Supply chain attacks are increasingly common and increasingly disruptive, but organizations still struggle to defend against them properly.
In this episode of the ITPro Podcast, Jane and Ross are joined by Haydn Brooks, CEO of supply chain security firm Risk Ledger, to talk about what threats businesses are facing, what mitigation strategies could work well, and why cyber teams need to work together throughout the supply chain.
Highlights
“Most of the attacks that you find in the supply chain are untargeted. So it’s where you’ve had a threat actor launch a lot of attacks against a lot of different targets, they’ve breached a company without really knowing who that company is or was, and then they’ve basically passed that access on to somebody else, or they’ve gone on and leaked data or taken that company offline. And it’s not really like a targeted attack against someone else, it’s just that other companies who use that supply chain experience that as a supply chain attack, and very few of them are targeted. Where they are targeted, they are very hard to defend against because essentially, as the end target, I’m having to worry about an attack against somebody else, which I have no control over, being able to detect that and then being able to somehow respond to it as well.”
“I think actually the regulation has kind of followed the movement that we’ve seen within the industry rather than the other way around … we’re seeing a lot of these regulations also requiring companies to be either taking threat intelligence from others or sharing threat intelligence with others, as well as reporting incidents. So all of the regulation and the way security teams operate is moving in that direction of being more open, sharing more to benefit the wider industry.”
As regulation continues to catch up with industry practice, the message from security professionals is clear: defending against supply chain attacks requires collective action, open intelligence sharing, and a willingness to take responsibility for risks that originate beyond your own perimeter.