How to assess and gain confidence in your supply chain cyber security
Pages
Page 5 of 29
Step 1: Understand why your organisation should care about supply chain cyber security
Unless you understand what needs to be protected and why, it can be very hard to establish any meaningful control over your supply chain.
A person or group of people might perform a cyber attack via your supply chain because:
- They may want to cause harm to your suppliers or your organisation. If your suppliers are more susceptible to cyber attacks than your organisation, they could offer a much easier route to accessing your systems, networks and data.
- They may want to cause harm to suppliers you have relationships with. In this case your organisation might not be of specific interest. However, disruption of a supplier might achieve the objective of affecting a whole sector and undermine confidence on a broader scale.
Who are behind supply chain attacks, and what are their motives?
- Online criminals Excel at identifying what can be monetised, for example stealing and selling sensitive data, or holding systems and information to ransom.
- Hackers Individuals with varying degrees of expertise, often acting in an untargeted way (perhaps to test their own skills or cause disruption for the sake of it).
- Political activists Out to prove a point for political or ideological reasons, perhaps to expose or discredit your organisation’s (or suppliers') activities.
- Terrorists Interested in spreading propaganda and disruption activities, they generally have less technical capability.
- Foreign governments More likely to use sophisticated attacks, they are generally interested in accessing really sensitive or valuable information that may give them a strategic or political advantage.
- Malicious insiders Use their access to an organisation’s data or networks to conduct malicious activity, such as stealing sensitive information to share with competitors.
- Honest mistakes Sometimes staff, with the best of intentions just make a mistake, for example by emailing something sensitive to the wrong email address.
As a result, it is important to consider what your organisation and your suppliers do, who might be interested in causing harm to them, and what their motives might be?
To understand the threats to your supply chain, it’s useful to think more about what and how the supplier is delivering its services to you, and to consider how these might be targeted.
For instance, if they are providing software, how do you confirm that their development systems are secure and the software has not been tampered with? If staff are being supplied, how can you gain confidence that they have been appropriated screened or vetted? If hardware is being supplied, are any embedded components supplied by third parties, how was the due diligence on these components conducted?
Standard cyber threats might include:
- malware (such as spyware, wiperware or trojans)
- cyber attacks (such as phishing attacks, DDoS attacks, ransomware demands, and business email compromise)
- vulnerabilities from unpatched software or untested hardware components
Further examples of standard cyber threats can be found in the ENISA Threat Landscape report.
As supply chains are complex, there are numerous ways they can be exploited to carry your attacks against your organisation. The table below lists some typical attacks, and the vulnerabilities that they might seek to exploit. Often multiple attacks types are combined, for instance using people to instigate a phishing attack, followed by an attack on a configuration or login information.
| Example supply chain attacks | Vulnerabilities that could be exploited |
|---|---|
| Social Engineering: employees, developers or third party suppliers who have authorised access to your organisation’s systems, networks and data | People who have authorised access to an organisation’s systems, networks and data (this could be employees, developers and third party suppliers) may fall vulnerable to attacks, such as a phishing attack to gain credentials, either by accident or coercion. If a human can be tricked or coerced into providing information, this may be used to gain access to unauthorised systems. |
| Attack pre-existing software: software used by the supplier, web servers, applications, databases, monitoring systems, cloud applications and firmware. | If a supplier uses out of date or unpatched software packages containing vulnerabilities, these could provide a route for attack. Alternatively, a supplier of any pre-existing software used by an organisation may stop providing patches, or the processes and systems it uses to develop and distribute patches may become compromised (as was the case for the SolarWinds attack). |
| Attack code / software libraries: containing collection of pre-written code for re-use, created internally by a supplier or via a third party (such as the Log4J vulnerability). | Software code that is relied upon by your organisation might be uploaded to a public software code repository without your knowledge by a supplier. This code could include sensitive information such as credentials that might prove useful to attackers. It is difficult to ensure the integrity of software and code stored and shared in public software and code repositories. An attacker may also manipulate this publicly available software and code in ways that might provide them future access to your systems and services e.g. a means to gain remote access. This now vulnerable software and code library may have been included in a product, system or service provided by your supplier without your knowledge. |
| Attack on data and configurations: information that you care about and security configurations (such as personally identifiable information of customers and suppliers, IP addresses, passwords, MAC addresses, API keys, firewall rules, URLs, settings and cryptography). | Data may be used, exploited, sold or manipulated breaching the confidentiality and availability of the data. If security configuration information is not secured, it may be possible for threat actors to gain unauthorised access to systems, services and information. |
| Attack via processes: such as backups, updates, signing certificate processes, account creation, credential management. | Tampering of business-critical processes can be dangerous, particularly those that usually help to enforce security (such as account creation or credential management) or those that could enable fraud. Many processes are automated, as such, if they are tampered with in some way, detection may be difficult. |
| Hardware attack: from hardware produced by the supplier such as chips, USBs. | Exploit (such as backdoors) can be embedded into hardware platforms at source and consequently be very difficult to detect. As a result, it might be important to understand where the components are sourced from and ensure that those sources can be trusted. This could be challenging, as often there are limited choices around component manufacturer (and the ability to carry out due diligence may also be limited). |
From these examples, it is clear that you need to understand:
- the type of product or service your supplier is providing
- what information and assets of yours they have access to
Additionally, you should think about this in the context of what you care about and want to protect the most. For more information, refer to Stage 2a. Prioritise your crown jewels.
