The importance of your supply chain for cyber security

supply chain security

Why is supply chain security important? Well, unfortunately, cyber criminals have started to target businesses that provide critical services to other organisations. This allows them to increase the impact of their attack and their potential for financial gain.

This is because many organisations rely on external suppliers to provide a variety of core services, products and systems. For example, your business will likely be reliant on an external IT company, accountancy firm, cloud service provider, website developer, digital marketing agency, or payment provider. 

Each of these external suppliers will, in turn, be relying on external parties themselves, creating a network of co-joined organisations. The net result is a large, complex supply chain. 

Somewhere in this network, there could be a potential system flaw, a disgruntled member of staff or a number of vulnerabilities that could potentially lead to an incident or event, which would affect anyone in this supply chain. Often, we refer to this being the weakest link.

For example: 

Fastly 

Fastly are a cloud computing company that offers a content delivery network. Their customers include a number of high-profile websites including Amazon, Reddit, PayPal and Spotify. This meant that when Fastly’s system failed, all those websites could not retrieve their data and were forced offline. It would appear that the cause was a software bug that one of their customers triggered. The consequences could have been potentially more significant than downtime.

Target

A vulnerability in Target’s supply chain affected them back in 2013. This was a payment card breach through the refrigeration company Fazio Mechanical, who had access to Target’s systems to carry out maintenance. It is understood the supplier received an email containing Malware, which stole credentials to the online portal they used for Target.

British Airways 

More recently, an attacker gained access to BA’s network through login credentials provided to a third-party provider of cargo services. From here, the attacker was able to gain access to other parts of BA’s network and access log files containing 108,000 payment card details. This was part of a testing feature that someone had not disabled. The attackers also managed to gain access to the BA website through files they accessed containing code, and then redirect customer payment card data to a different website.

Ticket Master 

Ticket Master was using a chat-bot feature on its website, hosted by a third party, on its online payment page. This gave an attacker access to customer financial details. This potentially affected 9.4m of Ticketmaster’s customers across Europe, with 60,000 payment cards belonging to Barclays bank customers being subjected to known fraud.

Service providers and cyber security risk

The cyber security risks to the service providers businesses use become their own cyber security risks. This risk could be anything from a business email compromise through to credential stuffing.

If a cyber criminal wants to attack a larger organisation, often the easier route is to go through their suppliers, because this is normally an easier target. Their cyber defences are often nowhere near as well funded as those of larger organisations.

Suppliers can provide a route to a larger organisation’s supply chain. This means security is part of the onboarding requirement for contractors working with Government-controlled organisations. The MOD, NHS, local authorities, and increasingly, larger organisations who have identified supply chain risk within their risk management require proof of good security from their suppliers.

Supply chain requirements

The requirements for supply chain are normally determined by the perceived risk and the classification of data that the external organisation could potentially access. It might be a self-assessed Cyber Essentials, an externally verified Cyber Essentials Plus, ISO 27001, a pentest, or proof of Payment Card Industry compliance – or any combination thereof. It is a requirement to have a SOC/ SIEM solution in place for critical national infrastructure providers, for example.

In addition, since the GDPR came into force in May 2018, supply chain due diligence has become part of the accountability of a data controller. This has led to a ream of third party security questionnaires asking for evidence of controls, numerous policies and assurance. 

Ultimately, if the data controller has not carried out due diligence on their supply chain, they could be ultimately to blame for any breach that originated from the third party that affected their data, as in the example of BA and Ticketmaster.

So where do you start?

You need to map out which third party suppliers you use. Which classification of data do they have access to? And consider not only carrying out your own security checks, but also a full risk analysis of the impact an incident originating with them could have on your organisation. Could it be critical to your operations? Could it affect your customers’ data? Or could it affect your ability to operate?

Understand what ‘appropriate technical and organisational controls’ are in place, and bear in mind that this could be subjective. It may sound harsh, but can you really trust the reassurances you have been provided? Is there any third-party independent assurance or testing that you can rely on?

Though Cyber Essentials and Cyber Essentials Plus are great certifications, they are only a moment in time. So how do you know they are maintaining these standards throughout the year, between assessments? Also consider whether a self-assessed Cyber Essentials is the appropriate level of certification required for your risk assurance. Or would an independent verification provide more substantial assurance?

Ongoing supply chain security

As far as ongoing supply chain assurance, consider looking for that UKAS certified ISO 27001 (International Standard for Information Security). This is a risk-based management system of continual improvement for information security.

Web apps, websites, supplier sites etc could be independently pentested to ensure they do not contain vulnerabilities that could effectively leave a door open for an attacker, who could then use it as a route to your data.

Has the supplier put in place robust training and staff awareness around GDPR and Cyber security? And can they evidence this is their training records?

Also consider how, if a supplier needs to access your systems, you can ring fence that access to the minimum they need to carry out that function, for the minimum time. Where possible, you should set up multi-factor authentication rather than rely on just a username and password. If you have an outsourced IT company that needs to access your system remotely, make sure this is not a continually open door, but just for an authorised, pre-arranged moment in time. 

Check out the NCSC Principles of Supply Chain Security. This is effectively about identifying the supply chain, understanding the risks and putting measures in place to mitigate these.

Final thoughts on supply chain security

Everyone should be bearing in mind supply chain security nowadays. It doesn’t matter how much resource you put into making sure your cyber security is in good shape – if you are reliant on an external provider that doesn’t take it quite so seriously, it could have a significant impact on your operations and bottom line. 

It’s also worth looking at gaining accreditations yourself, as a means of helping differentiate yourself from your competition. Increasingly, larger organisations require their suppliers to have measures in place to prove they’re secure, so get ahead of the game, and your competitors, by achieving recognised security accreditations.

If you want to find out more about achieving accreditations, or how best to ensure you don’t have weaknesses in your supply chain, fill in the contact form below and a member of our team will happily talk you through it.