Editor's Choice


Cybersecurity for operational technology: Part 3: Third-party supplier risks to OT Systems

October 2021 Editor's Choice

According to a recent World Economic Report, the Covid-19 pandemic has increased our reliance on the global supply chain, while the Internet has accelerated the digitisation of business processes(1). To remain competitive, manufacturing companies are increasing their reliance on suppliers to help adopt 4IR innovations such as Artificial Intelligence, Machine learning, IoT and Big Data. This has exponentially increased risks from a cybersecurity perspective. As supply chains have become integrated, interconnected and increasingly complex, supply chain cyber-attacks are on the increase as they are very effective. Suppliers are most likely the second or third biggest risk in terms of cybersecurity.

The SolarWinds hack

A supply chain attack targets third-party suppliers who already have access to their customer’s systems. This is easier than trying to hack customer’s systems directly. This is effective as it hides the malware inside trusted software which is then distributed to thousands of customers. A recent example is the SolarWinds hack – one of the largest ever recorded cyber-attacks(2). SolarWinds provides tools for thousands of organisations to monitor their IT networks and infrastructure systems. Early in 2020, hackers used an inadvertently sent out software update to customers that included the hacked code(3). The exploit created a backdoor through which hackers could gain access to customer’s IT systems. Hackers could then access system files, exfiltrate or alter data and impersonate user accounts. The backdoor could also be used to install more malware, allowing them to escalate and maintain their hold on IT systems. The malware went undetected for months. This affected up to 18 000 customers, including critical agencies in the US government. More than 80% of the targets were Fortune 500 companies, i.e. Microsoft, Cisco, Intel and Deloitte.

This was a complex attack and required material resources. Nation-state hackers are believed to have been responsible, i.e. Russia’s Foreign Intelligence Service, known as the SVR. The real danger to enterprises is that once this approach has been used, it is out in ‘the wild’ and can be re-used or modified by other groups with far fewer resources.

Supply chain attacks are only one of the cyber risks from third-party suppliers. Here are a few more to take note of:

• New vendors and technologies are emerging all the time. IoT devices are a major concern as the focus is mass-producing low-cost connected devices, not protecting customers from cybersecurity threats.

• Support staff accessing your systems on-site or remotely with insecure connections or devices. This can introduce malware or open your systems to new vulnerabilities.

• Insecure software development can result in software being installed that can be easily exploited. This is especially risky with Internet-facing systems.

• Improperly trained support staff who neglect to apply basic security configurations.

• Insecure configurations of cloud and or software as a service are also common.

Assessing the risks

Regular risk assessments need to be conducted on third-party providers to address all the potential risks that they can introduce to your organisation. This will identify, assess, measure and monitor any risks associated with the relationship. The next step is to implement mitigating controls to address the risks. Third-party providers need to be effectively managed throughout the whole ‘Vendor Lifecycle’ from selection and on-boarding to off-boarding. Suppliers need to be challenged about their approach to cybersecurity and what security certifications and frameworks they have adopted. If they develop software or are a cloud or SaaS provider, they should have mature, secure development processes and apply cloud security principles(4).

Secure development applies fundamental, sound and secure software development practices based on established best-practice documents from organisations such as BSA, OWASP and SAFECode(5). If they do not have anything in place, they should commit to a prioritised roadmap to improve their cybersecurity posture. Procurement and IT should build a cyber-reputation scorecard and avoid suppliers with a poor record. This will require effective and regular threat intelligence. Threat intelligence is information that helps organisations understand, identify, prevent and respond to security threats(6). Supplier contracts should be updated to address cybersecurity and introduce penalties should breaches be resulting from any negligence.

Targeted cybersecurity training should be conducted for OT and procurement staff. Adopting a best-practice cybersecurity framework is important. This provides an holistic view of what is needed and will help establish your organisations’ current level of maturity and provide a roadmap for improvement going forward. This will be covered in detail in the next article.

