Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - When It Comes To Cyber Security, Firms Must Prove Due Diligence Or Be Passed Up For Partnership
Articles

When It Comes To Cyber Security, Firms Must Prove Due Diligence Or Be Passed Up For Partnership

ISBuzz TeamBy ISBuzz TeamOctober 20, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Technology security and Internet safety and privacy issues with a human eye and digital binary code as surveillance of hackers or hacking from cyber criminals watching prohibited private access to web sites with firewalls.
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In terms of business risks, data breaches and cyber-crime in general are quickly marching up the list of priorities for companies around the world.

For businesses at the enterprise level, this concern is manifesting itself in the increasing pressure they are forcing on their suppliers to prove they are practicing due diligence when it comes to keeping their systems safe.

This proposition can pose a significant challenge for many supply chain partners. CTOs, for example, may be asked to submit an outline of the cyber security practices their company has in place before a partnership is finalised. The companies whose security approaches are deemed too risky may find themselves being passed on for partnerships, as enterprises seek to keep their supply chains strong.

Whether it is in recruitment, accountancy, law or catering supplies, the trusted relationship in the supply chain is now under threat, with failure to demonstrate accountability, compliance and effective reporting a key factor in decisions about who does business with whom.

The usual layers of security no longer cut it and with the EU General Data Protection Regulation coming into effect in just over 18 months’ time, organisations need to start putting their respective houses in order. This means measurable and reportable intelligence about not only their own, but also their partners’ and suppliers’ cyber security practices.

Innovation, implementation of policy and a strong and sustained focus on the critical and most vulnerable areas of security are key to staying one step ahead of the attacker. The question is, do enough businesses understand the nature of the threats and what is required to defeat them? Are they able to provide demonstrable reporting to the satisfaction of their legal department when completing supplier cyber security questionnaires?

The danger of complacency

Despite the number of high-profile and damaging data leaks that occurred around the globe last year, many businesses are still complacent about security. For many, security is still a matter of out-dated perimeter security that completely ignores the area where most danger now lies – in file-based malware attacks delivered in email attachments. These attacks using common file-types such as Word, Excel, PDF or PowerPoint now account for 74 per cent of successful data breaches.

Perhaps businesses will sit up and take notice after one of the companies hit last year – Talk Talk – was back in the news this month (October), fined £400,000 for allowing the details of nearly 157,000 customers to be stolen by hackers.

For any business with supply chain partners, it is no longer good enough to claim that targeted attacks cannot be prevented and to assert that post-infection detection and response with anti-virus software is solely the answer.

Technology that works

Among enterprises at the top of the supply chain, it is increasingly understood that the only effective solution that will provide impregnability against this deliberate corruption of email-bound documents lies in file-regeneration technology.

An automated solution utilising this capability disarms malicious files, producing a benign version referenced against the manufacturer’s original standard, checking it right down to byte level instead of just looking for active content in the body of the document. A sanitised file is regenerated at sub-second speeds and passed on to users in real-time to maintain business continuity.

The technology protects organisations against even the smallest and most subtle alterations in file structure, detecting for example, where criminals have changed just two bytes in a PDF file to crash the reader software in order to trigger malware or hidden exploits. This type of attack is simply not visible, or stoppable, without such document regeneration software.

This a technology that also sanitises outbound emails, using the same techniques to ensure that no business is ever held responsible for the potentially catastrophic consequences of infecting a supply chain partner or client. Reliance on encryption and digital signature-based security may reduce some of the risk from third-party interception, but it will not prevent an organisation from unwittingly delivering an infected file, since hackers are now adept at using delayed-action embedded code or structural manipulation, in combination with clever use of social engineering.

Fit to do business with

Besides eliminating known and evolving threats, one of the great benefits of file-regeneration is that it puts organisations back in control, deciding who should receive specific file content as part of a broader security and risk management strategy. Crucially, it also provides supply chain partners with the evidence that their organisation has adopted the solution that is known to be effective against file-based threats – by far the most common origin of cyber-attacks.

The overall outcome is that organisations can send and receive emailed documents, transfer files or share and access cloud file stores with and from customers, partners and suppliers in full confidence and in turn are regarded as safe to do business with.

It is clear that only the kind of genuine innovation to be found in file-regeneration solutions will give organisations this watertight and demonstrable level of security. In the face of so many emerging threats it is vital that the CTOs and CISOs throughout the supply chain recognise this important fact in the ongoing battle against cyber-crime.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}