When most people think about a cyber attack, they picture someone attempting to breach a firewall or trick a member of staff into clicking a malicious link. Both are common attack methods, but there is another route that organisations often underestimate: compromising a trusted supplier, service provider, or software platform and using that trust as a way into the target environment.
This type of compromise is known as a supply chain attack, and it has become one of the most significant security risks facing organisations of all sizes.
Why supply chain attacks are so effective
The effectiveness of a supply chain attack comes from the fact that it exploits legitimate trust relationships.
When an organisation installs software from a reputable vendor, it is reasonable to assume that software is safe. When updates are delivered through official channels, very few organisations have the ability to independently inspect every component before deployment. Attackers understand this, and increasingly target suppliers, software developers, and service providers because compromising a single trusted source can provide access to hundreds or thousands of downstream organisations.
The 2020 SolarWinds compromise remains one of the best-known examples. Attackers infiltrated the company’s software build environment and inserted malicious code into legitimate Orion software updates. Approximately 18,000 customers installed the compromised update, unintentionally providing attackers with access into government departments, large enterprises, and security organisations.
What made the incident particularly concerning was that many affected organisations had followed accepted security practices. They were using a legitimate product, applying official updates, and still became victims.
Although SolarWinds was a highly sophisticated operation widely attributed to a nation-state threat actor, the underlying principle applies equally to smaller-scale attacks.
A compromised WordPress plugin, an infected open-source dependency, a malicious browser extension, or a poorly secured remote management platform used by an outsourced IT provider can all become effective entry points into an organisation.
Where supply chain risks commonly appear
Supply chain exposure is often broader than organisations initially realise. Common areas of risk include:
- Managed service providers with remote administrative access
- Remote monitoring and management (RMM) platforms
- Cloud hosting providers and SaaS platforms
- Open-source software libraries and dependencies
- Website plugins and third-party integrations
- Software update mechanisms
- Hardware vendors and embedded firmware
Many of these systems operate with elevated privileges or trusted network access, meaning a compromise can have a significant impact very quickly.
Practical steps to reduce supply chain risk
Few organisations can realistically perform deep technical security assessments on every supplier they use. However, there are several practical controls that significantly reduce exposure.
Understand what access suppliers actually have
Many third parties retain more access than they genuinely require.
Remote support tools, outsourced IT providers, cloud platforms, and software integrations often have privileged access into critical systems. Organisations should regularly review:
- which suppliers have access
- what systems they can reach
- whether that access is still necessary
- how the access is authenticated and monitored
Limiting unnecessary privileges substantially reduces the potential impact of a supplier compromise.
Review how software updates are managed
Automatic updates are generally beneficial because they reduce the time systems remain vulnerable to known security flaws. However, organisations should still understand:
- which systems update automatically
- which updates are manually approved
- whether updates are digitally signed
- how update integrity is verified
Where practical, critical updates should first be tested in a controlled environment before broad deployment.
Monitor trusted software for unusual behaviour
One of the challenges with supply chain attacks is that the malicious activity often originates from legitimate software that organisations already trust.
Unexpected outbound connections, unusual PowerShell activity, access to sensitive files, or privileged actions performed by software that would not normally require them should all be investigated.
This is where endpoint detection and response (EDR) tooling, intrusion detection systems, and centralised logging become particularly valuable. Effective monitoring depends on understanding what normal behaviour looks like within your environment.
Assess supplier security standards
Suppliers with significant access to your systems should be able to demonstrate reasonable security maturity.
Depending on the nature of the relationship, organisations may wish to request evidence such as:
- ISO 27001 certification
- Cyber Essentials or Cyber Essentials Plus accreditation
- recent penetration testing
- vulnerability management policies
- incident response procedures
- MFA enforcement for administrative access
Many organisations now include security reviews as part of procurement and supplier onboarding processes.
Taking a realistic approach
No organisation can eliminate supply chain risk entirely, particularly when dealing with widely used software or large external providers. A determined attacker who successfully compromises a trusted vendor may still find ways into customer environments.
However, organisations can significantly reduce the potential impact by:
- limiting unnecessary third-party access
- monitoring privileged activity closely
- segmenting critical systems
- maintaining strong logging and visibility
- preparing incident response plans that include supplier compromise scenarios
Supply chain risk is not a reason to avoid third-party software or external providers. Modern organisations depend on them. The important thing is understanding where trust exists within your environment, what level of access has been granted, and whether you would detect suspicious behaviour if that trust relationship was abused.
If you would like to discuss how intrusion detection or a security review could help your organisation manage this kind of risk, get in touch.