New U.S. Intelligence Programs Aim to Stop Supply Chain Cyber Hacks

The latest information sharing initiative is part of a broader campaign to raise awareness about the risks associated with poor supply chain security.


U.S. intelligence agencies are rolling out an exclusive cybersecurity information sharing initiative where American telecommunications, energy and financial services businesses will begin to receive classified threat intelligence reports about hackers who are targeting supply chain operations.

Led by the National Counterintelligence and Security Center, news of the information sharing plan follows a meeting between NCSC Director William Evanina (pictured below) and U.S. telecommunication industry leaders in Washington last month. 

A complimentary video published yesterday by NCSC (view above) also highlights the importance of supply chain security to mitigate threats associated with the theft of intellectual property, trade secrets and research and development methods.

“The supply chain is the interconnected web of people, processes, technology, information and resources that deliver a product or service,” the NCSC video describes. 

The aforementioned classified threat intelligence papers will reportedly begin being distributed to U.S. critical infrastructure developers via “secure channels” in two months, Bloomberg reports.

NCSC Director William Evanina

“You’d be shocked to find out how many people really don’t know where their stuff comes from”NCSC Director William Evanina

The latest information sharing initiative is part of a broader campaign to raise awareness about the risks associated with poor supply chain security, Evanina told Bloomberg. 

Thursday’s announcement represents a continued warning by the U.S. government to be wary about where basic, electronic components - like microchips - in their finished products are manufactured. 

U.S. companies whose supply chains rely on services and products developed in countries that have proven hostile to the U.S., including Russia, China and Iran, should be especially vigilant, U.S. lawmakers have previously warned.

A 2012 House Intelligence Committee report, for example, cautioned U.S. companies from depending on electronic components manufactured by two of China's leading technology firms, Huawei Technologies and ZTE Corp, due to the risk of embedded software and hardware that could enable surveillance capabilities. 

Executives overseeing the Chinese corporations, however, have consistently denied allegations they are influenced by China's communist government. 

U.S. businesses should know where their “stuff is coming from,” Evanina told Bloomberg.

“You might have the best software and cybersecurity programs, but if you don’t have the same due diligence and understanding of the threat for the people who buy the systems that run your buildings and facilities, you’re running the risk of potential compromise.”

But even with the very best threat intelligence available, most businesses will struggle to secure their supply chain processes, said Faizel Makhani, president and COO of cybersecurity company SS8 - a firm which counts many of the world’s largest intelligence agencies, telecommunications providers and critical infrastructure developers as clients. 

“The effort is notable and validates how elusive today’s cyber threats are, and how problematic data breach detection is. But it begs a couple of questions. Will businesses have the time [to react based on an intel report]? And, will it actually help them stop a breach or data exfiltration,” Makhani said in an email to FedScoop.  

“Providing the information is one thing, but doing the actual detection and response of threats is an ongoing practice,” he said, “The intelligence is constantly changing and organizations need automation that takes in the latest intelligence on an ongoing basis and applies it to history to really understand if a compromise has happened and if data is being transmitted.”

Source: FedScoop

Improving Supply Chain Security for Better Business Governance

Download the Paper: Improving Supply Chain Security for Better Business Governance


Article Topics


Modulo News & Resources

Improving Supply Chain Security for Better Business Governance
New U.S. Intelligence Programs Aim to Stop Supply Chain Cyber Hacks

Latest in Supply Chain

Walmart Unleashes Autonomous Lift Trucks at Four High-Tech DCs
Ranking the Best Countries for Private Business in EMEA
Frictionless Videocast: The Importance of Water at the U.S./Mexico Border with Commissioner Maria-Elena Giner, International Boundary and Water Commission
Why are Diesel Prices Climbing Back Over $4 a Gallon?
Plastic Pollution is a Problem Many Companies are Still Ignoring
Luxury Car Brands in Limbo After Chinese Company Violates Labor Laws
80% of Companies Still Unsure How to Best Leverage AI, Study Finds
More Supply Chain

Modulo is the leading global provider of Governance, Risk Management, and Compliance (GRC) and Smart Government solutions. Over 1,000 customers globally leverage Modulo to monitor IT risk through automated workflow; report compliance against industry regulations, standards, and policies; prioritize operational risk through analytics and consistent business metrics; secure cloud environments; identify and remediate the most critical vulnerabilities; and much more. Modulo is the first company in the world to obtain ISO 27001 certification – the international standard for the governance of information security management systems – which guides Modulo’s product development and proven risk reduction life-cycle methodology. Modulo continues to actively lead the creation and definition of International Standards in the GRC space.


View Modulo company profile

 

Featured Downloads

GEP Procurement & Supply Chain Tech Trends Report 2024
GEP Procurement & Supply Chain Tech Trends Report 2024
We’ve researched the five biggest trends in the supply chain space this year, and, drawing on our expertise in procurement and...
Unified Control System - Intelligent Warehouse Orchestration
Unified Control System - Intelligent Warehouse Orchestration
Download this whitepaper to learn Unified Control System (UCS), designed to orchestrate automated and human workflows across the warehouse, enabling automation technologies...

An Inside Look at Dropshipping
An Inside Look at Dropshipping
Korber Supply Chain’s introduction to the world of dropshipping. While dropshipping is not for every retailer or distributor, it does provide...
C3 Solutions Major Trends for Yard and Dock Management in 2024
C3 Solutions Major Trends for Yard and Dock Management in 2024
What trends you should be focusing on in 2024 depends on how far you are on your yard and dock management journey. This...
Packsize on Demand Packing Solution for Furniture and Cabinetry Manufacturers
Packsize on Demand Packing Solution for Furniture and Cabinetry Manufacturers
In this industry guide, we’ll share some of the challenges manufacturers face and how a Right-Sized Packaging On Demand® solution can...