Why we need a mindset shift to combat the new wave of supply-chain cyberattacks

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Dani Michaux, EMA Cyber Leader and Head of Cyber Security, KPMG Ireland


• The digital ecosystem has expanded in response to changing needs during the pandemic.

• There is a current rise in cyberattacks, often on vulnerable digital supply chains.

• Organizations must overhaul their risk-assessment procedures and widen the scope of their cybersecurity strategy.

Over the past year, we have seen major geopolitical changes driven by the impact of COVID-19, forcing organizations to strengthen their resilience approaches. The realization has also dawned that the world, as we once knew it, has changed.

A new operating model is emerging based on various restructuring activities, accelerating digitalization initiatives, alternative partnership models, and a sharper focus on core activities. As organizations pivot, it is important to reflect and consider the risks that may emerge as part of these major changes.

Prominent among these challenges is the need to safeguard the new digital ecosystem, which underpins this transformation, from cyberattack and the breakdown of our information infrastructure.

The digital world kept turning in 2020

Cybersecurity is key to achieving the Fourth Industrial Revolution. COVID-19 has accelerated that revolution and the use of digital and cloud technologies in both the public and private sectors. Those technologies are now fundamental to our society.

Sadly, the pandemic has also shown that organized crime is opportunistic and ruthless in its exploitation of events to gain financial advantage. Thus, we have witnessed a steady stream of high-profile cyberattacks on private enterprise, government and social media platforms during the year.

Nevertheless, it’s encouraging to observe the pace at which organizations rolled out robust digital infrastructure during difficult times, and the collaboration that we saw amongst business, technology and security teams to safeguard these rapidly deployed services. It shows us how these often-siloed parties can work together effectively to introduce secure innovation at market speed.

COVID-19 has given the remit of Chief Information Security Officers (CISO) a new dimension. Suddenly, they must concern themselves with effectively managing thousands of home-working sites, personal devices and a rapid shift to the cloud. The CISO has moved from securing corporate IT boundaries to a broader view of enterprise security.

The timescale for many cloud-migration projects has collapsed from years to months in the race to meet fast-changing business needs. Hyperscale cloud providers are increasingly dominant and intently focused on security.

Digital supply chains are becoming increasingly complex.
Digital supply chains are becoming increasingly complex. Image: University of Cambridge

The rise of supply chain attacks

Political and business leaders have become alert to the global interdependence of many critical functions and the nature of risk that cross-border supply chains have. The pandemic made these murky operational and systemic risks real and has given people pause for thought.

Supply-chain attacks are not new. However, in the new highly digitalized and interconnected world, they are becoming more prominent. Frequent attacks raise concerns around the ability of business organizations to remain resilient.

A common theme of all of these attacks is the presence of third-party providers of hardware, services or software. In complex infrastructure, set-ups that include rapid pivoting to new environments and dependencies on third-party suppliers are common.

Third-party providers are targeted with the ultimate aim of reaching a bigger mark. The methods and duration of the compromise vary, but there are some common patterns. These include exploiting rapid deployment challenges, looking for exposures in security controls as firms shift rapidly to new technology.

Lessons can be learned from sectors like oil and gas, where human safety is on top of executive agendas and assumptions are constantly challenged. It starts from the proposition that you can’t assume that anything will work in the event of a major incident. That’s the culture of resilience that should be in place in all organizations. It is a question of broad operational resilience, not just of IT systems and security.

A different risk-assessment mindset

As we look into the future of highly digitalized and scalable environments, resilience will likely be paramount and non-negotiable and may rely on the stability of the end-to-end supply-chain. However, it will also require a mindset shift in the approach to data security.

The hunt will be on for cybersecurity orchestration opportunities, for robotic process automation around manual security processes, for more integration with IT key workflows, and for new managed service and delivery models. Third-party security may also need new models for more dynamic risk management and scoring, including better tracking of supply-chain stresses.

