Skip to content
Search AI Powered

Latest Stories

Report identifies top supply chain cyber risks

A failure to test systems and lack of clear-cut security policies put companies and their customers at risk.

Screen Shot 2023-04-19 at 9.08.57 AM.png

Rampant cyber security weaknesses are putting supply chains at risk, according to a report from British cyber security company Risk Ledger, released this week.


Risk Ledger’s State of Cyber Security in the Supply Chain 2023 report is based on proprietary data from more than 2,500 suppliers on the company's risk management platform. The findings identify the 12 most common weaknesses among suppliers, especially third-tier suppliers and others that are further down a company’s supply chain.

Risk Ledger defines third-party suppliers as external companies that a business uses to provide a service as part of their own delivery or a company that provides elements of a product they make. According to the report, 40% of third-party suppliers do not conduct regular penetration tests of internal systems and 32% do not have a supplier security policy that outlines the security requirements that their suppliers should meet—which puts their own and their customer’s data at risk, according to the report.

“Attackers are targeting under-resourced suppliers with weaker defenses as a way of disrupting or compromising larger organizations,” the company wrote in a statement describing the findings. “The notable ransomware attack on a supplier to semiconductor giant Applied Materials is expected to lead to $250 million in lost sales. With well over 60% of organizations having suffered a data breach through a third party, this regularly results in regulatory fines, huge data recovery costs and loss of consumer trust.”

Two of the top 12 weaknesses revealed in the report include:
  • 17% of suppliers do not enforce multi-factor authentication (MFA) on all remotely accessible services. MFA requires a second source of validation before granting users access to a device or service—in addition to entering a password, the user may also be asked for a code or fingerprint, for example. MFA is the simplest, most effective way to keep hackers out of your online accounts, according to Risk Ledger, but it can be cumbersome for users and is therefore often provided as an optional setting that needs to be intentionally configured. “This often leaves MFA disabled and the accounts vulnerable to unauthorized access through password theft,” according to the report.
  • 23% do not use “Privileged Access Management” controls to securely manage the use of privileged accounts, which are the ultimate target for attackers. With high privileges, an attacker can access more sensitive (and more valuable) data, and modify security detection tools to cover their own tracks.
The report explains that these weaknesses are common causes of cyber security incidents, and that a high proportion of third-, fourth-, and fifth-party suppliers are not using controls to protect themselves or their customers in these areas. It also offers recommendations by cyber security experts for improving companies’ third-party risk management strategies, including benchmarking data.

The Latest

More Stories

screenshot of map of shipping risks

Overhaul lands $55 million backing for risk management tools

The supply chain risk management firm Overhaul has landed $55 million in backing, saying the financing will fuel its advancements in artificial intelligence and support its strategic acquisition roadmap.

The equity funding round comes from the private equity firm Springcoast Partners, with follow-on participation from existing investors Edison Partners and Americo. As part of the investment, Springcoast’s Chris Dederick and Holger Staude will join Overhaul’s board of directors.

Keep ReadingShow less

Featured

Report: Five trends in AI and data science for 2025

Report: Five trends in AI and data science for 2025

Artificial intelligence (AI) and data science were hot business topics in 2024 and will remain on the front burner in 2025, according to recent research published in AI in Action, a series of technology-focused columns in the MIT Sloan Management Review.

In Five Trends in AI and Data Science for 2025, researchers Tom Davenport and Randy Bean outline ways in which AI and our data-driven culture will continue to shape the business landscape in the coming year. The information comes from a range of recent AI-focused research projects, including the 2025 AI & Data Leadership Executive Benchmark Survey, an annual survey of data, analytics, and AI executives conducted by Bean’s educational firm, Data & AI Leadership Exchange.

Keep ReadingShow less
aerial photo of port of miami

East and Gulf coast strike averted with 11th-hour agreement

Shippers today are praising an 11th-hour contract agreement that has averted the threat of a strike by dockworkers at East and Gulf coast ports that could have frozen container imports and exports as soon as January 16.

The agreement came late last night between the International Longshoremen’s Association (ILA) representing some 45,000 workers and the United States Maritime Alliance (USMX) that includes the operators of port facilities up and down the coast.

Keep ReadingShow less
Logistics industry growth slowed in December
Logistics Managers' Index

Logistics industry growth slowed in December

Logistics industry growth slowed in December due to a seasonal wind-down of inventory and following one of the busiest holiday shopping seasons on record, according to the latest Logistics Managers’ Index (LMI) report, released this week.

The monthly LMI was 57.3 in December, down more than a percentage point from November’s reading of 58.4. Despite the slowdown, economic activity across the industry continued to expand, as an LMI reading above 50 indicates growth and a reading below 50 indicates contraction.

Keep ReadingShow less
pie chart of business challenges

DHL: small businesses wary of uncertain times in 2025

As U.S. small and medium-sized enterprises (SMEs) face an uncertain business landscape in 2025, a substantial majority (67%) expect positive growth in the new year compared to 2024, according to a survey from DHL.

However, the survey also showed that businesses could face a rocky road to reach that goal, as they navigate a complex environment of regulatory/policy shifts and global market volatility. Both those issues were cited as top challenges by 36% of respondents, followed by staffing/talent retention (11%) and digital threats and cyber attacks (2%).

Keep ReadingShow less