• Sacramento Region Managed IT and Cloud Services
  • 1 ‪(916) 905-0874
  • [email protected]
locutis_logolocutis_logolocutis_logolocutis_logo
  • HelpDesk
    • Business Tech Support in Sacramento
    • Mobile Computer Repair
    • Virtual CIO
    • Disaster Recovery
    • Recommended Technology Platform
  • Reputation
    • Listings Management
    • Listings Distribution
    • Customer Voice
    • Reputation Management
    • Social Marketing
    • Advertising Intelligence
  • LocalAds
    • Targeted Video & OTT Ads
    • Targeted Display Ads
    • Phone Call Leads
    • Store Visits
    • Form Fill Leads
    • Weather Based Advertising
  • Cloud
    • Web Site Design
      • E-Commerce Development
      • Recent Projects
    • Hosting
      • Managed Hosting
      • Managed E-Mail
      • Self Managed Hosting
      • Servers
      • Business E-Mail
    • Domains
      • Register Domain
      • Transfer Domain
    • SSL Certificates
  • About Us
    • Industries
      • Startup Companies
      • Non Profit Organizations
      • Food Services
    • All Legal Agreements
      • Privacy Policy
      • Terms Of Service
      • Refund Policy
  • Get Help
    • Support Portal
    • Submit A Ticket
    • Remote Support Session
    • By Appointment
    • By Phone
    • By E-Mail
    • Get A Refund
  • Login
    • SoLoMo
    • CloudFilter Quarantine
    • XtraMail
    • CloudMail
    • Plesk WebMail
    • Endpoint Manager
    • Plesk Hosting Panel
    • Domain Control
  • Radar
✕
Laptop, Mouse, Stethoscope, Notebook, Keyboard
What Are the Best Ways to Give an Older PC New Life?
June 25, 2022
Silver Imac on Top of Brown Wooden Table
Are Two Monitors Really More Productive Than One?
July 5, 2022

What You Need to Know About the Rise in Supply Chain Cyberattacks

Cyber, Attack, Encryption, Smartphone, Mobile, Finger

Any cyberattack is dangerous, but the particularly devastating ones are those on supply chain companies. These can be any supplier – digital or non-digital – of goods and services.

We’ve seen several attacks on the supply chain occur in 2021 that had wide-reaching consequences. These are “one-to-many” attacks where victims can go far beyond the company that was initially breached.

Some recent high-profile examples of supply chain attacks include:

  • Colonial Pipeline: A ransomware attack caused this major gas pipeline to be shut down for nearly a week.
  • JBS: The world’s largest supplier of beef and pork products was hit with ransomware that caused plants in at least three countries to shut down for several days.
  • Kaseya: This software company had its code infected with ransomware, which quickly spread to IT businesses that used its products and to roughly 1,500 of their small business customers. 

Why do you need to be worried about supply chain attacks even more so than in the past? Because they’ve been growing and are expected to continue this trajectory.

Supply chain attacks rose by 42% during the first quarter of 2021. A surprising 97% of companies have been impacted by a breach in their supply chain, and 93% suffered a direct breach as a result of a supply chain security vulnerability.

If you’re not properly prepared, then you can be impacted by a breach of software you use or have a vital service or goods supplier go down for several days due to a cyberattack. 

As part of any good business continuity and disaster recovery strategy, you should look at supply chain risks in light of the current increase in attacks and formulate a plan.

How Can You Mitigate Your Risk of Losses Due to an Attack on Your Supply Chain?

Identify Your Supplier Risk

You can’t fix what you don’t know is wrong. So, you need to begin by shedding some light on your risk should one of your vendors get hit with ransomware (the current attack of choice on the supply chain) or another type of breach.

Make a list of all your vendors and suppliers, both for goods and services. This includes everything from the cloud services you use to the company that supplies your office products or any raw materials you may use in a product you sell.

Review these vendors to identify their cybersecurity risks. This is something you may need some help with from your IT partner. We can work with you to review vendor security or send them a survey to find out where they stand as to their cybersecurity, and then determine how much that may leave you at risk as one of their customers.

Create Minimum Security Requirements for Digital Vendors

Come up with some minimum security requirements that you can use as a benchmark with your vendors. One way to make this easier is to use an existing data privacy standard as your requirement. 

For example, if a vendor is GDPR compliant, then you know they’ve adopted several important cybersecurity standards that protect their business, and yours, from an attack.

Do an IT Security Assessment to Learn Where You’re Vulnerable

If the software you use had a vulnerability that was exploited by hackers to take over a system, how much does that leave your systems at risk? Do you have a regular patch application strategy in place to ensure any software updates are applied right away?

You should have an IT security assessment done if you haven’t done one in over a year. This will help you identify how strong your systems would be at preventing a breach or ransomware infection that was coming from a digital supply chain vendor.

Put Backup Vendors in Place Where Possible

If you sell widgets and have a single supplier for one specific part needed for that widget, you’re at a much higher risk of downtime than if you had two suppliers of that part.

If a key vendor of yours is attacked and can’t fill orders or provide services for a week or more, how will that impact your business? This is what you want to consider when setting up backup vendors.

For example, most companies would consider themselves down and not able to operate without their internet. Having a backup internet service provider can help you avoid lengthy downtime should your main ISP go down.

Look at putting this type of safety net in place for all vendors that you can.

Ensure All Data Kept in Cloud Services is Backed Up in a 3rd Party Tool

Microsoft recommends in its Services Agreement that customers back up their cloud data that is kept in its services (such as Microsoft 365). The policy states, “We recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.”

You should have a backup (in a separate platform) of all data that you store in cloud services, so you’ll be protected in case of a ransomware infection or other data loss or service loss incident.

Schedule A Supply Chain Security Assessment

Don’t be in the dark about your risk. Schedule a supply chain security assessment to learn where you could be impacted in the case of a cyberattack on a supplier.

—
Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

Share
0

Related posts

Free photos of Ransomware
November 25, 2022

Simple Guide to Follow for Better Endpoint Protection


Read more
red padlock on black computer keyboard
November 20, 2022

Insider Threats Are Getting More Dangerous! Here’s How to Stop Them


Read more
Free photos of Checklist
November 10, 2022

Checklist for Better Digital Offboarding of Employees


Read more
Free Person Shopping Online Stock Photo
November 5, 2022

9 Urgent Security Tips for Online Holiday Shopping


Read more
Free Close Up of a Keyboard Stock Photo
October 25, 2022

What Is Microsoft Defender for Individuals & What Does It Do?


Read more

    Our Services

    • HelpDesk
    • Reputation
    • LocalAds
    • Cloud
    • About Us
    • Get Help
    • Login
    • Radar

    Get Help Now

    What You Need to Know About the Rise in Supply Chain Cyberattacks
    Customer Service

    1-916-905-0874
    [email protected]

    We are on a mission to help small businesses, recording studios, religious organizations, and entrepreneurs with teams of 5 to 20 members with the hard to understand technological components of their businesses to meet industry standards, allowing them to reach their full potential, so we can grow together.

    © 1998-2022 Locutis IT Services. A Service of Front Line Media inc. All Rights Reserved.
    All Trademarks and Indica are properties of their respective owners.
    • Sacramento Region Managed IT and Cloud Services
    • 1 ‪(916) 905-0874
    • [email protected]

    First Name

    Last Name *

    Company or Family *

    Title

    Email

    Phone


    Fax

    Mobile


    Website


    Industry

    No. of Employees

    Street

    City

    State

    Zip Code

    Country

    Message