Cyber Supply-Chain Attacks

I recently attended a webinar sponsored by the FBI‘s InfraGard program, which I am a member of.  I wanted to share some useful information from this webinar.


Here is some thought provoking informatin regarding cyber supply-chain risks:

  1. 50% of data breaches are attributable to a 3rd party vendor.

  2. 83% of organizations do nothing to manage third party risk.

  3. 80% of data breaches are discovered by someone outside the breached organization.

So, what are some of the things you can do to mitigate your risk?

  1. Assess the risk before you allow a vendor access to your network.

  2. Understand your level of risk.  Is a large company a large risk and a small company a smaller risk?  Not necessarily.

  3. Perform an independent security assessment to understand your level of risk.  This assessment should include, at minimum:

  4. Network/Perimeter Scan.

  5. DNS Resilience.

  6. Email Security.

  7. Web Application Security.

  8. Hacker Threat Analysis.

  9. Breach Metrics

  10. Patching Candence.

Keep in mind that doing an assessment is just the start.  It’s important to have the tools and processes in place to manage the assessment results.

If you life in a regulated world, you have even more to worry about.  If you take credit cards, you need to comply with PCI 12.8.  If you are in healthcare, you are governed by HIPAA and if you do business in or have employees who are residents of the EU, you much comply with GDPR.

It’s not a matter of if you will be at risk, it’s a matter of when.  You need to have a plan for dealing with a breach caused by a vendor.  Understand your communication and reporting responsibilities and develop your plan now, not after you have an incident.

Share this:

  1. Email

  2. Print

  1. Tweet