In light of the cyber attack targeting SolarWinds, security and risk professionals are working to identify instances of the Orion software within their organization -- including their broader partner ecosystem -- and reduce their exposure. How responsive have organizations been to the SolarWinds hack?
BitSight is leveraging our continuous collection of security performance and software usage data on 260,000 organizations across 24 sectors to track the prevalence of Orion -- including trojanized versions of the software -- and observe steps taken by organizations to reduce their exposure.
BitSight observes that many organizations with publicly exposed trojanized versions of Orion have acted over the last 3 days to remove those instances from the Internet or to patch them:
While these efforts may shut off further penetration, organizations once using trojanized versions of Orion may have been compromised since March; FireEye and Microsoft have suggested that a smaller number of organizations may have been impacted.
Organizations are also acting to remove their instances of SolarWinds Orion from the Internet, likely bringing the software inside the firewall to reduce potential exposure. The rate that organizations are removing these instances is significantly less than the trojanized version -- likely due to the fact that Orion is a critical piece of software for many organizations:
BitSight recommends that security and risk professionals immediately determine the prevalence of SolarWinds Orion within their organization and broader third party supply chain in order to mitigate the risk of exposure. Given the significance of this incident, BitSight recommends reporting any potential exposure to senior executives and the board as soon as possible. For additional information, please read our earlier Part 1 analysis of the SolarWinds breach.
The SolarWinds supply chain attack did more than just create cybersecurity problems for businesses and government agencies – it has had a strong impact on the mindset of CISOs. Already under stress, the incident further dispirited many...
The SolarWinds hack, discovered in late 2020 when FireEye announced it had been targeted through a third party vulnerability, has now become one of the most widespread and impactful supply chain attacks in history.
In light of the cyber attack targeting SolarWinds, security and risk professionals are working to identify instances of the Orion software within their organization -- including their broader partner ecosystem -- and reduce their...
© 2021 BitSight Technologies. All Rights Reserved. | Privacy Policy | Security | For Suppliers
Contact Us | BitSight Technologies | 111 Huntington Ave, Suite 2010, Boston, MA 02199 | +1-617-245-0469