GlossaryCompliance operations

Supply chain attack

Short answer

A supply chain attack compromises an organisation indirectly, by attacking a supplier, software vendor or service provider it trusts. Through a malicious update, a compromised component or a provider's access, one breach can reach hundreds or thousands of customers at once.

How they happen

Attackers insert malicious code into legitimate software updates, as in the SolarWinds case in 2020. They compromise IT service providers and use their remote management tools to reach customers, as in the 2021 attack on Kaseya, which spread ransomware to up to around 1,500 businesses. They publish poisoned open source packages, or exploit a vulnerability in widely used software, such as the MOVEit file transfer tool in 2023, to steal data from many organisations at the same time.

Why they are effective

Customers trust their suppliers' updates and access by default. A single compromise gives the attacker many victims, and the activity often looks legitimate because it comes through an approved channel.

Reducing the risk

Know which suppliers have access to systems and data, and limit that access to what is necessary. Assess critical suppliers through third party risk management and security questionnaires. Monitor supplier access and remote tools. Keep an inventory of software components with an SBOM where possible. Include supplier compromise scenarios in incident response plans.

Regulation

NIS2 requires entities in scope to address supply chain security, including the security practices of their direct suppliers. DORA sets detailed rules for ICT third party risk in the financial sector, and the Cyber Resilience Act raises security requirements for the products themselves.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub