How a critical situation not related to IT can lead to breach
With changes to cybersecurity over the past year, we often think of modern cyber espionage as something conducted remotely, thousands of miles away from the target. However, a recently discovered breach shows that lapses in procurement management, supply chain security, and counterfeiting can lead to major cybersecurity events. During an emergency, a consumer ordered storage drives outside of their normal procurement methods. Although the drives were received, malware had been installed on three-quarters of the drives and went undetected for months. These counterfeit drives were modified with malware and sold as budget-friendly hardware; they were bought by ordinary consumers and have since triggered malware infections at factories and research facilities across multiple industries.
At Rolka Loube, we follow strict policies and processes, and we have implemented training on the detection of counterfeits. We source our purchases through verified vendors to ensure they come through intended supply chains. An additional recommendation is to never compromise or ignore policies and procedures during emergency or crisis situations. Instead, implement risk mitigations by shortening delivery times through faster shipping, or keep additional stock of necessary items.
Lastly, deploy a trusted endpoint detection and response (EDR) platform. This software is designed to detect, mitigate, and remediate malicious code that can enter a system through external means like mass storage devices. EDR platforms can also be used to limit the connectivity of storage media, ensuring only approved or whitelisted devices are allowed to mount for data transfer. Additionally, use the EDR platform on an air-gapped or standalone device to perform malware scans prior to connecting new or foreign devices to production networks and assets.