Attacks/Breaches
8/6/2014
09:30 AM
Connect Directly
RSS
E-Mail
50%
50%

5 Steps To Supply Chain Security

The integrity of enterprise data is only as strong as your most vulnerable third-party supplier or business partner. It's time to shore up these connection points.

Download the entire
August 2014 issue of
Dark Reading Tech Digest
, distributed in an all-digital format (registration required).

One of the largest known breaches, resulting in 110 million records lost and hundreds of millions of dollars in damages, started with a small, third-party supplier. We're talking about Target, where attackers compromised Fazio Mechanical Services, a provider of heating, ventilation, and air conditioning services, to gain access to the retail giant's network. The breach lasted 19 days and contributed to a 46% drop in year-over-year quarterly profits for the company, according to Target's filings with the Securities and Exchange Commission. Nearly 100 lawsuits have been filed so far, and Target's then CEO, Gregg Steinhafel, and its CIO, Beth Jacobs, have resigned.

"The Target breach is a watershed moment in third-party attacks," says Stephen Boyer, CEO of BitSight, a security intelligence firm. "No one wants to be the next one."

The breach may be a watershed, but it's hardly unique. The August 2013 defacement of The New York Times occurred because attackers fooled the media organization's DNS provider into granting access to the account that determined how the Internet routed traffic to the Times' site. Lockheed Martin suffered an attack through a flaw in RSA's SecurID system. The email addresses of customers who sought support from Twitter, Pinterest, and Tumblr were leaked when attackers breached support services firm Zendesk in February 2013. Security and CDN service CloudFlare was infiltrated via its CEO's Gmail account.

And the beat goes on.

Piggybacking on third-party suppliers is now a well-worn page in attackers' playbooks. Both RSA and whitelisting provider Bit9 suffered compromises, not to steal their data, but to weaken the protections around companies that use their services. IT is aware of the threat; respondents to InformationWeek's 2014 Strategic Security Survey who feel more vulnerable to attack this year than last increasingly point to partners. Those citing an inability to audit or assess outsourcing and/or cloud vendors jumped by nine points year over year, with fears over vulnerability of key technology products shooting up 13 points.

"If I want to attack Fort Knox and I know they have locks and guards and strong security, it is easier to attack one of their providers who already have access to the gold," says James Christiansen, VP of information risk management for Accuvant, an information security service provider.

Adding insult to injury, companies breached via a third party generally find their recovery costs higher. In 2013, the average breach cost for a US firm was $201 per lost record, according to the Ponemon Institute's 2014 Cost of Data Breach Study: Global Analysis report. Third-party involvement was the second most important negative factor in the cost of a breach, costing companies an average of $14.80 more per record, just behind the impact of a lost or stolen device, which added $16.10 per record.

Vendors, Suppliers, Contractors -- Oh, My!
US companies rely heavily on third-party firms to provide services critical to their businesses yet generally have little visibility into the security practices of those firms. While larger suppliers may spend a significant amount on security, there is no guarantee -- and less likelihood -- that smaller partners are making similar investments, says BitSight's Boyer.

In short, supplier-based attacks are particularly scary because they're out of IT's control. "The only real knob or lever you have is the questionnaire," says Boyer, referring to the annual surveys many companies use to assess their suppliers' security and, in theory, prod providers into taking protections more seriously. Some supplier-customer pairs are more likely to be targeted, such as retailers reliant on third-party point-of-sale technology firms, companies attacked via their law firms, and medical information targeted through the doctor's office. But no one is immune.

To read the rest of this story, download the August
Dark Reading Tech Digest, distributed in an all-digital format (registration required).

Robert Lemos is a veteran technology journalist of more than 16 years and a former research engineer, writing articles that have appeared in Business Week, CIO Magazine, CNET News.com, Computing Japan, CSO Magazine, Dark Reading, eWEEK, InfoWorld, MIT's Technology Review, ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/8/2014 | 11:14:27 AM
Re: 110 million? Not so big anymore
Other thing is that one is directly related to your back account and money, the other one is about usernames and passwords mainly and there may not be anything they can get out of that.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/8/2014 | 11:12:13 AM
Re: 110 million? Not so big anymore
That makes sense, however I would think it is less about the number of records more about what results they gate out of attacks.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/8/2014 | 11:10:07 AM
Targetís responsibility
 

Target may be working  with third parties but it is still Target's responsibly to make sure the third part they work with has proper controls in place to avoid a such attack that they faced.  Obviously nobody talks about third part but Target and consumers would hold target responsible.
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Moderator
8/6/2014 | 4:55:10 PM
110 million? Not so big anymore
With reports that a Russian hacking group has amassed over 1 billion logins, 110 million hardly seems noteworthy.

But attacks on supplier equipment are scary. If the bag guys get there first, it's too late.
marklfeller
50%
50%
marklfeller,
User Rank: Apprentice
8/6/2014 | 3:57:50 PM
asada
My last pay check was $9500 working 12 hours a week online. My sisters friend has been averaging 15k for months now and she works about 20 hours a week. I can't believe how easy it was once I tried it out. This is what I do,

 

 

=======================

WWW.JOBS606.COM

======================= 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2003-1598
Published: 2014-10-01
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.

CVE-2011-4624
Published: 2014-10-01
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

CVE-2012-0811
Published: 2014-10-01
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files gene...

CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Chris Hadnagy, who hosts the annual Social Engineering Capture the Flag Contest at DEF CON, will discuss the latest trends attackers are using.