Date: 2021-10-12

How to protect your organization from security threats across your supply chain

Defending your organization from cyberattacks that directly target you is difficult enough. But protecting yourself against attacks that hit you through your supply chain is even more of a challenge. How do you combat something over which you seemingly have little or no control? A report by cybersecurity provider BlueVoyant looks at supply chain security breaches and offers tips on how to prevent them. Released on Tuesday, the report titled Managing Cyber Risk Across the Extended Vendor Ecosystem is based on a survey of 1,200 CIOs, CISOs and chief procurement officers in large organizations throughout the U.S., the U.K., Canada, Germany, the Netherlands and Singapore. Commissioned by BlueVoyant and conducted by research firm Opinion Matters, the survey found that 97% of the respondents were hurt by a security breach that took place in their supply chain. Further, some 93% of those surveyed said their companies suffered a security breach themselves due to a weakness in a supply chain partner or third-party vendor. As a result, supply chain threats have received a renewed focus. Last year, 31% of the respondents said that supply chain and third-party risks were not a priority. This year, only 13% of those surveyed said that this type of risk was not on their radar. But a greater focus on supply chain threats doesn't automatically make them easier to detect. Among the respondents, 38% said they have had no way of knowing when or if a security issue occurs with a third-party vendor. Some 41% revealed that if they had discovered an issue and informed their supplier, they would be unable to confirm whether or not the problem had been resolved. This year has seen a number of cyberattacks and exploits that affected supply chain partners. A vulnerability in Microsoft Exchange exploited by a China-based group impacted thousands of companies with Exchange servers. The ransomware attack against Colonial Pipeline hurt fuel suppliers across the East Coast. And the ransomware incident against enterprise IT firm Kaseya trickled through to more than 1,000 organizations. To help you better manage and respond to supply chain threats, BlueVoyant offered the following recommendations: Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered Tuesdays and Thursdays