ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Supply chain cyber risk: a top priority in 2022

global supply chain cyber risks
global supply chain cyber risks

Ewen O’Brien at BlueVoyant explores the third-party cyber risk landscape and lays out a roadmap for how businesses can go about reducing their risk

 

Today, our extended and highly interconnected business ecosystem means that it is challenging for organisations to adequately secure their supply chain. In our modern world, organisations are working with more and more external parties and in the past five years the use of third-party vendors, which make up the supply chain, has increased exponentially. 

 

In fact, many companies now outsource core functions to derive greater efficiencies and cost savings, from Human Resources (HR) to recruitment to cloud hosted vendors to legal and marketing. According to a 2019 Deloitte survey, 70% of organisations have moderate to high dependency on external suppliers, with Deloitte’s 2022 global third-party risk management survey indicating that this has risen to 73%. This means they are exposing themselves to high-profile risks at an unprecedented level. 

 

Maintaining oversight of third parties 

The biggest challenge going forward will be for organisations to provide the appropriate oversight to these third parties before it is too late. BlueVoyant’s 2021 Global Insights Report: Supply Chain Risk highlighted that a staggering 93% of the organisations surveyed had experienced a direct cyber security data breach because of weaknesses in their supply chain. The average number of times they said they were breached in a 12-month period was 3.7.

 

Attackers see the interconnected ecosystem as an easy target. Both nation state adversaries and advanced criminal groups regularly scan internet-facing systems of vendors to identify soft and easy targets. 

 

Companies have hundreds, if not thousands of suppliers and some of these, particularly small and medium sized suppliers in the long tail, are poorly defended. That said, even a normally well-defended supplier regularly makes changes to its firewalls and defensive systems and occasionally makes a mistake – creating periodic vulnerabilities. 

 

Emerging cyber vulnerabilities

Zero-day and other emerging vulnerabilities are growing in frequency. New zero-day vulnerabilities and other emerging threats are discovered every year in widely used technologies. For example, the number of vulnerabilities in 2021 was 28,000.This illustrates the size of the problem, with some of the most high-profile vulnerabilities including Log4Shell, Solar Winds, Kaseya, and F5.

 

For example, Log4Shell was a critical vulnerability in the logging tool Log4j, used by millions of computers around the world that run online services. A wide range of organisations, governments and individuals were affected by it.

 

Although fixes have been issued many organisations still need to implement these. If left unfixed, attackers can break into systems, steal log in credentials, extract data, and infect networks with malicious software. Log4j is used worldwide across software applications and online services, and the vulnerability requires very little expertise to exploit. 

 

This makes Log4Shell potentially the most dangerous cyber vulnerability in recent years.

 

The speed at which adversaries exploit such vulnerabilities is also accelerating. For example, the average time to exploit vulnerabilities in 2020 was 42 days, decreasing to 12 days in 2021, as adversaries become smarter. This means that organisations are involved in a continuous battle as cyber criminals rapidly take advantage of new vulnerabilities.

 

A concerning delta between detection and patching  

That said, the average time for an organisation to detect a vulnerability is relatively fast. In the case of recent incidents, Kaseya took two hours and Solar Winds, F5 and Microsoft Exchange were three hours.

 

However, the average time to patch in 2022 is considerably slower, at 205 days. For most of the top exploited vulnerabilities, researchers or other actors released a proof of concept (POC) code within two weeks of the vulnerability’s disclosure, facilitating exploitation by a broader range of adversaries.

 

The US Government has published a list of the top 15 routinely exploited vulnerabilities here and many of these are still being exploited today. Admittedly, to a lesser extent, malicious cyber actors also continue to exploit publicly known, dated software vulnerabilities—some of which were also routinely exploited in 2020 or earlier.

 

The exploitation of older vulnerabilities demonstrates the continued risk to organisations that fail to patch software quickly enough, or that use software that is no longer supported by a vendor.

 

In fact, the delta between the average time to exploit vulnerabilities and the time to patch demonstrates that historic approaches to managing third-party cyber risk management do not work. As soon as a vulnerability is found, it is a race between businesses and cyber criminals.

 

When a business does realise that a vulnerability has been exploited, they will first check their own systems. In general, large enterprises tend to have better cyber defences than those of their supply chain ecosystem. Often that is because their suppliers don’t have the resources and/or people power to take actions. As a result, checking for vulnerabilities within the supply chain can take days, if not weeks and months.

 

Outsourcing third party cyber risk services

Ultimately, organisations and their suppliers need better risk identification so that they can supplement common standard, periodic point in time assessments and questionnaires, to solutions that identify, validate, prioritise, and confirm mitigation of cyber threats and vulnerabilities.

 

To reduce risk, they ideally need a fully operationalised outsourced third-party cyber risk service, which can rapidly identify externally visible critical cyber security vulnerabilities and issues in a customer’s third-party ecosystem, working directly with the vendor to resolve such issues. Cross-supply chain vulnerability analytics need to be produced in minutes, with dialogue starting with the supply chain ecosystem within hours, instead of days and weeks.

 

Businesses looking for a third-party cyber risk managed services approach shouldn’t be worried about having to start their third-party analysis from scratch. They should think of external third-party cyber risk companies as an accelerator of this process. 

 

To better manage third-party cyber risk, organisations need to see this as a continuous process, through taking a preventative – rather than reactive – approach. Compliance and governance must go together, mitigating risk while enhancing rewards, and positively impacting reputation and the bottom line.

 


 

Ewen O’Brien is Vice President Third Party Cyber Risk at BlueVoyant

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543