The SolarWinds supply chain attack did more than just create cybersecurity problems for businesses and government agencies – it has had a strong impact on the mindset of CISOs. Already under stress, the incident further dispirited many CISOs who continually face escalating cyber threats. The SolarWinds hack was the latest – and biggest – shot across the bow.
Stopping every attack is unrealistic but doing the same thing repeatedly and expecting a different result isn’t going to cut it anymore. Despite years of heavy investment in security controls, organizations aren’t seeing the level of cybersecurity hygiene they need.
If CISOs are to combat emerging supply chain cyber security threats and vulnerabilities, a new approach is needed. It’s time for CISOs to capitalize on their authority. Rather than throw up their arms and say there’s not much more they can do to reduce risk, let’s look at four things CISOs can do to transform supply chain cyber security risk management.
1. Use objective data to verify third-party security hygiene during the onboarding process
To ensure that third parties adhere to a company’s security standards, vendors must be properly vetted during the onboarding process. This typically involves point-in-time security questionnaires or assessments. The problem with this approach is that the input is subjective and, without an extensive audit of the third-party’s security program, unverifiable.
A better approach is to use a risk assessment tool, like Bitsight Security Ratings. Security ratings provide immediate, up-to-date, and objective data about a third-party’s security posture. These ratings, which range from 250 to 900 with a higher score suggesting a stronger security posture, empower CISOs to compare vendors’ security profiles side-by-side and make decisions based on risk.
With this data in hand, security managers can prioritize which vendors need the most attention prior to onboarding, such as a more in-depth cyber security assessment. The result is a more accurate real-time picture of cyber risk than can be achieved by completing costly risk assessments, penetration tests, or vulnerability scans.