Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 4 Tips For Cyber-Securing Supply Chains
Articles

4 Tips For Cyber-Securing Supply Chains

ISBuzz TeamBy ISBuzz TeamMarch 21, 2017Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Many organizations are increasingly outsourcing software development and acquiring open source software products. In an effort to reduce costs for production or manufacturing requirements for information technology systems, networks and software, companies are disregarding the complexity of a supply chain cybersecurity.

Supply chains that contain IT systems such as software or hardware components are often a target of cyber attacks, malware, advanced persistent threats (APT) and cyber terrorism. This can lead to one or more components being compromised somewhere during the lifecycle of the supply chain, varying from development process to deployment. In order to avoid such security breaches, thorough and detailed cybersecurity measures must be implemented during the entire process of supply chain transportation. Here are a few tips on how to cyber-secure supply chains and ensure a safe delivery of products.

In-depth Analysis

A company should always run an in-depth analysis and assessment of the supply chain in order to find potential security threats and vulnerabilities. Supply chain cybersecurity threats can be found in computer hardware or networks that have been delivered with preinstalled malware on it, malware that has been inserted into software or hardware somewhere during the delivery process, vulnerabilities in software applications or networks within a supply chain that hackers can discover and exploit in order to breach security.

For example, back in December 2014, Lenovo shipped their notebooks worldwide with a preinstalled adware known as “Superfish”. Users couldn’t detect this software as malicious nor could the antivirus software installed on their system, mostly because that kind of software tends to be trusted since it came as default software. Superfish software installs a self-signed root HTTPS (Hypertext Transfer Protocol Secured) certificate that intercepts encrypted traffic for every website that a user visits.

Whenever a user visits an HTTPS website, the site’s certificate is signed and therefore controlled by Superfish, falsely presenting itself as the official website certificate. The private encryption key associating the Superfish-signed Transport Layer security (TLS) was the same for every Lenovo device. Hackers were able to use the key to certify imposter HTTPS websites that impersonate user’s Bank websites or other secure websites on the Internet. To make things worse, PCs with an installed Superfish root certificate would fail to recognize these websites as forgeries. It wasn’t until February 2015 that this security breach was discovered.

In fact, cybersecurity threats can originate anywhere from developer’s coding to delivery of the components to their destination. That’s why it is of the utmost importance for a company to conduct a comprehensive and in-depth analysis for cybersecurity risks and threats for each part of the supply chain’s lifecycle.

Communication

Aside from the analysis, companies should strive to procure software and hardware components from trusted sources as well as organize reliable means of transportation and well informed and educated personnel that will be a part of the supply chain. Also, establishing an open communication between the IT staff and the supply chain staff is of vital importance. Companies can fully utilize the potential of ecommerce logistics as well as implement user-defined policies and protocols for supply chain staff members and IT support staff. With premade detailed policies and regulations, the staff should make sure that delivery of the components is secure and that the integrity of the hardware or software components is not compromised at any moment, during the transportation.

Automation

Most parts of the software supply chain can be automated, further increasing its cybersecurity. For example, the U.S. National Institute of Standards and Technology’s Risk Management Framework offers companies detailed automated policies and security protocols that will ensure a higher level of cybersecurity. Automation of software supply chain can implement firewalls, assessment analysis and monitoring of software components and applications from the moment they are developed until they are up and running. Automation can effectively detect vulnerabilities and security threats early on, as opposed to manual monitoring which is prone to human error.

Leverage Government

Government can be an asset when it comes to cybersecurity. Although, a single company’s supply chain may not be on government’s agenda, its focus on infrastructure from a cyber risk point of view, certainly fits together with corporate interests. As mentioned, a good example is the U.S. Department of Homeland Security’s Office of Cybersecurity & Communications and the National Institute of Standards and Technology that are developing a set of cybersecurity standards and protocols for critical infrastructure and increased cybersecurity that companies can utilize.

Cyber-securing a supply chain is a difficult process because there are too many factors that can compromise the products. However, with some time and effort, companies can increase their cybersecurity and lower the risks of potential threats.

[su_box title=”About Nate Vickery” style=”noise” box_color=”#336588″][short_info id=’61879′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}