References

(1)WEF, 2021 Advancing Supply Chain Security in Oil and Gas: An Industry Analysis http://www3.weforum.org/docs/WEF_Advancing_Supply_Chain_Security_in_Oil_and_Gas_2021.pdf

(2)Business Insider, 2021 - The US is readying sanctions against Russia over the SolarWinds cyber attack. Here’s a simple explanation of how the massive hack happened and why it’s such a big deal, https://www.businessinsider.com/solarwinds-hack-explained-government-agencies-cyber-security-2020-12?IR=T

(3)Chatham House, 2021 - The SolarWinds hack: A valuable lesson for cybersecurity,

https://www.chathamhouse.org/2021/02/solarwinds-hack-valuable-lesson-cybersecurity?gclid=EAIaIQobChMIhOT948Lp8gIVGqd3Ch0fTw0_EAAYBCAAEgJjZvD_BwE

(4)Cloud Security Alliance, https://cloudsecurityalliance.org/

(5)Nist, 2021 - Secure Software Development Framework, https://csrc.nist.gov/projects/ssdf

(6)ZeroFOX, 2021 - What is External Threat Intelligence, https://www.zerofox.com/blog/what-is-external-threat-intelligence/


About Bryan Baxter


Bryan Baxter.

Bryan Baxter has been in the IT Industry since 1992 in various roles before recently joining Wolfpack Information Risk. He has helped customers successfully manage and deliver IT infrastructures to around 7000 users in several countries, where, of course, the recurring theme has been keeping customers secure from cybersecurity threats. For more information contact Bryan Baxter, Wolfpack Information Risk, +27 82 568 7291, [email protected], www.wolfpackrisk.com


Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Loop signature 22: How cyclical disturbances affect a control loop
Michael Brown Control Engineering Editor's Choice
When tuning noisy loops, we recommend in our courses that one should eliminate the noise by editing it out, so the tuning will be done only on the true process response, free of any noise. The controller is controlling the process, and is not controlling the noise.

Read more...
High-performance motion control for teabag packaging machine
Beckhoff Automation Editor's Choice
Teepak relies on PC-based control and drive technology from Beckhoff to set new benchmarks for speed and precision in its teabag packaging machines.

Read more...
VEGA takes the pressure out of water pressure measurement
VEGA Controls SA Editor's Choice
Water treatment systems in metropolitan areas require careful monitoring and management processes across widespread networks. However, process plants choosing VEGA for their process automation know that the company offers more than just precise and reliable pressure sensors and instrumentation.

Read more...
Advantages of wireless storage tank and container tank level monitoring
Turck Banner Southern Africa Editor's Choice
Implementing a tank monitoring system that utilises ultrasonic or radar sensors in a wireless network has many advantages.

Read more...
Bringing Industry 4.0 to a castings foundry for heavy industries
Editor's Choice
Moving to Industry 4.0 takes time and determination, especially for an established company in a heavy industry. Castings foundry, POK in Mexico has moved toward Industry 4.0 in a series of steps over several years, changing from manual to automated systems for more available, immediate and reliable data.

Read more...
SMOM – the future is here now
Iritron Editor's Choice IT in Manufacturing
In his presentation at the recent MESA Africa conference, Neels van der Walt, business development manager at Iritron, revealed the all-encompassing concept of smart mining operations management (SMOM), and why it is inextricably linked to the future of worldwide mining operations.

Read more...
Navigating disruption in manufacturing
Editor's Choice IT in Manufacturing
When considering IT in manufacturing, the underlying assumption is twofold: first, a wave of valuable maturing technologies can be harnessed to create new business value, and second, the environment in which these technologies will be applied will be relatively predictable, with change following a manageable, evolutionary path. However, recent disruptions have shattered these assumptions.

Read more...
The fascination of movement
Editor's Choice Motion Control & Drives
A motor from Faulhaber provides gentle motion for the finest watches in the world.

Read more...
Complete system for transparent energy monitoring
Beckhoff Automation Editor's Choice Electrical Power & Protection
Transparent energy monitoring reduces both machine downtime and the necessity to oversize the corresponding components. Added to these advantages are simplified preventive maintenance, and increased production efficiency. The wide range of PC-based control technology from Beckhoff offers a solution that can be optimally adapted to individual applications.

Read more...
Iritron’s year of consolidation
Iritron Editor's Choice System Integration & Control Systems Design
Despite the multiple challenges faced by businesses in South Africa, the buoyancy of the technology sector worldwide has produced some green shoots for automation specialist, Iritron.

Read more...