Cyberattacks frequently make headlines, but one threat increasingly challenging security leaders — especially following the Log4j and SolarWinds incidents — is zero-day vulnerabilities. What is a zero day vulnerability and why is it relevant for third-party risk management?
What is a zero-day vulnerability?
A zero day (also referred to as 0-day) is a software vulnerability either unknown to its developer, or known and without a patch to fix it. The name derives from the fact that developers or vendors have "zero days" to fix the flaw before it is actively exploited.
Until the vulnerability is mitigated, attackers can use it to compromise data or additional systems, including operating systems, web browsers, office applications, open-source components, hardware, firmware, or Internet of Things (IoT) devices.
Zero day: vulnerability vs. exploit vs. attack
The term is often used along with words like vulnerability, exploit, and attack, so it’s helpful to understand the difference:
- Zero-day vulnerability: a software flaw that attackers discover before the vendor does. Because no patch exists yet, attacks exploiting it are likely to succeed.
- Zero-day exploit: the code that allows attackers to leverage the vulnerable piece of software to compromise systems; exploits are usually sold on the dark web.
- Zero-day attack: the use of a zero day exploit to disrupt, cause damage to, or steal data from a vulnerable system.
How to protect against zero-day attacks
Software is written by humans, and humans are fallible. Developers create software every day, but unbeknownst to them, it may contain vulnerabilities. This makes zero-day attacks inevitable, as attackers often spot those vulnerabilities before the developers detect and act on them.
So how can you minimize risk in your organization and across your digital supply chain?
Bitsight is the only third-party monitoring solution which offers Dark Web Intelligence for Supply Chains to detect early signs of real-world targeting and exposure across your vendor ecosystem beyond what static scores can reveal.
Basic zero day protection measures include:
- Keeping all software and operating systems up to date, installing patches as soon as they become available. Security patches often cover newly identified vulnerabilities, and poor patching cadence has been proven to correlate with risk.
- Enforcing security standards as part of your vendor risk assessments and due diligence process, and updating your requirements as needed after a zero day is discovered.
- Performing continuous monitoring and reassessment of your vendors as opposed to point-in-time calendar evaluations.
- Using a layered defense strategy, combining antivirus, firewall, and other security solutions, with security mechanisms like zero trust or MFA.
- Educating users on cybersecurity best practices, especially amid flexible work arrangements, as many zero-day attacks capitalize on human error.
Organizations must establish a comprehensive and agile TPRM strategy that incorporates continuous monitoring, timely vendor risk assessments, and rapid response mechanisms. Effective integration of threat intelligence within TPRM frameworks allows organizations to swiftly identify potential third-party exposures and initiate immediate mitigation actions, thus significantly reducing the window of risk associated with zero-day vulnerabilities.
Collaboration and transparent communication with third-party vendors are essential. Establishing clear expectations for vendors to promptly report their vulnerability status and remediation plans helps organizations better manage exposure. Moreover, conducting regular scenario-based exercises with critical third-party vendors enhances preparedness and ensures that all stakeholders clearly understand their roles and responsibilities during a zero-day incident.