Supply Chain Hacking Breaks Cyber Trust
Supply chain hacking poses significant risks to cybersecurity by exploiting trust in technology infrastructures. Luke Fox and Stuart McClure discuss how hackers can infiltrate systems through supply chain vulnerabilities. The SolarWinds hack exemplifies the dangers of misplaced trust in digital certificates and software updates.
This story was produced through MarketScale. See how Industrial IoT teams put it to work with AI Visibility (GEO).
Key takeaways
Supply chain hacking exploits trust within technology infrastructures, posing severe cybersecurity risks.
Traditional antivirus methods are inadequate against supply chain attacks as they cannot detect unknown viruses.
The SolarWinds hack highlights vulnerabilities in security processes and the importance of safeguarding build servers.
Get featured
Want to get featured in MarketScale Industrial IoT?
Create a free MarketScale workspace and get your company's expertise featured across our Industrial IoT coverage. No credit card, no demo required.
Bringing together leaders, lawmakers and lawbreakers. Host Luke Fox explores how innovations in business and technology are redefining our trust in security measures.
The principle of trust isn’t unique to human relationships. It’s also a significant part of technology infrastructures. This cyber trust is what lets software updates and patches from the development company to their customers. Unfortunately, hackers can infiltrate these exchanges, appearing trustworthy but are a wolf in sheep’s clothing.
Such is the case with supply chain hacking and the cybersecurity story of the year—Solar Winds. Lending his expertise on the topic and explaining hacking’s evolving world is industry expert, Cylance founder, and best-selling author Stuart McClure.
“Supply chain hacking is one of the most overlooked aspects of cybersecurity. An antivirus signature-based approach isn’t going to stop this,” McClure said. He explained that a signature-based approach is deeply flawed. “It only detects viruses it’s seen before, that match known signatures,” he said.
Realizing this system was broken, McClure revolutionized virus detection by using AI and machine learning when founding Cylance. “We applied machine learning and data science, learning from past viruses, and predicting in real-time whether something was virus-like,” McClure said.
McClure went on to explain the SolarWinds hack based on what is publicly known. It goes back to misplaced trust.
“The number one target of supply chain hacking is to hack the build server that houses all the code and before it’s compiled and signed with the digital certificate. Malicious code now looks legitimate,” McClure said. That appears to be what hackers did with SolarWinds. The hackers got into the code, it was released to users, and the customer networks trusted it and let it in.
SolarWinds illustrates the weaknesses of supply chain security, breaking trust in the technology and business partners. McClure warned, “This case is not unique, and it’s not the first time this level of attack occurred. What is unique is that they hit a core element, hacking just one system to infiltrate many eventually.”
Catch Up On Previous Episodes of The Trust Revolution!
Your experts belong here
Every story in MarketScale Industrial IoT starts with a company putting its controls engineers, plant-floor specialists, and integration partners on the record. Buyers are already reading this topic. The only question is whose experts they find.
Plant and controls buyers research deep before contact, and your engineers get to shape that research.
About the author