Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
  • Procurement Managers
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data / Password Recovery
        • File Integrity Management
        • Data Loss Prevention
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Developer Tools
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

View large
Bfore.AI Blog, Blog

How to limit the risks related to cyber attacks on the supply chain? | Bfore.AI

How to limit the risks related to cyber attacks on the supply chain?

This article was originally published by LOGON’s partner Bfore.AI. Click here to view the original article.

In today’s riskier and more connected environment, organizations must work closely with external partners to reduce vulnerabilities to cyber attackers.

Organizations are now embracing digital and analytics transformations like never before. Even those that didn’t expect to embark on major IT changes have had to adopt fully remote ways of working due to the COVID-19 pandemic. In rapidly changing business environments, companies are making many necessary IT changes on the fly, with security waivers and risk mitigation promissory bills issued almost as easily as ATO certifications. Cyber attackers and corporate spies are having a field day. They are taking advantage of this disruption by meeting in virtual rooms to engage in advanced persistent mapping of enterprise IT environments and associated vulnerabilities, including areas of those environments that rely on third-party support and capabilities.

With cyber attacks on the rise, business leaders in all industries are questioning the sources of their vulnerabilities, including the third parties and supply chains that make their operations possible. However, in the wake of high-profile events such as the recent Sunburst malware attack, chief information officers (CIOs) and chief information security officers (CISOs) are inundated with mixed messages. The Sunburst attack proved that enterprise environments and third-party capabilities are interpenetrated and indistinguishable. Attackers are opportunistic and adapt to whatever they can find, regardless of the source.

As a result, CIOs and CIOs are faced with a dilemma: they must now secure their own IT environments while ensuring the security of third-party elements of those environments. Third parties must be required to comply, both technically and in contractual risk mitigation elements, with security that supports business objectives. To ensure cooperation while providing sufficient protection for all parties, companies must therefore bring third parties into the inner circle of their security perimeters. At the same time, CIOs and CISOs are asked to keep a close eye on third parties. On the surface, the two mandates are opposite. But should they be? The short answer is no. The two positions, trust and oversight, don’t necessarily have to be opposed. In fact, they are most effective when contained in a reciprocal relationship.

The Sunburst attack reveals that certain types of attackers form large-scale alliances to achieve their threat-based goals. CIOs and CISOs, as well as their third-party colleagues, can and should do the same. They can work together to set the difficult goals and achieve the security excellence needed to meet the enterprise’s risk reduction requirements. Make no mistake, cyber threats are becoming increasingly perilous around the world. Attackers will have the upper hand until organizations are properly staffed and trained, acquiring the necessary capabilities and tools. This means working with their third parties to maintain a united security front.

CISOs and CIOs are aware of more gaps and weaknesses in enterprise cybersecurity than they would like. Moreover, in dealing with third parties, these weaknesses are often masked. But the Sunburst attack brought these points into sharp focus. The time has come to openly challenge the cybersecurity status quo. In the face of growing challenges, companies must partner with their third parties and demand the best in security.

 

I. Do the right analysis to better understand the risks

Recent cyberattacks have highlighted many cybersecurity challenges. One of the most important revelations is that enterprise security is as dependent on the global cyber ecosystem as it is on the actions of individual institutions. CIOs and CISOs are accustomed to managing their own operations and, ideally, having a strong influence on the behavior of the company’s employees and contractors.

The truth is that, no matter how big a company is, it is just one of millions of players on the global Internet. Its security posture depends on each of its employees, contractors, suppliers, resellers, cloud partners and sometimes even customers, but also on those same elements belonging to any other company, in its own market and in the wider global economy.

An enterprise has a lot to do, if only to keep all its direct users under control. To deal with the vulnerabilities generated throughout cyberspace, a common global security defense is needed. This means that companies must communicate openly with partners and rivals. Conversations between CISOs may seem awkward, but they are now necessary.

Companies must realistically examine their operations to determine the most likely forms of attack. New exposures resulting from acquisitions or sales of business units must be addressed. Attacks can come in the form of advanced persistent threats from nation-states, ransomware operations, cyber theft and industrial espionage, or malicious actions by individuals (internal or external threats).

The most viable enterprise security strategies must take into account the various dimensions of the threat environment, each of which is likely to change, sometimes dramatically, at any time:

  • The nature of the attackers and their most likely tactic
  • The nature of the current and impending enterprise security environment
  • The nature of the business, including acquisitions, operations, market conditions, partners and competitors.

A company that acquires an overseas asset to improve its market share and positioning may expose itself to threats it never previously considered. The due diligence team will need to review the acquired operation and all of its third parties to identify potential new threats and vulnerabilities. If the acquisition is a defense contractor, for example, the parent company could even be the target of a nation-state attack. Once the new acquisition’s systems are connected to the new parent’s corporate network, anything on them could be exposed to espionage or theft.

II. Recommendations for companies and outsourcers to improve third-party cybersecurity

Two good areas to start improving defenses are communication and third-party cybersecurity. As with any large-scale improvement, these issues do not have simple solutions. Many public institutions and private sector companies, however, have achieved good results by addressing these two areas in tandem. Cybersecurity “hygiene” – the care, rigor and thoroughness with which cyber defenses are maintained – is of paramount importance. To maintain a uniformly high level of cybersecurity hygiene across the enterprise, including for new acquisitions and third parties, transparency and open communication are necessary.

In collective ecosystems, companies can achieve both transparency and cybersecurity hygiene rigor through joint work. Attackers are often highly capable and motivated to develop strategic campaigns. To address these very real threats, we as defenders must be equally capable and motivated. The following recommendations are based on the knowledge and experiences of organizations that have successfully reduced third-party cyber risks.

