Cyber-threats are increasing with the transformation of digital life in the wake of the pandemic. A risk-based approach is needed to safeguard the software and systems that underlie digital supply chains. The procurement process, third-party agreements and source code are areas of concern, write GEORGES DE MOURA and CHRISTOPHE BLASSIAU.

The ongoing digital transformation has opened up a whole new way of living and working. As deeper performance insights and new levels of connectivity allow businesses to reap the benefits of breakthrough technologies, the world is becoming faster, more flexible and more efficient.

This shift is creating a global ecosystem where physical and digital things are increasingly connected, from critical infrastructure assets to people and data.

A study by Gartner finds that in 2019, 60% of organisations worked with more than 1 000 third parties, and those networks are only expected to grow. Other research by Deloitte shows that 40% of manufacturers had their operations affected by a cyber-incident during 2019. And in 2018, the average financial impact of a data breach in the manufacturing industry was $7.5 million.

Moreover, global technology supply chains are increasingly diverse and complex, resulting in changes in the overall risk for critical systems that support national defence, vital emergency services and critical infrastructure.

In December 2020, a global cyber-intrusion campaign was uncovered by a leading cybersecurity firm that compromised first the source code and then subsequently updates to SolarWinds’ Orion Platform, a widely deployed IT management software product. The corrupted update was downloaded by thousands of SolarWinds customers and spanned US government agencies, critical infrastructure entities and private-sector organisations. Though this cyber-attack may be unprecedented in scale and sophistication, it is consistent with a number of persistent trends in using supply chain vectors.
This incident further reinforced the threat to global digital supply chains and the strategic imperative for public and private sector stakeholders to ensure trust in the digital ecosystem. It is critical that the software that drives the digital ecosystem is both trusted and secured. By reducing the risks and protecting the digital economy, our society will be able to realise the digital dividends of the Fourth Industrial Revolution.

The following core principles will contribute to a more secure and resilient supply chain and help move the needle on mitigating this complex and multifaceted challenge:

1. Embed security and privacy in the procurement process and life cycle
Having a mature third-party risk-management policy and practice will ensure cybersecurity and privacy are constantly considered and addressed with mature, consistent, repeatable and effective measures. These three precepts will embed them in every phase of the life cycle:
Cybersecurity and privacy are built-in requirements of the procurement processes from sourcing to off-boarding
All procurement contracts shall stipulate and contain clear and precise clauses that enforce continual compliance with cybersecurity and privacy requirements.
Security and privacy obligations shall be continuously reviewed and optimised to keep up with the evolving threats.

2. Take a risk-based approach in assessments of third parties
A risk-based approach will help guide the third-party acceptance/rejection decision-making process, and helps efficiently and accurately mitigate cybersecurity threats third parties pose to the broader ecosystem.
A risk-based approach improves the assessment of third parties’ security posture. By applying risk measurement and ratings tools and other trusted methodologies, organisations can better identify and rank third-party relationships by risk criticality.
It ensures an accurate appreciation of risk, helps establish the measures third parties must take to mitigate their risks before entering an agreement with an entity and enable regular and/or continuous security performance monitoring.
It contributes to a collaborative and valuable outcome for an organisation and its broader ecosystem.
It helps tailor mitigation plans and scale efforts and resources that ensure trustworthy, secure, privacy-protective and resilient products, systems and services. But it also helps third parties better understand gaps in their own security posture and, ultimately, demonstrate their cybersecurity maturity to their customers and stakeholders.

3. Implement a source code policy and secure-by-design development
Such a policy aims to reduce the risks around the development, management and distribution of software and software source code, which must go beyond defending intellectual property and address customer impact. It will help protect and strengthen trust in the digital ecosystem so businesses, governments and individuals can all have trust in, contribute to and benefit from the digital economy.

The policy should apply to all source code written by or on behalf of an organisation and must ensure that any source code is not tampered with, does not contain any known unmitigated security vulnerabilities and contains a licence that is compatible with the company’s other policies. It also prevents source code from being dynamically linked to third-party hosted source repositories. When third-party code is used as part of a software/firmware solution, the organisation is responsible for change management as part of a secure development process.

The policy also controls and governs all aspects of how the source code is stored and transmitted, including, but not limited to authorization and access, residency, protection at rest and protection in transit.
Ensuring compliance to this policy will help reduce the threat of source code leakage, improves secure access and enables the traceability of any third-party code. Additionally, source-code development must include security and privacy in the design phase, and evidence of threat modelling must be documented.

The policy should be based on widely recognised frameworks such as the NIST framework to establish secure-by-design development practices, covering four areas:
1. Ensure that the organisation’s people, processes and technology are prepared to perform secure software development at the organisation level and, in some cases, for each individual project.
2. Protect all components of the product from tampering and unauthorised access
3. Produce well-secured products that have minimal security vulnerabilities in its releases.

4. Identify vulnerabilities in product releases and respond appropriately to address them and prevent similar vulnerabilities from occurring in the future.

By regularly assessing the security posture of third parties, from early sourcing stages, to security due diligence and periodically throughout the duration of a collaborative relationship, an organisation will be able to maintain trust with its customers and business partners across the supply and value chains.

A common understanding and approach to existing and emerging threats will enable industry and government actors to implement appropriate countermeasures to mitigate supply chain security risks. In the fallout of the SolarWinds incident, it is crucial all stakeholders in the supply and value chains embrace a risk-informed cybersecurity approach to ensure a secure and resilient ecosystem.

The IMM Graduate School, one of Africa’s foremost online education providers specialising in marketing, supply chain and business disciplines, has added two new supply chain management qualifications to its arsenal: A Higher Certificate in Supply Chain Management and BCom Honours in Supply Chain Management. For more information, click here.

Global technology supply chains are increasingly diverse and complex, resulting in changes in the overall risk for critical systems that support national defence, vital emergency services and critical infrastructure.

By reducing the risks and protecting the digital economy, our society will be able to realise the digital dividends of the Fourth Industrial Revolution.

©Republished with permission from the World Economic Forum in accordance with the International Public License.

Georges de Moura is Head of Industry Solutions, Platform for Shaping the Future of Cybersecurity and Digital Trust at the World Economic Forum.
Christophe Blassiau is Senior Vice-President, Cybersecurity and Global CISO, at. Schneider-Electric.


Subscribe to stay informed whenever a new issue is published

Subscribe now