TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Cyber

Supply chain risk

by Mark Rowe

Businesses are deeply interconnected – and cyber risks in one part of the supply chain can have far-reaching effects, according to a vendor. Incidents can affect the global supply chain, as seen in the Kaspersky (June 2024), Snowflake (May 2024), and Crowdstrike (July 2024) incidents, says Bitsight in its report, Under the Surface: Cybersecurity Risks within the Global Supply Chain.

Bitsight’s global and UK-specific data is based on an analysis of 500,000 organisations, 40,000 products, and 12,000 providers, mapping over 61 million digital supply chain relationships. Among the findings – the typical UK organisation uses 29.1 providers and 81.6 products; that’s a larger supply chain by a tenth than the global average. As the cyber firm points out, the larger and more complex a supply chain, the greater the attack surface, increasing opportunities for cybercriminals to infiltrate networks. The report makes the point that supply chain risks donโ€™t just come from direct providers โ€“ they extend through multiple tiers, creating hidden vulnerabilities that businesses may not be aware of.

UK reliance

According to the study, 30 per cent of the UK supply chain relies on organisations designated by the United States’ Department of Defense as โ€œChinese Military Companies.โ€ Bitsight says that the continued reliance on these providers underscores the challenge of securing the digital supply chain against foreign influence. Even with increased scrutiny and regulatory efforts, Chinese state-linked firms maintain a significant foothold in UK industries, making it critical for organisations to assess their vendor relationships and mitigate potential risks.

Hidden pillars

The report says that the UKโ€™s most influential global providers arenโ€™t just big-name technology firms โ€“ they include niche software vendors that quietly power essential industries. The research identifies โ€œHidden Pillarsโ€; that is, lesser-known technology companies that serve large portions – or even the majority – of specific industries. A security failure at one of these companies could trigger cascading effects within and across industries. Customer count does not equal criticality, as some niche providers serve only a handful of companies yet support massive market share in industries like energy, finance, and logistics. Some of the most critical software and infrastructure providers operate with fewer than 50 employees, yet their technology is embedded in Fortune 500 companies and global enterprises.

Challenges

Organisations that supply digital products and services – known as providers – may face greater cybersecurity challenges than the businesses they serve. On average, providers use 2.5 times more products and have ten times more internet-facing assets globally, making them more exposed to cyber threats. While providers outperform consumers in four of six security standards โ€“ including DMARC, SPF, DKIM, and DNSSEC โ€“ they lag behind in areas such as patch management, open ports, insecure systems, and botnet infections. The UK is no different: businesses exhibit better cybersecurity performance than their providers. Moreover, regardless of provider size (as measured by market share) there are going to be some providers that fail to achieve or maintain a good security posture.

Ben Edwards, Principal Research Scientist at Bitsight, said: โ€œOver the past year, weโ€™ve seen several highly-visible security incidents that highlight how incidents in the digital supply chain can have a massive ripple effect across the global economy. Even the most security-conscious companies are vulnerable to weaknesses in their supply chain. Organisations must continuously evaluate their third party vendors and suppliers and work proactively to close security gaps.โ€

See also his blog, on the Bitsight website.

Visit bitsight.com.

Related News

  • Cyber

    Encryption in cyber frameworks

    by Mark Rowe

    Without encryption, any data shared within networks (and over the internet) is at risk of being manipulated by hackers. Although there are…

  • Cyber

    Ransomware survey

    by Mark Rowe

    Almost six in ten (59pc) businesses in the financial services sector have admitted to being on the receiving end of a ransomware…

  • Cyber

    Global Head of Incident Response

    by Mark Rowe

    The intelligence and cyber security consultancy S-RM has promoted Casey Oโ€™Brien to Global Head of Incident Response (IR). Casey will work with…