{"id":36708,"date":"2022-06-16T05:00:00","date_gmt":"2022-06-16T05:00:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/36708"},"modified":"2022-06-16T05:00:00","modified_gmt":"2022-06-16T05:00:00","slug":"security-think-tank-best-practices-for-boosting-supply-chain-security","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=36708","title":{"rendered":"Security Think Tank: Best practices for boosting supply chain security"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/06\/security-think-tank-best-practices-for-boosting-supply-chain-security.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>It\u2019s old news that the pandemic has accelerated the adoption of digital means, but perhaps not widely recognised or accepted yet is that this will change the security paradigm in the short to medium term. And only a few organisations that expect their operations to be disrupted are looking for proactive ways to <a href=\"https:\/\/www.computerweekly.com\/resources\/IT-risk-management\">manage risk<\/a> to their increasingly complex operations.<\/p>\n<p>In particular, the adoption of new technologies to help drive efficiencies across the business is leading to more complicated IT ecosystems that are, in some cases, <a href=\"https:\/\/www.techtarget.com\/searcherp\/definition\/supply-chain-security\">heavily integrated with partners, alliances and suppliers<\/a>. This grey area of risk falls outside the traditional good practice guidelines we have come to know well. We must now adapt our methods and approaches to identify and manage this new risk vector.<\/p>\n<p>With the traditional corporate boundary now becoming increasingly blurred, expanding deep into your supplier landscape, trying to track \u201cwho does what and when\u201d with our data is a growing challenge. We now face an increased \u201cattack surface\u201d, presenting many unknown risks and impacts on our daily operations \u2013 and our response needs to reflect that.<\/p>\n<p>This is an industry-agnostic problem. It affects financial services accelerating digital adoption to provide better services to their customers. Equally, the rise of e-commerce and non-store retailing within consumer, manufacturing and distribution is placing huge demands on technology-driven solutions to streamline operations. Real-time stock levels, tracking software allowing for improved accuracy over end-to-end manufacture to delivery to the customer are examples of where your software talks to your supplier\u2019s software, which talks to their supplier\u2019s software. All that requires new approaches to managing risk.<\/p>\n<p>Breaches in security can erode market value and damage brand reputation. The attack on <a href=\"https:\/\/www.computerweekly.com\/news\/252521308\/SolarWinds-CEO-offers-to-commit-staffers-to-government-cyber-agencies\">SolarWinds<\/a> and the ransomware attack on Florida-based IT company <a href=\"https:\/\/www.computerweekly.com\/microscope\/news\/252514248\/Kaseya-Compliance-and-security-top-of-mind-for-MSPs\">Kaseya<\/a> spread through hundreds of networks. That failure to appreciate risk in the overall end-to-end system had a significant material impact on their operations. The <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-57707530\">Swedish Coop supermarket chain<\/a> was forced to close all 800 outlets for five days, resulting in sales loss of about SEK90m (\u00a37.2m) a day, highlighting the need to readdress our approach to risk management and look further afield than our own corporate domain.<\/p>\n<p>The unknown risks from this interconnected world include exposed or abandoned internet-facing servers highlighting asset management issues, and confidential documents leaking due to a lack of consistently applied data classification and handling across multiple organisations. Other dangers come from default, out-of-the-box login credentials, pointing to build standards not being met, and legacy hardware falling off the support radar and identifying failing decommissioning processes.<\/p>\n<p>Further problems can arise from suppliers not doing what they are expected to do and not identifying breaches you were blissfully unaware of. All this is in addition to the need to respond to the growing regulatory focus on supply chain accountability, which is placing further pressure on already pressed resources to address risk.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"What do we need to do?\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>What do we need to do?<\/h3>\n<p>So, how do we broaden risk management processes to incorporate the supplier landscape and streamline efforts? There are five key areas to focus on:<\/p>\n<ul class=\"default-list\">\n<li>Access \u2013 we need to be more transparent and know \u201cwho\u201d has access to our network and systems. We also need to understand \u201cwhat\u201d they do inside our network and with our data and \u201chow\u201d they access it.<\/li>\n<li>Data \u2013 we need to understand \u201cwhat\u201d data is at risk. That means understanding the full end-to-end architecture that flows into, and out of, our own environment and identify what are the points of exposure that could undermine our operations (\u201coutside-in\u201d scanning).<\/li>\n<li>Suppliers \u2013 we need to increase collaboration and take proactive measures to understand \u201chow\u201d our suppliers manage their own IT estates if they are connected to us (this is not about \u201cpointing fingers\u201d). We also need to mature the commercial obligations with our suppliers to provide greater comfort over how they will handle our data (simply asking them to be ISO compliant isn\u2019t enough).<\/li>\n<li>Technologies \u2013 we now need to leverage red-teaming techniques, attack surface scanning and \u201ccontinuous control monitoring\u201d to test the robustness of our controls.<\/li>\n<li>The business \u2013 we need to understand what the material impact on our operations would be in the event of a compromise to our systems or suppliers\u2019 systems.<\/li>\n<\/ul>\n<p>By adapting our traditional approach to managing risk, we can identify the attack surface across the entire IT ecosystem and, by proxy, identify areas of weaknesses we need to fix. This will also enable the more efficient and effective use of scarce resources to target areas of vulnerability underpinning our operations, allowing us to obtain a higher degree of assurance in this connected world.<\/p>\n<p><em>Carl Nightingale is a <a href=\"https:\/\/www.paconsulting.com\/services\/cyber-security-and-digital-trust\/\">cyber security<\/a> expert at PA Consulting&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/em><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s old news that the pandemic has accelerated the adoption of digital means, but perhaps not widely recognised or accepted yet is that this will change the security paradigm in the short to medium term. And only a few organisations that expect their operations to be disrupted are looking for proactive ways to manage risk [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":36709,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-36708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/36708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=36708"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/36708\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/36709"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=36708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=36708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=36708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}