Cybersecurity and Supply Chain Risk Management Are Not Simply Additive: Implications for Directions in Risk Assessment, Risk Mitigation, and Research to Secure the Supply of Defense Industrial Products : RAND Corporation , 2023
From the report: "That an organization will experience a costly cyberattack tends to be discussed as a “when,” not an “if.” For supply chains, for which third-party cybersecurity has become a prominent concern, describing such attacks as eventualities might seem reasonable. According to a survey conducted by the cybersecurity company BlueVoyant, 92 percent of respondents reported suffering a cyber intrusion in 2019–2020 as a direct result of third-party cybersecurity weakness in the supply chain (BlueVoyant, 2020). A 2017 attack, dubbed NotPetya, originated from an exploited vulnerability in a small accounting software company yet led to massive disruptions across Europe and resulted in costs in the millions of dollars for recovery, network sanitization, and lost sales (Nash, Castellanos, and Janofsky, 2018). That and other recent events, including a 2020 breach commonly referred to as SolarWinds—in which cyber intruders appear to have accessed and exploited software update mechanisms that would ordinarily contribute to security across government and industry—lend credence to perceptions of inevitability."
Authors - Greenfield, Victoria A., Welburn, Jonathan W., Schwindt, Karen, Ish, Daniel, Lohn, Andrew J., Hartnett, Gavin S.Subjects
Authors
Publishers
Format
Related Resources