How Cybercriminals Could Be Infiltrating Your Supply Chain

In today’s modern technology landscape, you would expect for large organisations and enterprises to have advanced cyber defences in place - but can the same be said for their partners?

Cybercriminals have mastered the art of uncovering the paths of least resistance that lead to an organisation’s valuable assets and confidential information. To counter this, security professionals have introduced more robust and sophisticated measures to make it harder for attackers to succeed.

Yet, organisations are only as strong as their weakest link, and if a large organisation has invested in its cybersecurity infrastructure without its partners doing the same, then they have opened the door to “island hopping”. 

Cybercriminals are increasingly opting for island hopping, where they infiltrate a single, weaker target to exploit existing credentials and gain access into larger enterprises – essentially, a paradise of interconnected organisations. 

Island hopping represents a significant threat to any organisation that works with third parties. Particularly susceptible are those enterprises that engage with all sizes of vendors, contractors, and service providers.

Unfortunately, smaller suppliers with potentially weaker security postures can become easy entry points for cybercriminals and pose a substantial risk to their larger clients.

A Paradise For Cybercriminals

Even when suppliers appreciate the importance of cybersecurity, they may lack appropriate resources and be unable to afford the level of defence and monitoring capabilities that are necessary.  Although, business partners and suppliers are not consciously letting bad actors into their networks unchallenged, adversaries are taking advantage of these trusted relationships.

Cybercriminals know that organisations often grant their business partners some level of access to their systems, making them prime targets for phishing, social engineering, and man-in-the middle attacks. Malicious actors are also aware that suppliers are often given more access to systems than they need. Therefore, the question for many enterprises has become, how do they secure their business from island hopping attacks, whilst at the same time being able to continue working with valued suppliers, whatever their size? This problem needs a solution capable of closing vulnerable security gaps in the collaborative workflow, whilst also keeping partnerships running smoothly.

The Role Of Zero Trust

A zero trust authentication strategy can play a pivotal role in an organisation’s cybersecurity infrastructure and ensure that suppliers don’t unwittingly become the bridge for island hopping attacks. Instead of assuming that users and devices are trustworthy, this approach requires continuous verification of every user, device, and application which tries to access resources, based on fine-grained authorisation that can accommodate nuanced data sharing across internal and external users.

By extending this centralised approach to suppliers and third parties, organisations can have visibility and access control of their entire ecosystem in one place, including users, suppliers, partners, roles, and applications.  Always-on verification from dynamic risk indicators such as network device, identity, location, ensures that after authentication is granted it is also monitored throughout each digital interaction to detect any unauthorised access or hijacked session. In this way, any suspicious access can be denied or terminated.

Utilising zero trust authentication can be the difference between being a victim of cybercrime or thriving while protected.

Having the right kind of authentication tools in place will help to minimise risks and, if backed up with education and supporting materials, can further enhance security for all parties. Offering free cybersecurity training to suppliers can help them to improve their ability to defend and respond to threats as well as understand obligations to compliance regulations.  This mutual commitment of time and resources can cement and build longer term commercial partnerships.

It’s important to understand that the risk of a breach is never completely eradicated when dealing with third parties. However, zero trust authentication significantly strengthens security and ensures that every access attempt is rigorously verified, reducing the odds of a successful attack.

Adopting a zero trust mindset puts organisations in a much safer position than those who trust anyone who seemingly has legitimate credentials but turns out to be an island hopping cyber tourist with criminal intentions.

Stuart Hodkinson is VP EMEA at PlainID

Image: Erik_and_so_on

You Might Also Read:

Mapping Out The Journey To Zero Trust:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

 

« Intelligence Chiefs Accuse China Of IP Theft & Online Deception
A Microchip To Reshape Artificial Intelligence »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Detectify

Detectify

Detectify is a web security service that simulates automated hacker attacks on your website, detecting critical security issues before real hackers do.

CYBERSEC Forum

CYBERSEC Forum

CYBERSEC Forum is an annual European Public Policy Conference dedicated to strategic aspects of cybersecurity.

Commonwealth Cybercrime Initiative (CCI)

Commonwealth Cybercrime Initiative (CCI)

The CCI unites 35 international organisations contributing to multidisciplinary programmes in Commonwealth countries. These organisations form the CCI Consortium.

Civic Technologies

Civic Technologies

Civic’s Secure Identity Platform (SIP) uses a verified identity for multi-factor authentication on web and mobile apps without the need for usernames or passwords.

TrueFort

TrueFort

TrueFort take an application-first approach that offers comprehensive protection for real-time visibility and analysis, protection and better communication across business, IT, and security teams.

Industrial Control System Information Sharing and Analysis Center (ICS-ISAC)

Industrial Control System Information Sharing and Analysis Center (ICS-ISAC)

ICS-ISAC is a non-profit, public/private Knowledge Sharing Center established to help facilities develop situational awareness in support of local, national and international security.

Securosys

Securosys

Securosys is a technology company dedicated to securing data and communications. We develop, produce, and distribute hardware, software and services that protect and verify data and their transmission

Hayes Connor Solicitors

Hayes Connor Solicitors

Hayes Connor Solicitors is a specialist data breach and cybercrime law firm. We act for clients on individual data breaches and also where a group has been compromised as part of a targeted attack.

FCI

FCI

FCI is a NIST-Based Managed Security Service Provider (MSSP) offering Cybersecurity Compliance Enablement Technologies & Services to Financial Services organizations.

Capgemini

Capgemini

Capgemini is one of the world's foremost providers of consulting, technology and outsourcing services. Areas of expertise include Cybersecurity.

Cranium

Cranium

AI is being implemented into every business process, but nobody knows whether their AI is secure. Our mission is to deliver security and trust to the AI revolution.

Cenobe Cyber Security

Cenobe Cyber Security

Cenobe provides customized solutions to keep you ahead of potential threats and ensure the security of your organization's systems and data.

Institute for Applied Network Security (IANS)

Institute for Applied Network Security (IANS)

For the security practitioner caught between rapidly evolving threats and demanding executives, IANS Research is a clear-headed resource for decision making and articulating risk.

IS4IT Kritis

IS4IT Kritis

IS4IT is your partner for the successful planning, introduction and implementation of company-specific information security concepts.

Alcatel-Lucent Enterprise (ALE)

Alcatel-Lucent Enterprise (ALE)

We are Alcatel-Lucent Enterprise. Our mission is to make everything connect with digital age networking, communications and cloud solutions.

CyberHive

CyberHive

CyberHive offer a complete suite of threat protection modules that seamlessly integrate to block current, as well as future threats.