{"id":6392,"date":"2021-03-05T19:44:03","date_gmt":"2021-03-05T17:44:03","guid":{"rendered":"https:\/\/tekmart.co.za\/t-blog\/?p=6392"},"modified":"2021-03-05T19:44:05","modified_gmt":"2021-03-05T17:44:05","slug":"tips-for-suppliers-on-how-to-prevent-supply-chain-attacks","status":"publish","type":"post","link":"https:\/\/tekmart.co.za\/t-blog\/tips-for-suppliers-on-how-to-prevent-supply-chain-attacks\/","title":{"rendered":"Tips for suppliers on how to prevent supply chain attacks"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>\n<h2 class=\"wp-block-heading\"><strong>Every company, large and small, must assume it is a target in the supply chain. Suppliers should follow these best practices to keep themselves and their customers protected.<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineImages\/Cobb_Michael.PNG\" alt=\"Michael Cobb\"\/><\/figure>\n\n\n\n<p>By <a href=\"https:\/\/www.techtarget.com\/contributor\/Michael-Cobb\">Michael Cobb<\/a><\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>A big IT security mistake made by many small and medium-sized enterprises, or SMEs, is not realizing they are a potential target for well-resourced and sophisticated hackers.<\/p><\/blockquote><\/figure>\n\n\n\n<p>Their arguments run the gamut, from &#8220;We don&#8217;t have much of a presence on the web&#8221; and &#8220;We&#8217;re just a small player in our industry,&#8221; to &#8220;Our turnover is small in comparison to our competitors&#8221; and &#8220;Hardly anyone&#8217;s heard of us.&#8221; These claims blindly assure SMEs they won&#8217;t be victims of a targeted attack and provide them with what they believe are good excuses to not invest more heavily in cybersecurity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Don&#8217;t forget the supply chain vulnerability<\/strong><\/h3>\n\n\n\n<p>But all companies &#8212; big and small &#8212; have customers. And those customers have customers. And somewhere along this chain of relationships exists the hacker&#8217;s intended target. The target company probably has strong security controls in place with a dedicated security team monitoring the network for malicious intrusions and suspicious behavior. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Overcoming these protections is one reason why\u00a0supply chain attacks\u00a0have become a common tactic. Here, hackers use one of their target&#8217;s suppliers as a steppingstone to gain access to the main victim&#8217;s network. The consequences of this technique mean every company in a supply chain needs to assume they are a potential target and must know how to prevent supply chain attacks by securing their data and networks accordingly.<\/p><\/blockquote>\n\n\n\n<p>Depending on the nature of the relationship, customers may require potential suppliers to show their cybersecurity strategy meets an acceptable standard and they have effective processes and controls in place to detect, respond, mitigate and recover from breaches and other security events. In fact, many tenders for contracts stipulate that suppliers comply with relevant standards, such as those mandated by\u00a0ISO 27001, PCI DSS, HIPAA and\u00a0ITAR. <\/p>\n\n\n\n<p>Although obtaining certifications can be quite onerous and time-consuming for smaller companies, it does ensure that IT systems and the data they handle are protected and that employees are aware of their role in keeping data secure.Every company in a supply chain needs to assume they are a potential target and must know how to prevent supply chain attacks by securing their data and networks accordingly.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Audits and security reports play a crucial role<\/strong><\/h3>\n\n\n\n<p>A slightly less arduous route for SMEs is to obtain a\u00a0Service Organization Control\u00a02 report, which provides assurances about the effectiveness of controls in place at a service organization, or a\u00a0SOC for Cybersecurity\u00a0report, which covers processes for handling enterprise-wide cyber-risks. <\/p>\n\n\n\n<p>Audits and reports are completed by an independent certified public accountant and determine if the audited entity is appropriately addressing its cybersecurity risks. If none of these options is affordable, then a self-assessment audit based on SOC 2 is an alternative that some customers will find acceptable.<\/p>\n\n\n\n<p>A self-assessment audit is best conducted in two stages:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Adequacy audit.<\/strong>\u00a0This review demonstrates that policies and procedures protecting data and managing information risk are sufficient.<\/li><li><strong>Compliance audit.<\/strong>\u00a0This is an\u00a0evidence-based assessment\u00a0of the implementation and effectiveness of policies and procedures.