Of course, the commonplace SOC 2 and ISAE 3402 assessments may play a role as firms seek to provide evidence once to satisfy a myriad of client questions over their cybersecurity. However, we can also expect to see the rise of “utility models” where intermediary organizations aggregate together client assurance requirements to undertake a one-size-almost-fits-all assessment of suppliers’ cybersecurity.

Over the last few years, firms have also sprung up offering risk-scoring services based on scanning of a firm’s internet-facing services, monitoring for data disclosures in the shady corners of the internet, and alerting customers that a supplier may have a potential problem, which they may not be aware of or the supplier has yet to disclose.

As outsourcing of non-core business services accelerates, it is worth asking: Do you really pay sufficient attention to your dependency on third parties who are now integral to your security and resilience as a business?

As we look to the future, organizations should move from just thinking about enterprise firewalls, antivirus software, and patching policies to considering approaches to security, which starts from the premise that a company’s success is based upon its reputation – ultimately a manifestation of the trust others have in its offerings.

What is the World Economic Forum doing on cybersecurity

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. We are an independent and impartial global platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors. We bridge the gap between cybersecurity experts and decision makers at the highest levels to reinforce the importance of cybersecurity as a key strategic priority. World Economic Forum | Centre for Cybersecurity

Our community has three key priorities:

Strengthening Global Cooperation – to increase global cooperation between public and private stakeholders to foster a collective response to cybercrime and address key security challenges posed by barriers to cooperation.

Understanding Future Networks and Technology – to identify cybersecurity challenges and opportunities posed by new technologies, and accelerate forward-looking solutions.

Building Cyber Resilience – to develop and amplify scalable solutions to accelerate the adoption of best practices and increase cyber resilience.

Initiatives include building a partnership to address the global cyber enforcement gap through improving the efficiency and effectiveness of public-private collaboration in cybercrime investigations; equipping business decision makers and cybersecurity leaders with the tools necessary to govern cyber risks, protect business assets and investments from the impact of cyber-attacks; and enhancing cyber resilience across key industry sectors such as electricity, aviation and oil & gas. We also promote mission aligned initiatives championed by our partner organizations.

The Forum is also a signatory of the Paris Call for Trust and Security in Cyberspace which aims to ensure digital peace and security which encourages signatories to protect individuals and infrastructure, to protect intellectual property, to cooperate in defense, and refrain from doing harm.

For more information, please contact us.

This mindset leads to embedding security into products and services but, more than that, it focuses attention on protecting customers, clients and those increasingly important supply-chain partners. It emphasizes stewardship of the trust they place in you when they share their most sensitive data or show their willingness to become dependent on you.

No organization is an island, and all of us are part of an increasingly hyperconnected world. In that world, trust in supply chains and ecosystem relationships matters more than ever.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

Hantavirus-hit ship evacuation completed as quarantines begin

This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Strait of Hormuz de-escalation is urgent, says UN chief

This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
This article is published in association with United Nations.

Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
Nuclear energy in the Middle East: A realistic choice or a risk?

Nuclear energy in the Middle East: A realistic choice or a risk?

This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Bahrain and US float Security Council resolution on the Strait of Hormuz

This article is published in association with United Nations. Bahrain and the United States have circulated a draft Security Council resolution calling for Iran to cease attacks in the Strait of Hormuz, their ambassadors outlined to journalists at UN Headquarters in New York on Thursday. The text is supported by Kuwait, Qatar, Saudi Arabia and the […]
© CDC An enhanced microscopic image shows the Hantavirus.

Hantavirus outbreak: Another passenger contracts disease

This article is published in association with United Nations. It’s been confirmed that another passenger from the cruise liner linked to the outbreak of hantavirus has contracted the disease, which has claimed the lives of three people on board and sparked an international alert coordinated by the UN World Health Organization (WHO). The individual, who is […]
This article is published in association with United Nations.

UN warns of worsening human rights crisis in Mali after deadly attacks

This article is published in association with United Nations. The human rights situation in Mali is rapidly deteriorating following coordinated attacks by armed groups across the country, with civilians killed, displaced and cut off from food and aid, UN rights office OHCHR said on Tuesday. The violence, which erupted on 25 and 26 April, saw large-scale […]
© UNICEF A damaged ambulance in Tebnine in southern Lebanon.

