enterprisesecuritymag

| | ENTERPRISE SECURITY8 MAY - 2022IN MY OPINIONIN MY OPINIONA year or so ago, the general public thought little about the term "supply chain." Today, it's all we hear about. Information Technology professionals have long monitored and managed supply chain logistics. In many cases, it is the first step in enterprise risk management and vulnerabilities assessment. For IT, safeguarding your supply chain often comes down to coding and/or testing for vulnerabilities.However, not all vulnerabilities are introduced through a failure in coding or testing. Some are deliberately introduced into software or firmware by malicious actors. The Kaseya ransomware event this past July demonstrates the danger of a sophisticated criminal attack of a central target in order to compromise a large number of organizations. Reflecting on Bad ActorsCybercriminals breached Kaseya, a global managed service provider, in order to inject malicious code into their Virtual System/Server Administrator (VSA) software. VSA is a platform used to manage customer networks, servers, and workstations. Managed service providers use this platform to administer their own infrastructure and the infrastructure of their customers. By compromising one company, the criminals had the potential to inject their ransomware into the environments of thousands of Kaseya customers. Supply chain attacks like this can bypass all the protective controls of an organization.Supply chain attacks are not new. When I was working as a systems administrator in 1995, my employer received over 100 new floppy disks, sealed in boxes of ten. All of these disks were infected with a boot sector virus. FIVE TIPS TO PREVENTING A SUPPLY CHAIN INCIDENTBy Paul Mocarski, Vice President And Chief Information Security Officer, Sammons Financial GroupFortunately, Norton Antivirus caught the virus and we avoided a significant, potentially devastating, incident. More recently, the U.S. government identified concerns with computer hardware coming from Chinese suppliers.In 2020, SolarWinds Orion software suffered a breach. The main targets of the SolarWinds breach were U.S. government agencies that include the Departments of Treasury, Homeland Security, Commerce, State, and Energy. Considering that more than 18,000 customers installed the malicious software, it's easy to see the potential for collateral damage in one of these attacks. Whether it is compromised software or hardware, what makes these attacks so dangerous is that they are coming from "trusted sources." If a trusted source like Microsoft were to be breached, IT and cybersecurity professionals have little recourse in preventing the introduction of malicious code into our environments. While supply chain attacks are difficult for companies to prevent, there are proven ways to minimize impact.Incident ResponseA documented and tested incident response plan is essential. All organizations ­ from health care to financial services ­ must have a response plan in place. The plan must be detailed and actionable in order to serve as a playbook on how to respond to these types of incidents. If you do not have an incident response plan in place, start now. Software and Hardware InventoriesSoftware and hardware inventories are foundational IT and security controls that are essential during response. These inventories can help to triage a potential event, and determine its scope and impact. As an example, a
< Page 7 | Page 9 >