{"id":9625,"date":"2021-08-03T09:05:17","date_gmt":"2021-08-03T13:05:17","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=9625"},"modified":"2021-08-04T08:34:38","modified_gmt":"2021-08-04T12:34:38","slug":"review-of-third-party-security-critical-to-limit-attacks","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/review-of-third-party-security-critical-to-limit-attacks\/","title":{"rendered":"Review Of Third-Party Security Critical To Limit Attacks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Companies that lull themselves into complacency are exposed to the risk of supply chain attacks even if they have done their due diligence in assessing the security of their third-party suppliers before entering into a partnership.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies would typically give their third-party suppliers &#8220;the keys to their castle&#8221; after routinely reviewing the vendor&#8217;s history and systems, said Steve Turner, a New York-based Forrester analyst who studies security and risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Third-party vendors should be able to deal with irregular activity in their systems and have an adequate security architecture to prevent downstream effects, he added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hamza Siddique, head of cybersecurity at Capgemini Southeast Asia, noted that technical controls and policies from third-party vendors or supply chain partners were not always consistent with their customer&#8217;s capabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This created another attack surface or an easy target in the customer&#8217;s network and could lead to risks associated with operations, compliance and brand reputation, Siddique said in an email interview.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To better mitigate such risks, he recommends a third-party risk management strategy that draws on best practices from NIST and ISO standards, including the need for regular audits, planning for third-party response to incidents, and implementing limited and restricted access mechanisms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to containment and recovery, the consulting company&#8217;s service portfolio also includes support for its customers in establishing a strategy for recognition and analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The defense strategy of companies against ransomware attacks must also go beyond the mere purchase of products and deal with the configuration of the systems and their architecture.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It was stressed that third-party systems should be regularly re-evaluated or, if this were not possible, that organizations should have tools and processes in place to protect themselves against downstream attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This may be more difficult for small and medium-sized enterprises that do not have the resources or know-how to do so, which typically rely on their managed service providers to provide these services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cyberattacks can be divided into different parts and delivered by a number of threat actors with expertise in each part of the attack. One could be instructed to build the malware while other subsidiaries focus on breaking through a network and developing the exploit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware attacks have also evolved into multi-layered exploitation, with cybercriminals seeing data theft as more lucrative than a disruption of service.<\/p>\n\n\n<p>For more information, read the <a href=\"https:\/\/www.zdnet.com\/article\/constant-review-of-third-party-security-critical-as-ransomware-threat-climbs\/\" target=\"_blank\" rel=\"noopener\">original story<\/a> in ZDNet.<\/p>","protected":false},"excerpt":{"rendered":"<p>Companies that lull themselves into complacency are exposed to the risk of supply chain attacks even if they have done their due diligence in assessing the security of their third-party suppliers before entering into a partnership.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-9625","post","type-post","status-publish","format-standard","hentry","category-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/9625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=9625"}],"version-history":[{"count":4,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/9625\/revisions"}],"predecessor-version":[{"id":9666,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/9625\/revisions\/9666"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=9625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=9625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=9625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}