 

A. Businesses that rely on third parties should be vigilant about the following

For companies that rely on third-party services and capabilities, such as software development and technology tools, consider taking the following steps and actions, as appropriate:

  • Apply role-based access controls to applications, databases, and infrastructure; remove single user accounts on highly privileged systems (such as network access systems). Wherever possible, operate under zero-trust expectations, if not actual zero-trust controls.
  • Apply risk-based multi-factor authentication (MFA) for all role-based privileged access.
  • Create use cases in the security and operations center to identify suspicious third-party use cases. These can be “impossible logins” – single user logins made in a short period of time from multiple geographically remote IP addresses – or “impossible tokens” (SAML tokens valid for 24 hours should be reported).
  • Create incident guides for third-party supply chain attack scenarios, and conduct tabletop exercises with major software vendors. Establish connections with points of contact (CISO to CISO connections are particularly effective), secure communication channels, and ensure all personnel are aware of incident handling procedures.
  • Mandate security training and certifications, service level agreements (SLAs) and escalation protocols in third-party contracts. Surprisingly, many third-party contracts for technology services and capabilities do not specify security requirements, SLAs or escalation procedures. Work with the company’s procurement functions to ensure that these elements are routinely included in any relevant vendor contract.
  • Evaluate Tier 2 (and beyond) suppliers. Many of these organizations are small and medium-sized businesses with limited security and compliance resources. Therefore, it is critical to strike the right balance between assessing their cybersecurity hygiene and overburdening them with information requests.
  • Adopt a third-party risk management framework that performs an algorithmic risk assessment of your vendors. Regularly assessing suppliers on a relative risk basis can help inform strategic sourcing, risk management and resource allocation decisions.

 

B. Third-party suppliers should apply the following best practices to protect their customers’ assets

To serve customers more securely, consider the following steps, as appropriate, for third-party vendors:

  • Conduct security scans on all products and transparently communicate the current security status, including vulnerabilities, to customers.
  • As soon as possible, identify and fix product vulnerabilities that could be exploited; communicate these activities to customers.
  • Use threat modeling during product development and share results with customers. Develop threat models that consider attack scenarios from within and without. Ensure that there is as much emphasis on scenarios covering legitimate denial of service as there is on those covering potentially compromised assets.
  • Expand existing code testing capabilities (general, static, and dynamic security testing) to include stress testing for code tampering, data integrity degradation, and business integration suitability.
  • Conduct red team exercises using software supply chain attack scenarios to test infrastructure security posture for current products. Adjust exercises to anticipate various supply chain infiltration attempts.

 

III. integrate legal risk as part of a comprehensive approach to cybersecurity

Legal avenues are another way to reduce business risk from third-party attacks. Organizations can (and should) contractually require third parties to meet the company’s cybersecurity standards. Third parties should also be contractually obligated to impose the same standards on any subcontractors that may affect the company’s data or systems.

Companies can also contractually require regular technical testing of third parties. This involves penetration testing and red team exercises, which many vendors do not yet allow. Yet to improve communications and cybersecurity in the enterprise ecosystem, these tests must be part of the routine. Enterprises need penetration testing and red teaming exercises for their own capabilities to ensure they are compliant with security requirements; the same approach should be required of third parties.

A new era of cybersecurity has been defined by more sophisticated cyberattacks, the widespread adoption of digital and analytic transformations, and changes in the workplace, particularly work-from-home arrangements. These conditions challenge existing third-party and supply chain security management procedures.

A radical new approach is needed that emphasizes strong communication and full alignment of third-party cyber protection with business requirements and standards. This new approach goes beyond meeting compliance requirements; its goal is to significantly reduce risk across the enterprise. The change is significant but necessary because the security environment, as CIOs and CISOs well know, has become much more dangerous.


Prevent the next Cyber Threat

Bfore.AI patented AI technology combined with hyperscale observation infrastructure and modern APIs augment our customers security postures with Predictions.

Solution Highlight

Discover Predictive Cyber-Security

Book a live demo with our specialist to discover how Bfore.AI helps organization fight cyber threats with their patented technology.

Book a demo
Contact Us Today

FOLLOW US ON

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter
  • YouTube
Read Next:
Application Security BlogArtificial IntelligenceBlogLOGON Blog
AI-Augmented Penetration Testing: Meeting the Scale Challenge
Application Security BlogArtificial IntelligenceBlogIT Management BlogLOGON Blog
The First Autonomous AI Cyber Attack is Here: Is Your Enterprise Ready?
Application Security BlogBlogLOGON Blog
Shift Left, Verify Right: The Blueprint for Modern Application Security Across Asia

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...

Fill in the form below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Watch On-demand Webinar

  • This field is for validation purposes and should be left unchanged.

Get Your Free UserLock Trial

  • This field is for validation purposes and should be left unchanged.

Download Your Free Trial 10-Day Trial Today

  • Downloading and evaluating Smart Package Studio is quick and easy
  • Includes a short introductory guide that suggests smart features to try
  • Access the full functionality of Smart Package Studio during the trial
  • This field is for validation purposes and should be left unchanged.

Request for Priority Support with our support team

  • This field is for validation purposes and should be left unchanged.
  • Drop files here or
    Max. file size: 30 MB.

    Get Free Assessment of your Web Asset

    Request a free non-intrusive security assessment of your website. Get a report with an overview of client-side security risks.

    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form

    Recommend a Topic

    • This field is for validation purposes and should be left unchanged.

    Partner with Us on the next episode

    • This field is for validation purposes and should be left unchanged.

    Watch On-demand Webinar

    • This field is for validation purposes and should be left unchanged.
    Start PreCrime Network for Free

    Oops! We could not locate your form.

    Book a Free Demo Today

    Get Your Free Trial

    Oops! We could not locate your form.

    Get Your Free Trial
    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form
    • This field is hidden when viewing the form
    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form