Supply Chain Vulnerability
- •
What it is
- •
a weakness introduced anywhere along a product or service's supply chain — raw materials, suppliers, manufacturers, distributors — that an attacker can exploit without the victim's suspicion, since organizations tend to trust their suppliers
- •
- •
Risk categories
- •
service providers — third parties with access to internal systems (network, utility, cleaning, payroll, cloud services, etc.); ongoing security audits of providers should be part of the contract
- •
hardware providers — can you trust your new server/router/switch/firewall? use a small, tightly controlled supplier base
- •
software providers — trust is confirmed via a Digital Signature at install time; open source software is not immune to compromise either
- •
- •
Real-world examples
- •
Target Corp. breach (November 2013) — attackers stole VPN credentials from an HVAC vendor via a phishing email, then used Target's own network to infect cash registers at 1,800 stores, resulting in 40 million stolen credit cards
- •
July 2022 — DHS arrested a reseller CEO who had sold over $1 billion of counterfeit Cisco networking products since 2013
- •
SolarWinds supply chain attack — SolarWinds Orion software updates were compromised between March–June 2020 (not discovered until December 2020), affecting roughly 18,000 of SolarWinds' 300,000 customers, including Microsoft, Cisco, Intel, and multiple US federal agencies
- •
- •
Related
- •