In the six months since the SolarWinds supply chain attack there has been increased action in the cybersecurity breach world – and the bad actors aren’t letting up. This means that cybersecurity protection is more critical than ever.
But what lessons can be learned and what measures can organizations take to reduce risk? Earlier this year, Bitsight hosted a panel discussion on the future of supply chain cyber risk management in the wake of the SolarWinds attack. Below are key reflections and takeaways on ways forward.
The SolarWinds incident: The knowns and unknowns
Although the SolarWinds hack – considered one of the most significant attacks against a critical supply chain partner – is ongoing and will take years to comprehend, there are known indicators from which to draw some salient implications.
Early reports indicate that up to 18,000 customer networks were affected, although current data suggests that infected customers are fewer in number than initial reports. However, several security vendors have since disclosed SolarWinds-related incidents – an alarming development that the industry continues to watch.
“SolarWinds appears to have owned the ‘keys to the kingdom’ for many organizations, possessing the ability to update software, patch systems, manage virtualization systems, monitor networks, and more,” said Stephen Boyer, Chief Technology Officer and Co-Founder of Bitsight. Despite these capabilities, according to Bitsight data, very few organizations classified SolarWinds as a critical vendor – making it an ideal target for disseminating an attack.
Learning from failures
Understanding the failures that contributed to the SolarWinds hack is the first step to putting cybersecurity protection measures in place to prevent history from repeating itself.
In the months leading up to the incident the public and private sector failed to follow through on warnings that trusted supply chains presented grave risk. That was a key failure, and a significant contributing factor to the attack.
“Despite increasing awareness about supply chain security and the origins of code, organizations did not adequately assess the cybersecurity of companies from whom they accept software updates,” said Richard A. Clarke, Chairman of Good Harbor Security Risk Management.
“Signs that SolarWinds … was not taking cybersecurity seriously enough were everywhere. They appear to have had no Chief Information Security Officer and to have had a low security score from a reliable external evaluation product … Anyone doing serious supply chain risk assessments would have flagged the company as a risk.”
Tiering critical vendors is a must
The panel noted that organizations are already taking steps to better understand supply chain risk, but stressed the imperative of tiering critical vendors for greater scrutiny.