rely on their service providers to stay on top of breaking developments and get their systems patched. Suffice it to say, that small government organizations are at least as at risk if not more, to supply chain attacks, given the combination of the ubiquity of vulnerable software and the lack of resources to properly secure it.

How to protect yourself from supply chain risks

So, what should smaller government entities do to protect themselves from supply chain cybersecurity risk? Well first of all, practicing good third-party risk management goes a long way. Even with limited resources, some minimal vetting and monitoring of vendors can be done. And buying from reputable technology providers who can prove their security postures protect you quite a bit even though it’s no silver bullet.

If you are going to use a managed services provider for some or all of your IT functions, make sure those companies have good security bonafide. Are they compliant with all the standards you have to meet? Do they have sufficient insurance to cover your costs if you are hit with ransomware as a result of a security failure on their part? A minimum of $10 million is recommended even for the smallest organization.

Finally, you can leverage some of the protections that the larger governmental organizations have with their complicated purchasing requirements and more sophisticated vetting by using the same products and services that they contract with. Sometimes you can even save money by purchasing under a blanket discount program. However, sometimes these larger solutions are not designed for small government and can be price prohibitive. And as the SolarWinds debacle shows, even if a company is a large, well-known technology provider, it is not enough to ensure the security of a purchased product.

Regardless, state and local governments are going to have to up their game, with partnerships, cooperatives, and information sharing along with evolving their cybersecurity programs as best they can with their limited budgets or end up as roadkill on the information superhighway. The bad guys are getting better all the time and your citizens and taxpayers will demand that you do the same.

Looking for the latest gov tech news as it happens? Subscribe to GT newsletters.

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2024 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2024 www.usscmc.com