logo

Assessing and mitigating supply chain cybersecurity risks

ID: fca8515e-f163-5782-9f96-6ffe4eb02cc0

STIX ID: report--fca8515e-f163-5782-9f96-6ffe4eb02cc0

Feed Name: WeLiveSecurity (ESET Research)

Date Published: 2024-01-25

Date Updated: 2026-05-01

...
...

This article outlines the rising cybersecurity risks in complex digital supply chains, highlighting attack types such as compromised software updates, open‑source package abuse, business email compromise, credential theft, and data theft, with examples including Kaseya, MOVEit, 3CX, and Log4j. It recommends eight risk‑mitigation practices—supplier due diligence, open‑source risk management and prompt patching, periodic supplier risk reviews and approved lists, formal supplier policies and SLAs, least‑privilege/Zero Trust access, a rehearsed incident response plan, and adoption of standards (ISO 27001/28000)—to reduce operational, legal, and reputational impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.