The SolarWinds supply chain attack discovered in late 2020 was a wakeup call for security managers across all industries. The hack is shaping up to be one of the most impactful attacks against a critical supply chain partner in history.
It’s no surprise then that security and risk leaders are taking a closer look at hidden cyber security threats and vulnerabilities – both within their own organizations and across their vendor and partner ecosystems – and focusing more than ever on mitigating risk exposure. In the days following the SolarWinds hack, Bitsight observed that 71% of organizations with publicly exposed, trojanized versions of the SolarWinds Orion platform acted to patch or remove those instances from their network.
Despite this quick remediation, the breach remains a concerning example of just how vulnerable organizations are to malicious activity in today’s ever-evolving risk landscape.
Major cyber events like the SolarWinds supply chain attack put renewed focus on the importance of robust cybersecurity programs. These hacks shouldn’t distract security leaders from paying attention to common vulnerabilities and exposures (CVEs) in their digital ecosystem, because these more common vulnerabilities can open doors to hackers wanting to hide on their network long-term.