Skip to content
Search AI Powered

Latest Stories

Report identifies top supply chain cyber risks

A failure to test systems and lack of clear-cut security policies put companies and their customers at risk.

Screen Shot 2023-04-19 at 9.08.57 AM.png

Rampant cyber security weaknesses are putting supply chains at risk, according to a report from British cyber security company Risk Ledger, released this week.


Risk Ledger’s State of Cyber Security in the Supply Chain 2023 report is based on proprietary data from more than 2,500 suppliers on the company's risk management platform. The findings identify the 12 most common weaknesses among suppliers, especially third-tier suppliers and others that are further down a company’s supply chain.

Risk Ledger defines third-party suppliers as external companies that a business uses to provide a service as part of their own delivery or a company that provides elements of a product they make. According to the report, 40% of third-party suppliers do not conduct regular penetration tests of internal systems and 32% do not have a supplier security policy that outlines the security requirements that their suppliers should meet—which puts their own and their customer’s data at risk, according to the report.

“Attackers are targeting under-resourced suppliers with weaker defenses as a way of disrupting or compromising larger organizations,” the company wrote in a statement describing the findings. “The notable ransomware attack on a supplier to semiconductor giant Applied Materials is expected to lead to $250 million in lost sales. With well over 60% of organizations having suffered a data breach through a third party, this regularly results in regulatory fines, huge data recovery costs and loss of consumer trust.”

Two of the top 12 weaknesses revealed in the report include:
  • 17% of suppliers do not enforce multi-factor authentication (MFA) on all remotely accessible services. MFA requires a second source of validation before granting users access to a device or service—in addition to entering a password, the user may also be asked for a code or fingerprint, for example. MFA is the simplest, most effective way to keep hackers out of your online accounts, according to Risk Ledger, but it can be cumbersome for users and is therefore often provided as an optional setting that needs to be intentionally configured. “This often leaves MFA disabled and the accounts vulnerable to unauthorized access through password theft,” according to the report.
  • 23% do not use “Privileged Access Management” controls to securely manage the use of privileged accounts, which are the ultimate target for attackers. With high privileges, an attacker can access more sensitive (and more valuable) data, and modify security detection tools to cover their own tracks.
The report explains that these weaknesses are common causes of cyber security incidents, and that a high proportion of third-, fourth-, and fifth-party suppliers are not using controls to protect themselves or their customers in these areas. It also offers recommendations by cyber security experts for improving companies’ third-party risk management strategies, including benchmarking data.

Recent

More Stories

reagan national DCA airport photo

Reagan National airport plans to reopen today after deadly crash

All flights remained grounded this morning at Washington, D.C.’s Reagan National Airport (DCA) following the deadly mid-air crash last night between a passenger jet and an Army helicopter.

In a statement, DCA airport officials said they would open the facility again today for flights after planes were grounded for more than 12 hours. “Reagan National airport will resume flight operations at 11:00am. All airport roads and terminals are open. Some flights have been delayed or cancelled, so passengers are encouraged to check with their airline for specific flight information,” the facility said in a social media post.

Keep ReadingShow less

Featured

Jump Start 25 conference opens in Atlanta

Jump Start 25 conference opens in Atlanta

Artificial intelligence (AI) and the economy were hot topics on the opening day of SMC3 Jump Start 25, a less-than-truckload (LTL)-focused supply chain event taking place in Atlanta this week. The three-day event kicked off Monday morning to record attendance, with more than 700 people registered, according to conference planners.

The event opened with a keynote presentation from AI futurist Zack Kass, former head of go to market for OpenAI. He talked about the evolution of AI as well as real-world applications of the technology, furthering his mission to demystify AI and make it accessible and understandable to people everywhere. Kass is a speaker and consultant who works with businesses and governments around the world.

Keep ReadingShow less
trends in robotics

IFR: five trends will drive robot growth through 2025

As the global market value of industrial robot installations passes its all-time high of $16.5 billion, five trends will continue to drive its growth through 2025, according to a forecast from the International Federation of Robotics (IFR).

That is important because the increased use of robots has the potential to significantly reduce the impact of labor shortages in manufacturing, IFR said. That will happen when robots automate dirty, dull, dangerous or delicate tasks – such as visual quality inspection, hazardous painting, or heavy lifting—thus freeing up human workers to focus on more interesting and higher-value tasks.

Keep ReadingShow less
graphic of cargo in motion

Disruption events to global supply chains rose 38% over 2023

Overall disruptions to global supply chains in 2024 increased 38% from the previous year, thanks largely to the top five drivers of supply chain disruptions for the year: factory fires, labor disruption, business sale, leadership transition, and mergers & acquisitions, according to a study from Resilinc.

Factory fires maintained their position as the number one disruption for the sixth consecutive year, with 2,299 disruption alerts issued. Fortunately, this number is down 20% from the previous year and has declined 36% from the record high in 2022, according to California-based Resilinc, a provider of supply chain resiliency solutions.

Keep ReadingShow less
chart of cargo theft in 2024

Cargo theft activity set new highs in 2024

Cargo theft activity across the United States and Canada reached unprecedented levels in 2024, with 3,625 reported incidents representing a stark 27% increase from 2023, according to an annual analysis from CargoNet.

The estimated average value per theft also rose, reaching $202,364, up from $187,895 in 2023. And the increase was persistent, as each quarter of 2024 surpassed previous records set in 2023.

Keep ReadingShow less