Cyber Expert Warned SolarWinds In 2017

The SolarWinds breach is much bigger than first believed. The initial estimates were that Russia sent its hacking probes only into a few dozen of the 18,000 government and private networks. 

But after Microsoft dug deeper into the attacks it now appears Russia exploited multiple layers of the supply chain to gain access to as many as 250 networks.

A cyber security expert, Ian Thornton-Trump who worked at SolarWinds, says he warned the management about the possible serious hacking attacks if the company had not improved its internal security. 

Thornton-Trump now works as the chief information security officer at Cyjax and he says he had warned SolarWinds that it was not taking security seriously enough in 2017 when he worked as an adviser for the company. He later resigned from the company in May 2017 after giving a PowerPoint presentation with at least three SolarWinds executives raising his concerns.

In December 2020 a serious cyber attack led by state-backed Russian hackers affected more than 250 US federal agencies and private companies.  The hackers got into government and private networks by inserting malicious code into SolarWinds' premier software product, Orion.  And Solar Winds is believed to be one of several supply chain vendors Russia used in their hacking attacks. 

Current and former employees of SolarWinds suggest it was slow to make security a priority, even as its software was adopted by America’s premier cybersecurity company and federal agencies.

Employees say that this problem arose under Mr. Thompson, an accountant by training and a former CFO as he examined every part of the business for cost savings. Because of Thompson’s methods many security practices were lost because of their expense. His approach helped almost triple SolarWinds’ annual profit margins to more than $453 million in 2019 from $152 million in 2010, placing security at greater risk.

SolarWinds moved much of its engineering to satellite offices in the Czech Republic, Poland and Belarus, where engineers had broad access to the Orion network management software that Russia’s agents compromised.

Other former and current SolarWinds staffers say the company was slow to prioritise security, even when its software was adopted by top cybersecurity companies and federal agencies. SolarWinds only took action on security in 2017 under the threat of penalty from a new European privacy law, when it hired its first chief information officer and brought in a vice president of security architecture.  

While the motive for the attacks is not known, some believe it is a Russia effort to intimidate Washington just weeks before President-elect Biden's inauguration, to gain leverage against the US before forthcoming nuclear arms talks.

Intelligence officials say It could be months, years even, before they understand the breadth of the hacking. Jake Williams, a former hacker for the US National Security Agency (NSA) now president of cyber security firm Rendition Infosec, told reporters that technology companies such as SolarWinds that build and produce computer code often “don’t do security well”.

SolarWinds gained a foothold in the government marketplace many years ago because it was regarded as “idiot proof”, and was the first software of its kind, said Williams. “Orion is to network management systems what Kleenex is to tissue,” he said. “Other products are laughably complex and bad by comparison. It was the first actually easy-to-use network management system, and took off like wildfire as a result.”

Since it was founded in 1999, SolarWinds has  been awarded contracts with the US government worth more than US$230 million. Its software is used by many federal government agencies. The US military, the FBI, the Secret Service, the National Nuclear Security Administration, the Veterans Affairs. the Department of Homeland Security and others.

Bloomberg:     Newsweek:       New York Times:    SCMP:     Daily Mail

You Might Also Read:

The SolarWinds Hack Can Directly Affect Industrial Control Systems:

 

 

« Julian Assange Will Not Face Trial In The US - Yet
Social Media Platforms Block Donald Trump »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Softtek

Softtek

Softtek helps its clients to gain a competitive edge by implementing digital solutions that propel their business strategies.

Fraunhofer Institute for Secure Information Technology (SIT)

Fraunhofer Institute for Secure Information Technology (SIT)

Fraunhofer SIT is a research centre specialising in all areas of IT security.

Center for Cyber Safety and Education

Center for Cyber Safety and Education

The Center for Cyber Safety and Education works to ensure that people across the globe have a positive and safe experience online through our educational programs, scholarships, and research.

ArcusTeam

ArcusTeam

ArcusTeam is at the forefront of the firmware and applications security industry, with a mission to increase the level of security on all IoT devices and applications.

Swiss Accreditation Service (SAS)

Swiss Accreditation Service (SAS)

SAS is the national accreditation body for Switzerland. The directory of members provides details of organisations offering certification services for ISO 27001.

iSecurity Consulting

iSecurity Consulting

iSecurity delivers a complete lifecycle of digital protection services across the globe for public and private sector clients.

Absa Cybersecurity Academy

Absa Cybersecurity Academy

Absa Cybersecurity Academy is an initiative aimed at empowering marginalised South African youths to become certified cybersecurity specialists.

Softcat

Softcat

Softcat offer a broad portfolio of IT services and solutions covering Hybrid Infrastructure, Cyber Security, Digital Workspace and IT Intelligence.

Tego Cyber

Tego Cyber

Tego Cyber delivers a state-of-the-art threat intelligence platform that helps enterprises deploy the proper resolution to an identified threat before the enterprise is compromised.

Cyber Lockout

Cyber Lockout

Comprehensive ransomware insurance and preventative cybersecurity technology solution, working together to help protect businesses 24/7/365.

Stacklet

Stacklet

Stacklet provides cloud governance as code platform that accelerates how Global 2000 manages its security, asset visibility, operations, and cost optimization policies in the cloud.

NorthStar

NorthStar

NorthStar provide the visibility needed to track and reduce risk through risk-based vulnerability management and vulnerability exploit prediction.

Catalyst Campus For Technology & Innovation

Catalyst Campus For Technology & Innovation

Catalyst Campus is a collaborative ecosystem to create community, spark innovation and stimulate business growth.

INT3L

INT3L

The INT3L group (formerly Defentek) is a provider of national security and intelligence solutions, systems and services.

Heritage Cyber World

Heritage Cyber World

Heritage Cyber World is a one stop solution for all your security needs that brings together a team of security experts and analysts to deliver high-class security services.

Secher Security

Secher Security

Secher Security is a professional and secure partner with a high level of professional expertise in simplifying and optimizing complex IT infrastructures.