Supply Chain Cyber Attacks Are On the Rise: How To Protect Your Company

supply chain cyber attacks

When it comes to cyber security, things are always changing, and technology is always growing or improving in one way or another. As a result of this, cyber attacks have been on the rise, attacks that can be particularly threatening to supply chain businesses. These supply chain cyber attacks can cause a number of problems for a company, and can even go beyond just the company itself. 

So why are supply chain cyber attacks causing more and more concern among businesses? Because they keep increasing in frequency and in severity. Consider that:

  • There was a 42 percent increase in supply chain attacks in the first quarter of 2021 (CIPS).
  • Supply chain attacks hit three in five businesses in 2021 (CSO Online).
  • A whopping 97 percent of businesses were impacted by a supply chain breach and 93 percent suffered a direct breach due to a supply chain’s vulnerability in 2021 (Bluevoyant).
  • More than half of businesses (52 percent) have had a supply chain  organization hit by ransomware (Trend Micro).

These statistics continue to rise in 2022, with Sonotype predicting a 700 percent increase in repository attacks over the last three years.

These attacks can happen to any business at any time. If you are not prepared and protected, it is likely your business may have a breach in your software, and due to this cyber attack, your goods and services providers could be compromised for days. 

To keep your business safe and secure, you should learn about the risks of cyber attacks to your supply chains. It is also important to have a plan on how to protect your business should your supplier’s security be breached. 

5 Tips to Lower the Risk of Losses From a Supply Chain Attack 

1. Identify Any Risks With Your Suppliers

Learn about any risks to your business if your supply chains are breached or hit with ransomware (the most common attack in regards to supply chains). Start by making a list of all of your suppliers,  whether they’re goods or services. This list includes not only vendors of materials and supplies your company uses or sells, but also any cloud services. You will need to carefully review each vendor to identify any risks or threats in their cyber security. 

2. Create Minimum Security Requirements

Come up with a list of minimum security requirements that each vendor must follow in order for your company to do business with them or use their products and services. It doesn’t have to be complicated or unique. You can even use an already existing data privacy standard. The goal is to ensure that your supply chains take the proper precautions to protect not only their own company, but also anybody they supply to. 

3. Complete a Vulnerability Assessment 

If any of the software you use had a vulnerability that a hacker used to their advantage, how much risk is your system in? Do you have an application in place that will provide any updates to your software as soon as possible? You must be knowledgeable about your risk. 

If you haven’t had an IT security assessment in a year or more, it is important that you do so. If your supply chain is hit with ransomware or a breach of security, this can detect how effective your software is at ensuring this attack does not reach you. Request a vulnerability assessment.

4. Always Have Backup (That Includes Backup Vendors)

If you have only one supplier for your materials, it is much more likely that your business will be impacted if that vendor is compromised. To ensure that you have access to the supplies you need, have two suppliers in place. That way, if a cyber attack takes down one of them, your business doesn’t have to be left in the dust. 

A good  example is your internet provider. Most businesses would in no way be able to operate if they did not have internet access. With a backup service in place, the entire business doesn’t have to go down when your main internet service provider goes down.  

Having a backup in place for all of your suppliers can bolster protection for your business.

5. Always Have Cloud Backup

Some people assume that because they use Microsoft 365, Google Drive or other cloud services, their data is backed up. This is not necessarily the case. In the Microsoft service agreement, it is stated “We recommend that you regularly back up your Content and Data that you store on the Services or store using Third-Party Apps and Services.” This same is true for any cloud service your business uses. 

You should back up all of your information in a separate platform that you store on cloud services. This ensures that you will still have access to your information in the case of a cyber attack on your main cloud. 

Examples of High-profile Supply Chain Cyber Attacks

Still not convinced that your business is truly at risk of these cyber attacks? Here are some examples of high-profile attacks that caused significant issues for the companies and their partners:

  • Colonial Pipeline: This gas pipeline was shut down for close to a week after it was hit with ransomware. 
  • JBS: One of the world’s largest suppliers of beef and pork products was shut down for multiple days in more than three countries after a ransomware attack. 
  • Kaseya: This software company was hit with ransomware that managed to reach about 1,500 of the IT businesses that use their products. 

Don’t Go IT Alone

We know that it can be extremely stressful to wade through the latest cyber security risks and figure out how you are going to protect your business. That is what we are here for. Contact us or book a consultation so we can help keep you and your business safe. 

Posted in
Dave Hatter

Dave Hatter

Dave Hatter (CISSP, CCSP, CCSLP, Security+, Network+) is a cyber security consultant, writer, educator and on-air media contributor. See hundreds of Dave’s expert interviews on cyber security on his YouTube channel, or tune in to 55KRC every Friday morning at 6:30 for his “Tech Friday” segment.

Share this Blog

Not Sure Where To Start Looking for an MSP?

Our Managed IT Checklist will help you choose the right IT provider.

Get the checklist

Explore the Latest Trends in IT

Google Workspace Vulnerability Risk Assessment

Google Workspace Vulnerability Risk Assessment

Have you or your company considered going through a Google Workspace vulnerability risk assessment? You wouldn’t be the first to...
social engineering threat trends

Don’t Be Fooled by These Social Engineering Threat Trends

Social engineering is the primary cause of cyberattacks today, so it is critical to keep your team informed of the...
Intrust Nine Days Away from Keyboard Initiative

Nine Days Away From Keyboard Initiative

At Intrust IT, we understand the importance of taking time off to recharge and refresh, just like Ferris Bueller did...
9 Phishing Scam Prevention Tips

9 Phishing Scam Prevention Tips

If you’ve been on the Internet or working at a desk job, you’ve likely heard the term “phishing” thrown around...
Azure vs Aws

Azure vs AWS: Which Should I Choose?

The Azure vs AWS debate is a complex one to handle. You’re likely thinking about which cloud architecture of the...
Cloud Organization Tips

8 Best Cloud Organization Tips (And Why You Should Use Them)

The cloud makes it easy to share, store and manage files, but without routine maintenance, it can become messier than...