<\/li><\/ol>\n\n\n\n<p>By conducting an adequacy audit first, any shortcomings can be corrected prior to the start of the compliance audit. There is no point in checking whether a business unit or system is compliant if sufficient documented policies and procedures aren&#8217;t already in place.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Once the adequacy audit is completed satisfactorily, the compliance audit can begin. This involves assessing the level of compliance with every mandatory policy and procedure in scope. <\/p><\/blockquote>\n\n\n\n<p>It&#8217;s important to focus the scope and the audit on areas that will be of importance to customers &#8212; for example, location, business unit, system, application or project. Customers will be particularly interested in security controls such as strong authentication, encryption of\u00a0data at rest and data in transit, business continuity plans and\u00a0security awareness training.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Not just checking boxes<\/strong><\/h3>\n\n\n\n<p>There are a number of other security controls suppliers should enforce to prevent supply chain attacks on their customers and partners, including the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Strong authentication.\u00a0<\/strong>Because stolen credentials are often used to gain a foothold in a network,\u00a0two-factor\u00a0or\u00a0multifactor authentication\u00a0should be mandatory for access to any sensitive or shared resources.<\/li><li><strong>Strong encryption.\u00a0<\/strong>Encrypting data at rest and data in transit is critical to reducing the likelihood of a data breach.<\/li><li><strong>BCDR integration.\u00a0<\/strong>Be prepared to\u00a0integrate your business continuity and disaster recovery plans\u00a0with your key customers to ensure there can be a coordinated response to any ongoing attack.<\/li><li><strong>Security awareness training and security job requirements.\u00a0<\/strong>Make sure employees know what&#8217;s expected of them, and train them to know how to detect and mitigate potential threats. Everyone&#8217;s job description should include their security responsibilities.<\/li><li><strong>Security control checks.\u00a0<\/strong>Systematically examining and verifying IT security controls provides important feedback on the state of an organization&#8217;s security strategy, and it lets employees address how security affects their work &#8212; both positively and negatively. It&#8217;s also an opportunity to demonstrate the importance that senior management places on information security.<\/li><\/ul>\n\n\n\n<p>As long as the goal of the audit isn&#8217;t seen as simply checking boxes but as an exercise to improve the protection of network resources and data, its structured and documented nature will result in a more secure IT environment.<\/p>\n\n\n\n<p>Remember, cybersecurity costs money and its\u00a0ROI cannot be easily evaluated. However, security&#8217;s effect on the bottom line is more critical than ever. Not only does a comprehensive cybersecurity strategy keep an organization&#8217;s systems up and running and prevent expensive data breaches, but it also provides a competitive advantage when seeking new business.<\/p>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>Every company, large and small, must assume it is a target in the supply chain. Suppliers should follow these best practices to keep themselves and their customers protected. By Michael Cobb A big IT security mistake made by many small and medium-sized enterprises, or SMEs, is not realizing they are a potential target for well-resourced and sophisticated hackers. Their arguments<\/p>\n<p><a class=\"more-link\" href=\"https:\/\/tekmart.co.za\/t-blog\/tips-for-suppliers-on-how-to-prevent-supply-chain-attacks\/\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[218,4,30,3,220,95],"tags":[],"class_list":["post-6392","post","type-post","status-publish","format-standard","hentry","category-ceo-quick-reads","category-datacenter-news","category-expert-advise-and-opinion","category-industry-news-and-expert-advise","category-supply-chain-management-scm-resources","category-timeless-tips"],"_links":{"self":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/6392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/comments?post=6392"}],"version-history":[{"count":1,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/6392\/revisions"}],"predecessor-version":[{"id":6393,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/6392\/revisions\/6393"}],"wp:attachment":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/media?parent=6392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/categories?post=6392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/tags?post=6392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}