Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

The SolarWinds Compromise and the Strategic Challenge of the Information and Communications Technology Supply Chain

usscmc by usscmc
December 24, 2020
The SolarWinds Compromise and the Strategic Challenge of the Information and Communications Technology Supply Chain
Share on FacebookShare on Twitter

Erica D. Borghard is a senior fellow with the New American Engagement Center at the Scowcroft Center for Strategy and Security at the Atlantic Council.

The compromise of the IT company, SolarWinds, and the breaches of multiple U.S. government agencies, including the Homeland Security, Treasury, and Commerce departments, could be the most significant cyber breach targeting the U.S. government in recent years. The extensive operation is reportedly the work of APT29 (also known as Cozy Bear), which is linked to Russian foreign intelligence. Currently, U.S. government officials are working to assess the scope of the operation, contain the damage, and ascertain the intent behind it. This incident raises two important implications for the strategic issue of the security of the supply chain for information and communications technology (ICT).

More on:

Cybersecurity

Russia

China

Supply Chains

First, much of the conversation around the ICT supply chain has been dominated by the U.S.-China [PDF] rivalry and, specifically, the purported competition between Chinese and Western technology firms over their relative global market share. There is considerable hype about China’s pursuit of dominance in this arena including concerns about Made in China 2025, China Standards 2035, and China’s Military-Civil Fusion strategy. The Trump administration has enacted a number of measures aimed at curbing China’s role in the ICT supply chain, including the May 2019 Executive Order that aimed to ban Huawei and ZTE from the U.S. market. Indeed, in an interview on Monday, Secretary of State Mike Pompeo responded to a question about the SolarWinds incident by calling attention to China, rather than Russia: “We see this even more strongly from the Chinese Communist Party.”

Net Politics

CFR experts investigate the impact of information and communication technologies on security, privacy, and international affairs. 2-4 times weekly.

The reality is that China is only one aspect of the challenge of supply chain security. In the case of SolarWinds—an American IT company—Russia seemingly compromised the ICT supply chain through a widely-used vendor. This incident had nothing to do with China’s position in the global supply chain. Instead, the SolarWinds case illuminates the issue of third-party risk. Third party firms, like SolarWinds, have become extraordinarily valuable, high-reward targets because they end up having a high concentration of data, access, and inroads into a number of entities. A threat actor targeting this kind of critical node in the supply chain could end up gaining access to a wide range of targets, with cascading implications.

Second, in light of the strategic significance of the ICT supply chain—the fact that nearly every aspect of modern economies and societies rests on complex global networks comprised of raw materials, hardware, and software—the United States needs a coherent and comprehensive national strategy. This was a core finding of the U.S. Cyberspace Solarium Commission. In October 2020, as a follow-on to its March 2020 report [PDF], the Commission released a white paper [PDF] on building a trusted ICT supply chain. It calls for, among other things, identifying the critical raw materials, hardware, and software the United States needs to secure, stimulating domestic investment, and working internationally to build trusted private sector partners. 

Securing the ICT supply chain will be a significant undertaking, requiring large-scale investment and dedicated attention over multiple administrations. Moreover, it is nearly impossible to secure every link in the supply chain. The U.S. should therefore expect that there will continue to be critical supply chain compromises. Moreover, supply chain cybersecurity is only one element of supply chain risk. Adversaries will seek to leverage U.S. dependence on materials and technologies as bargaining chips during a crisis or as part of coercive diplomacy.

This means the ICT supply chain issue should not only be framed in terms of security, but also in terms of resilience. Resilience encompasses the ability to anticipate, withstand, rapidly restore core functions and services, and evolve as an organization in the wake of a disruptive event. A resilience-based approach assumes that some compromises and disruptions are impossible to deter or prevent and, therefore, organizations should invest in being better prepared when these instances occur.

More on:

Cybersecurity

Russia

China

Supply Chains

A risk-based approach to cultivating the resilience of the ICT supply chain would include a number of elements. It would require systemically identifying and prioritizing critical assets, capabilities, functions, and dependencies. The United States needs better visibility into the supply-chain and to map dependencies across it to understand how an incursion or disruptive event in one area could have broader implications. For example, while the SolarWinds situation is still evolving, it’s not clear that the U.S. government even knows all of the departments and agencies that use SolarWinds. Prioritization should also drive decision-making around areas to invest in redundancies. A successful resilience approach would also rest on strategic intelligence capabilities to improve anticipation of and proactive response to adversary activity. This would include developing a better understanding of the threat environment, including evolving adversary intent, capabilities, and objectives; their intelligence objectives and collection requirements; and ascertaining likely avenues and methods of incursion.

Digital and Cyberspace Update

Digital and Cyberspace Policy program updates on cybersecurity, digital trade, internet governance, and online privacy. Bimonthly.

As the SolarWinds incident illustrates, cultivating the security and resilience of the ICT supply chain is an enduring and vexing challenge—one that will have strategic and economic implications for decades to come.

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2025 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2025 www.usscmc.com