Defending Against Cyberattacks via Supply Chains and Third-Party Services
Supply Chain Security
A supply chain refers to the entire series of process – from product planning and development to procurement, manufacturing, inventory management, logistics, and sales – as well as the group of organizations involved in this commercial flow. Cyberattacks that exploit this supply chain as a stepping stone to attack a primary target organization are called supply chain attacks. In recent years, they have become one of the most serious threats, consistently ranking near the top of the “Top 10 Information Security Threats” published annually by IPA (Information-technology Promotion Agency, Japan).
What Is a Supply Chain Attack?
Supply chain attacks can be broadly divided into three types:
- Attacks via business partners and affiliated companies
Rather than attacking a well-protected target organization directly, attackers first target business partners or contractors with weaker security measures and use them as a foothold to attack the primary target. - Attacks via software
Some attacks target the connections among all components involved in the software development lifecycle—including code, libraries, plugins, and various tools—as well as the people involved, such as developers and operators. Attackers compromise software delivered by the developer or vendor and use it as a route to attack the target organization. - Attacks via service providers
Attackers first target service providers that operate or maintain IT systems for the target company, then use the compromised provider as a foothold to attack the target company.
In all cases, attackers target exploitable points within the supply chain in order to gain unauthorized access to the target organization.
Asgent’s Supply Chain Attack Countermeasures
To defend against supply chain attacks, it is essential to build security measures with collaboration across the entire supply chain in mind, not just within your own organization. As noted above, attackers deliberately focus on areas with weaker security. Small and midsize organizations, in particular, often have fewer resources for security compared with large enterprises and are therefore more likely to become the initial target. Strengthening cybersecurity across the entire supply chain requires that these small and midsize organizations also implement appropriate security measures.
Two key points for countering supply chain attacks are:
1.Assessment and Countermeasures for Internal Security
First it is crucial to understand your own organization’s security posture. Identify the systems and applications currently in use, and verify whether they have vulnerabilities, whether configurations are appropriate, and whether they meet necessary security requirements.
In addition to implementing fundamental measures (for example, those recommended by IPA’s “Five Important Security Measures”), organizations should establish security policies and build an incident response framework that can handle security events across the entire supply chain.
- Attack Surface Management (ASM)
Areas, IT assets, and all of the components that make them up and that may be exposed to external attacks are collectively referred to as the attack surface. Attack Surface Management (ASM) is a continuous process of identifying and understanding these attack surfaces and detecting and assessing risks such as vulnerabilities that may exist within them.By using ASM, organizations can gain visibility into their publicly exposed IT assets and consider appropriate security measures based on their current situation.
Asgent provides a free ASM assessment for organizations seeking to understand their own attack surface. After identifying the status of your publicly exposed IT assets, please consult Asgent for appropriate countermeasures. We can propose a wide range of security solutions based on your needs.
- Provides a risk score that indicates how likely the organization is to be targeted by attackers
- Identifies the total number of IT assets accessible from the Internet
- Identifies major vulnerabilities and configuration issues
Learn More
ASM Checkup
Free Analysis Service
- Vulnerability Assessment Services
The service inspects your organization’s networks and applications for hidden vulnerabilities. We recommend using ASM to gain an accurate inventory of your IT assets first, and then performing a more precise vulnerability assessment based on that information.
Web Application Assessment Service
Platform Assessment Service
Penetration Testing
2.Establish Collaborative Frameworks across All Organizations in the Supply Chain
It is essential to strengthen security through collaboration across the entire supply chain. With new business partners, clearly define responsibility boundaries and how security risks will be addressed, and formalize these points in contractual agreements.