Software supply chain attacks, or digital supply chain attacks, have become increasingly prevalent over the last couple of years. According to a study by KPMG, 73% of organizations have experienced at least one significant disruption from a third-party in the last three years.
What’s the best way to protect against potential software supply chain attacks? To get the answer, let’s define what those attacks are, how they happen, and how you can defend against them.
What is a software supply chain attack?
A software supply chain attack exploits vulnerabilities in your supply chain. Often these vulnerabilities are caused by software vendors with poor security postures. Because these vendors host or have access to sensitive systems and data, such as cloud providers, any breach of their digital infrastructure can have ripple effects across the supply chain.
Notable examples of software supply chain attacks include SolarWinds, Target, Home Depot, and NotPetya incidents.
How to prevent a software supply chain attack
Understanding your expanding attack surface and using tools and best practices to reduce exposure can reduce the risk of supply chain attacks.
Here are four ways to prevent and mitigate supply chain attacks.
1. Automate manual vendor assessment tasks
As you onboard more and more vendors, you’re probably finding that your vendor risk management (VRM) process is weighed down by manual, inefficient, and time-consuming processes. Automating your assessment process can alleviate the pressure.
Instead of wading through manual paper trails or relying on Outlook to remind you of critical deadlines or follow-up actions, automated VRM workflows take care of everything for you. For example, you can automate questionnaire distribution, trigger documentation requests based on vendor tiering, and get automatic reminders when it’s time to reassess a vendor.
You can also refer to a repository of previous assessments on common vendors that organizations share—think Google, AWS, Microsoft, even SolarWinds—so you’re not performing tedious reviews from scratch.
2. Validate responses with objective data and evidence of your vendors’ true security postures
Security questionnaires or assessments are important, but they only provide a point-in-time view of cyber risk.
As your vendors digitally transform, partner with new companies, and outsource functions, cyber risks are constantly emerging, requiring a more organic method of risk mitigation. Assessments are also subjective and create a bottleneck for security and risk assessment teams, potentially delaying the onboarding of business-critical vendors.
A better way to ensure third parties are within your risk tolerance is to validate their responses to security questionnaires using security ratings.
A security rating is a tool that lets you proactively assess and reduce risk across your external attack surface, including third parties. Using data scanning technology, ratings provide an outside-in view of your third parties’ digital ecosystems. Findings are presented in an easy-to-understand score, similar to a credit rating, with a scale from 250-900, with 250 being the lowest measure of security performance and 900 being the highest.
Using these findings, you may decide not to partner with a vendor with a low security rating, citing enhanced cyber risk. Or you may opt to work with a vendor with mid-level risk and consult with them on how to improve their security rating.