supply chains

5 Questions CISOs Should Ask Vendors

CISOs face a barrage of vendor pitches and rely on targeted questions to identify products that solve real business security problems with clear ROI. They favor vendors who understand specific organizational needs, promote tools that reduce workload, integrate seamlessly, and are transparent about costs and updates. Credibility is built through validated outcomes, real-world examples, and responsiveness to customer input, while vague claims, fear tactics, unnecessary buzzwords, and inflexible pitching are immediate red flags.

https://www.csoonline.com/article/4059801/5-questions-cisos-should-ask-vendors.html

Fifty Years of Open Source Software Supply-Chain Security

Summary: The article discusses the enduring issues of software supply-chain security, highlighting a recent major attack on open source software through the XZ project. It reviews the history of software vulnerabilities, the consequences of supply-chain attacks, and the need for improved security measures such as authentication, vulnerability scanning, and the adoption of safer programming languages. The importance of funding open source projects to prevent security weaknesses is emphasized, drawing parallels to past incidents like Heartbleed. The author advocates for ongoing efforts to bolster defenses against potential attacks, as many fundamental security challenges persist in the industry.

https://cacm.acm.org/practice/fifty-years-of-open-source-software-supply-chain-security/

JPMorgan Chase CISO Warns Software Industry on Supply Chain Security

JPMorgan Chase's CISO Patrick Opet urges the software industry to prioritize secure development over rapid deployment in an open letter, citing risks from interconnected systems and reliance on a few vendors. He highlights past incidents affecting critical infrastructure and advocates for better security standards and transparency regarding third-party access. The letter coincides with discussions at the RSAC Conference on software security, echoing calls for secure-by-design practices.

https://www.cybersecuritydive.com/news/jpmorgan-chase-ciso–software-supply-chain-security/746476/

5 Questions CISOs Should Ask Third-Party Vendors

CISOs must evaluate third-party vendors to mitigate risks, especially as recent data breaches highlight vulnerabilities. Key questions to ask include:

  1. What is the vendor’s overall security program?
  2. What is their security development process?
  3. What are their supply chain practices?
  4. Are their privacy and data protection practices compliant?
  5. Is the vendor insured, and under what terms?

These questions help ensure robust data protection while integrating third-party services. CISOs should be central in vendor selection to prevent potential breaches.

https://www.infosecurity-magazine.com/blogs/5-questions-cisos-should-ask/

Cyberattacks Targeting IT Vendors Intensify, Causing Bigger Losses

Cyberattacks on IT vendors are escalating, resulting in significant financial losses, according to a Resilience report. In 2024, 23% of cyber insurance claims involved third-party breaches, causing operational disruptions and high costs, exemplified by UnitedHealth's $3.1 billion ransomware attack. Ransomware is still the leading cause of cyber claims, but attackers are shifting focus to larger targets for bigger payouts.

https://www.ciodive.com/news/vendor-driven-cyberattacks-losses/741686/

ENISA: Embedding Resilience in Critical Infrastructure

ENISA, led by Marnix Dekker, focuses on enhancing cybersecurity for critical infrastructure in the EU, emphasizing support for smaller suppliers against supply chain attacks. Compliance with the new NIS2 regulations is key to maintaining operational resilience. ENISA aims for harmonized security practices across member states to avoid fragmented approaches that could hurt collective cybersecurity. Dekker's team works on implementing NIS directives and fostering collaboration to aid less-secure sectors.

https://www.databreachtoday.com/enisa-embedding-resilience-in-critical-infrastructure-a-27351

Scroll to Top