Cyber vulnerabilities that are exploited by threat actors can have a negative impact on the organisation and the supply chain. They can cause reputational damage, financial losses, and major disruptions to your business operations and/or processes.
As a result, it is important to consider the potential negative impact a supplier relationship can have and understand how much risk your organisation is prepared to take.
Once this is understood in the context of your organisation, it becomes a lot easier to talk about and build a case for senior buy-in and investment to promote change around supply chain cyber security within the organisation.
It may also be beneficial to understand:
Supply chains can be complex, and may involve many different organisations working in very different ways. As a result, there is not really a ‘one size fits all’ approach to assessing supply chain cyber security risk. You should therefore seek to understand risks to your supply chain based on:
- what your suppliers provide to you
- the relationship you have with them
Where commonality exists in terms of types of risk posed, they should be grouped together in some way to make for more efficient cyber security risk analysis or treatment. The table below aims to provide examples of the types of supplier relationships you may have, and the different considerations you may need to make for that type. Of course, this will also depend on the risk appetite of your organisation and the sector in which you operate.
| Type of supplier relationship | Considerations |
|---|---|
| Outsourced service provider An outsourced end-to-end service. | An outsourced service provider runs a service on behalf of a consumer organisation and may have access to privileged accounts, information and networks. The risks are generally similar to if the supplier was running the service, so both organisations should conform to similar security standards.
Security responsibilities between vendor and customer need to be clearly defined via the shared responsibility model, although ownership always remains within the organisation. |
| Maintainer A supplier retained to maintain systems and fix issues. | A supplier retained to maintain your systems and services may require privileged and remote access to your systems and services. If a maintainer (or the systems they use to gain access to your systems and services) are vulnerable, then this could enable threat actors to gain both privileged and remote access to your systems and services.
It is therefore important that anyone in your supply chain uses secure systems to gain access to your systems or services. |
| Manufacturer Produces hardware or software components of a system that may be resold. | Vulnerabilities in a hardware or software product can emerge at any point in its lifecycle. Vulnerabilities can be introduced through poor or insecure design and development practices, and often vulnerabilities don’t become known until the product is in use in operational systems. It is therefore important that you ensure that the products you buy and use are supported, in that the manufacturer has in place a vulnerability management process and the capabilities needed to remediate (patch) newly identified vulnerabilities as quickly as possible.
You should also seek to understand how manufacturers manage newly discovered vulnerabilities, how they include cyber security into their products ‘by design’, and what cyber security testing has taken place as part of the product's lifecycle. |
| Integrator Builds complete systems using a number of discrete pre-built products. | Integrators may be on site, have privileged access, use powerful administration tools and may require remote access. They could introduce vulnerabilities to your systems and services through poor or insecure implementation and integration practices and mis-configurations (such as reuse of an administrator password or an insecure configuration of a sensitive database access). |
| IT support services Outsourcing the support of a business area to a third party, for example, security monitoring via a Security Operations Centre. | The provider may also host other organisation's services, providing a potential high value target for an attacker.
Understanding how the supplier segregates data and platforms from other organisations is a consideration, as well as ensuring that they have a similar level of IT security standards as your own organisation. It is also important to understand who has privileged access to your data and how this is protected. |
| Consultancy Vendors who provide advice, review or analysis of systems or processes. | A consultant with physical access to your premises may increase the risk of manipulation, theft or damage of data, or use of unauthorised tools.
Remote access requires a secure connection, and if the consultants' network is breached this could be used as a staging post.
Depending upon the nature of the assignment a consultant may hold sensitive information, for example if they are conducting a security assessment. |
| Cloud service providers (CSPs) Offer a cloud-based platform, infrastructure, application, or storage services to multiple clients on a shared platform. | Cloud service providers are typically large organisations with high levels of security controls already in place.
As such, there is limited opportunity for negotiation and the security controls availability for the cloud service provision will typically enable good security for a cloud service.
For more considerations on working with Cloud Service Providers see the NCSC's Cloud security guidance. |
| Managed Service Providers (MSPs) Provide a service to multiple clients on a shared platform. | A breach within a single MSP may allow access to multiple organisations, and become an attractive target.
The MSP should provide strong levels of security and provide assurance that data is segregated sufficiently and has good monitoring.
Responsibilities for security and communication channels need to be agreed between vendor and supplier, including when there is a breach in order to co-ordinate activities as required.
Where data is being stored (in particular if within another region or legal jurisdiction) should also be considered. |
| Cloud Resellers Provide a service to resell cloud platforms to clients on a shared platform. | Similar to CSPs and MSPs, a reseller may provide a more boutique service for an organisation and be the middle party between them and the larger cloud supplier.
It is important to understand the depth of the reseller's security standards and what privileges they will retain on the platform, post implementation. |
| Trusted Software Suppliers Provide software and updates that are treated as a known entity and installed into the enterprise as ‘trusted’. | A breach within a high-profile software vendor, who provides software into the enterprise of many thousands of organisations is difficult to achieve and typically a state level endeavour, but does yield a significant ability to target a particular organisation (or many).
Due to the backing of these attacks, they may be difficult to prevent. When engaging with a supplier that you may treat as trusted, it is important to understand their security within the software development lifecycle and what their track record is in preventing and responding to such attacks. |