In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
© Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

Uncertainty continues over safety in the Strait of Hormuz

This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]
© ADB/Ariel Javellana Women farmers in India sell wheat grain and buy fertilizer with the proceeds.

Middle East crisis puts aid, food, fuel further out of reach for millions already struggling – UN agencies

This article is published in association with United Nations. As the Middle East crisis continues the humanitarian fallout is worsening, with aid route disruptions and food and fuel price hikes wrecking the lives and the rights of the most vulnerable people worldwide, UN agencies warned on Friday. Heightened insecurity and instability around key Gulf routes, including […]
© Unsplash/Angus Gray Ship transits through the Strait of Hormuz have dropped by over 90 per cent since the crisis escalated in late February 2026.

Hormuz crisis strangling global economy, Guterres warns, demanding solutions to end stalemate

This article is published in association with United Nations. The escalating crisis in the Strait of Hormuz could push tens of millions into poverty, trigger a surge in global hunger and even tip the world towards recession, the UN Secretary-General warned on Thursday. António Guterres decried the restrictions on free passage through the crucial chokepoint which […]
This article is published in association with United Nations.

AI in advertising risks fuelling information crisis, UN warns

This article is published in association with United Nations. With spending on advertising topping $1 trillion a year worldwide, the United Nations on Wednesday highlighted the untapped power of major brands to shape the future of Artificial Intelligence, warning that a failure to act could deepen a global information integrity crisis. In a new brief titled […]
This article is published in association with United Nations.

2015 nuclear deal ‘no basis’ for any new agreement with Iran

This article is published in association with United Nations. The 2015 nuclear accord with Iran cannot be the starting point for a new agreement with the country, the head of the International Atomic Energy Agency (IAEA) said on Wednesday in New York.  Rafael Mariano Grossi was speaking during a press conference at UN Headquarters held on […]
Credit:Unsplash)

From Hormuz to Lebanon, crisis reverberates through trade routes, upending humanitarian networks

© WHO/Hanan Balkhy In Gaza displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services. This article is published in association with United Nations. Disruptions in the Strait of Hormuz continue to send shockwaves through global food systems, the UN Food and Agriculture […]
© UNICEF/Mohamed Zakaria A displacement centre in El Fasher, North Darfur (file).

World News in Brief: Sudan drone attacks condemned, South Sudan violence, airstrikes in Ukraine, South Africa Freedom Day

This article is published in association with United Nations. The United Nations has condemned two recent drone attacks in Sudan, one of which left seven dead, Spokesperson Stéphane Dujarric said on Monday during his regular media briefing in New York. An aid truck from the UN refugee agency (UNHCR) that was carrying emergency shelter kits came under attack by […]
© IMO/Cihancan Tunay A ship makes its way across an ocean.

Chokepoints and conflict: How the Hormuz crisis is exposing global shipping vulnerabilities

This article is published in association with United Nations. The blockading of ships in the Strait of Hormuz as a result of the conflict between the United States and Iran has demonstrated how ships and seafarers have become “leverage in geopolitical disputes,” according to the head of the UN’s International Maritime Organization (IMO). Since conflict began […]
Middle East war: After oil and gas, concerns grow over minerals crunch

Middle East war: After oil and gas, concerns grow over minerals crunch

This article is published in association with United Nations. The shipping crisis in the Strait of Hormuz caused by war in the Middle East has exposed a new threat: a looming shortage of strategic minerals that drive economies all over the world – and a race by countries to obtain them. Until war erupted on 28 […]
This article is published in association with United Nations.

Ceasefire extension offers diplomatic opening, but tensions persist in Strait of Hormuz

This article is published in association with United Nations. The United States’ decision to extend a fragile ceasefire with Iran has kept a narrow window open for diplomacy, but fresh security incidents in the Strait of Hormuz on Wednesday underscore the volatility of the situation and the risks to global shipping and regional stability. The UN […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com