Home » Industry News » Transport Logistics Freight News » Supply chain attacks have become an industry of their own

Supply chain attacks have become an industry of their own

Supply chain attacks have become an industry of their own

By CG Selva Ganesh, VP, CEO South Africa at In2IT Technologies

Cybersecurity has traditionally focused on keeping attackers out. To protect their systems, organisations have invested heavily in firewalls, endpoint protection, identity controls, and monitoring.

But defining that perimeter has become more difficult. Modern businesses rely on a growing network of software providers, cloud platforms, SaaS applications, APIs, managed services, and technology partners. While these connections increase organisational efficiency,
they also let attackers reach multiple targets with a single breach.

The result is a fundamental change in supply chain risk. Opportunistic attacks are becoming increasingly systematic, with threat actors deliberately identifying trusted technologies and relationships that can provide access to multiple organisations at once.

The weakest link may not be yours

The attraction of supply chain attacks is straightforward: why compromise 100 organisations individually when compromising one trusted provider could potentially open the door to all of them?

This principle has been shown repeatedly. For example, a compromised software update, stolen vendor credentials, or a malicious third-party component can provide access to companies that otherwise have strong security measures in place.

Recent cyber incidents show how big the problem is, and an examination of supply-chain compromises suggests they have increased greatly in recent years. As the

Center for Strategic and International Studies’ extensive database of cyber incidents shows, attacks are now more likely to exploit technology relationships than to rely on direct intrusion.

Third-party risk is fundamentally different from traditional cybersecurity risk because an organisation may have no control over a supplier’s code, infrastructure, or security practices and, yet still suffer the effects when that supplier is compromised.

SaaS has created a new trust chain

The situation grows even more complicated when we look at how modern SaaS environments connects.

Businesses rarely use cloud applications on their own. For example, a customer relationship management platform might connect to an email service, which in turn connects to a marketing platform, which then exchanges information with an analytics system via
APIs. Each connection creates another relationship that must be trusted.

The problem is that organisations tend to evaluate these applications one by one rather than the whole chain. Even if a SaaS provider has robust security measures, what about the integration that links it to another application? What permissions does the API
have? Which systems can it access? And how often are those credentials checked?

An attacker doesn’t necessarily need to compromise the primary application if they can exploit a weaker connection around it.

That is why third-party risk management should go beyond checking whether a supplier has the right security certifications; organisations need visibility into how their technology ecosystem is connected and where they extend trust.

APIs are becoming part of the attack surface

As businesses become more interconnected, APIs have become essential infrastructure because they let applications communicate, automate processes, and share information without constant human intervention.

However, this efficiency leads to a security problem. In effect, an API acts as a doorway between systems; attackers can use it to move data or trigger actions between trusted environments if the API is misconfigured, has excessive privileges or is not properly
monitored.

Imagine an organisation that allows a third-party application access to customer records via an API; if the integration is compromised, an attacker might access the information without directly breaching the organisation’s main infrastructure.

That is the reason why API security should be incorporated into overall supply chain security. Businesses need know not just who their vendors are, but also what those vendors can access and how they use that access.

Trust should be earned, not assumed

The solution is not to give up third-party technology, since modern businesses cannot operate effectively without it. Instead, organisations should change how they manage trust.

Zero-trust principles form an important foundation. Access must be restricted to business requirements, continuously evaluated, and removed when it is no longer needed. Third-party applications should not be given wide permissions just because they are seen
as trusted partners.

Vendor onboarding also must become more rigorous. Security assessments should examine how a supplier manages credentials, data, APIs, software dependencies, and incident response. Just as important, these assessments should not stop when the contract is signed.

A company that was safe when it was first taken on board can later introduce new risks through a modified architecture, new integrations, or due to compromised credentials. Third-party risk should therefore be continuously managed rather than subject to a yearly
compliance exercise.

Security needs to follow the relationship

As supply chain attacks become more systematic, organisations must realise their attack surface extends beyond the systems they own.

In this area, experienced IT consultants can make a big difference: they can help organizations map their relationships with third parties, audit of SaaS integrations, evaluate vendor security practices, and spot excessive permissions across connected environments.
Moreover, they can implement zero-trust access controls, monitor API trust relationships, and establish procedures for onboarding and offboarding vendors.

Most importantly, they can assist organisations in making the transition from a checklist-based approach to one that is based on risk when it comes to their technology ecosystem.

The aim is not to get rid of all external dependencies since that would be neither practical nor desirable; rather, it is to determine which relationships are most important, what access they have and what consequences would arise if that relationship were
disrupted.

The supply chain is now part of your perimeter

The modern enterprise relies on connections, since these connections generate a great deal of value, but they also provide routes that attackers can take advantage of.

Since threat actors are now becoming more careful in their choice of software providers, SaaS platforms, APIs and other trusted technologies, supply chain security can no longer be treated as a minor aspect of an organisation’s cybersecurity strategy.

The businesses which will be best able to cope with this change are those that understand that the security perimeter does not end where the infrastructure does. It extends to every relationship the business has chosen to trust.

To enquire about Cape Business News' digital marketing options please contact sales@cbn.co.za

Related articles

Electra Mining Africa delivers biggest edition in its 54-year history, connecting industry with technology, expertise and opportunity

Electra Mining Africa delivers biggest edition in its 54-year history, connecting industry with technology, expertise and opportunity Electra Mining Africa has concluded its biggest edition...

Common Boiler And Water Treatment Mistakes To Avoid

Common Boiler And Water Treatment Mistakes To Avoid When it comes to boilers and water treatment, decisions that seem to save money or keep production...

MUST READ

SEW-Eurodrive Puts Energy-Efficient Automation In Focus At Propak Cape

SEW-Eurodrive Puts Energy-Efficient Automation In Focus At Propak Cape SEW-EURODRIVE will showcase its comprehensive MOVI-C® modular automation portfolio at Propak Cape, highlighting how integrated drive...

RECOMMENDED