Skip to main content Skip to footer site map
Updates

Cybersecurity and Supply Chain Risk Management Are Not Simply Additive: Implications for Directions in Risk Assessment, Risk Mitigation, and Research to Secure the Supply of Defense Industrial Products : RAND Corporation , 2023

2023

RAND Corporation

Download PDF

From the report: "That an organization will experience a costly cyberattack tends to be discussed as a “when,” not an “if.” For supply chains, for which third-party cybersecurity has become a prominent concern, describing such attacks as eventualities might seem reasonable. According to a survey conducted by the cybersecurity company BlueVoyant, 92 percent of respondents reported suffering a cyber intrusion in 2019–2020 as a direct result of third-party cybersecurity weakness in the supply chain (BlueVoyant, 2020). A 2017 attack, dubbed NotPetya, originated from an exploited vulnerability in a small accounting software company yet led to massive disruptions across Europe and resulted in costs in the millions of dollars for recovery, network sanitization, and lost sales (Nash, Castellanos, and Janofsky, 2018). That and other recent events, including a 2020 breach commonly referred to as SolarWinds—in which cyber intruders appear to have accessed and exploited software update mechanisms that would ordinarily contribute to security across government and industry—lend credence to perceptions of inevitability."

Authors - Greenfield, Victoria A., Welburn, Jonathan W., Schwindt, Karen, Ish, Daniel, Lohn, Andrew J., Hartnett, Gavin S.

Subjects

Authors

Greenfield, Victoria A., Welburn, Jonathan W., Schwindt, Karen, Ish, Daniel, Lohn, Andrew J., Hartnett, Gavin S.

Publishers

RAND Corporation

Format

PDF - Download

Related Resources

s