Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

8/20/2015
11:45 AM
Sekhar Sarukkai
Sekhar Sarukkai
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

Beware The Hidden Risk Of Business Partners In The Cloud

Enterprises vastly underestimate the cyber risk from digital connections to vendors, suppliers, agencies, consultants -- and any company with which employees do business.

As more details emerge about the recent mega breach affecting CVS, Costco, Walmart, RiteAid, and Tesco, security experts are zeroing in on an often overlooked element in a company’s cyber defenses: its business partners.

The common thread between these companies is a third-party vendor called PNI Digital Media that provides photo processing websites and services for 19,000 retail locations. Similar to the massive 2013 Target breach in which hackers gained access to the company’s network via an unsecured heating and cooling vendor, it appears hackers leveraged trusted digital connections PNI had to these retailers to compromise their systems.

This recent data breach that began with PNI puts an often-neglected but ubiquitous area of exposure under the spotlight: the partner environment. Enterprises vastly underestimate risk from business partners, which can include vendors, suppliers, agencies, consultants, and any company with which employees do business. One common example is an airline that has a trusted digital connection to a company’s employee travel portal. While many companies perform in-depth analyses of their cybersecurity posture and harden their own internal systems against attack, the scale of connections to business partners and their risk is often unknown.

Consider the behavior of all your organization’s employees online, and then add to that surface area all of your company’s business partners. Even companies with the strictest security and data governance requirements deal with vendors who pay much less diligence to security. This is compounded by the ease of connecting to partners via cloud services.

Skyhigh recently analyzed the partner ecosystem for 400 large enterprises. We identified the cloud as the hub by which modern businesses connect and exchange information. This shouldn’t be a surprise; when was the last time you used a fax machine? The sheer volume of connections, however, is astounding: The average enterprise connects to 1,586 partners via the cloud. This figure is a key data point validating the rapidly maturing cloud economy, but it also points to a vector of attack that many organizations today may not be equipped to defend against.

 

To quantify the risk of these connections, we found that 8% of partners were high-risk. This seemingly reassuring statistic is misleading. Companies sent a disproportionally large amount of data to high-risk partners, with this 8% minority receiving 29% of all shared data. The horror stories among this risky bunch are (almost) enough to make CISOs pull out the fax machine and the USB drive again. We found an partner airline that had 9,717 login credentials for sale on the darknet and 209 devices infected with malware; an advertising agency had 1,565 compromised identities for sale across 29 darknet sites. The risky partners include businesses that potentially deal with sensitive data. The provider of financial services technology had 1,216 compromised identities for sale on the darknet. All three of these businesses had websites still vulnerable to POODLE.

Certain types of partners are particularly dangerous liabilities for enterprises. The nature of PNI’s business highlights the value to hackers of a foothold within a B2B vendor’s network. Large enterprises dwarf PNI in organizational size and security infrastructure, but a breach at a B2B company can also affect its customers’ customers.

Analysis of enterprise cloud usage points to a trend of “super partners” – specifically 58 businesses that act as major cloud hubs. Companies in this tiny minority are extremely “popular” with each super partner connected to over 50% of enterprises. This means a breach within one of these companies could put a large number of enterprises at risk. Worse, the group is less secure than the general partner environment, as 12.5% of super partners are considered high-risk.

While many question the inherent security of the cloud, the risk from business partners shows how factors outside the security capabilities of cloud providers can impact the threat landscape for many organizations. In fact, much of the threat to data in the cloud can be attributed to the enterprise itself, through risky user behavior or insider threat. But what I consider the true security blindspot is the prospect of exfiltration of corporate data through unsanctioned cloud services or high-risk usage by employees of sanctioned, secure cloud services like Box and Office 365. 

Cloud services enable thousands of organizations to share data and collaborate, revolutionizing the way we do work. A new way to work warrants a new security model. Expect a shift to data security as companies become aware of the extent of enterprise cloud adoption and the concomitant webs of cloud traffic.

Sekhar Sarukkai is a co-founder and vice president of engineering at Skyhigh Networks, where he is responsible for engineering and operations. He brings more than 20 years of experience in enterprise networking, security, and cloud services development. Prior to founding ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
JuliaNorma
50%
50%
JuliaNorma,
User Rank: Apprentice
8/25/2015 | 3:06:41 AM
abit risky
Really interesting review. The high risk is pretty big anyway but the cloud is really interesting for most of really huge businessess anyway... You'll just have to deal and anticipate these risks
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-14180
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are...
CVE-2020-14177
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from versio...
CVE-2020-14179
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from...
CVE-2020-25789
PUBLISHED: 2020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE-2020-25790
PUBLISHED: 2020-09-19
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our secu...