Building Supply Chain Cybersecurity Resilience | SupplyChainBrain

Building Supply Chain Cybersecurity Resilience

Photo: iStock/JuSun
Photo: iStock/JuSun

The success of the retail and hospitality industry is founded on a complex network of suppliers, vendors and other third-party partners. This large ecosystem is crucial to efficient operations, but it also creates cybersecurity risks for retailers and hoteliers.

Already, these organizations are tempting targets for bad actors due to their high volume of daily transactions and customer data, such as credit card numbers, login credentials and personally identifiable information like addresses and phone numbers. Cyber thieves have their eye on the data, and they’re finding new ways to infiltrate retail and hospitality organizations’ networks via the supply chain.

But there’s a powerful way to fight back. 

According to RH-ISAC’s CISO Benchmark Report, third-party supply chain attacks are the second most-cited cybersecurity risk for chief information security officers out of 350 different risks, second only to ransomware attacks.

Why the focus on defending against supply chain attacks? Due to deep integration with an increasing number of third-party vendors, retail and hospitality organizations’ supply chains provide many opportunities for cyber attackers to bypass defenses. Every day, sensitive data moves through many hands and networks. Plus, the interconnected nature of these exchanges means hackers only need one small point of entry to trigger a domino effect across dozens, if not hundreds, of organizations to inflict damage, from disrupting the flow of goods to delaying deliveries, causing inventory shortages, and stealing sensitive data.

Recent Cyber Attacks

Last year, a group of cyber attackers went after Otelier, a hotel-management platform relied on by more than 10,000 hotels around the world. Using an infostealer (a type of malware designed to steal sensitive information), the cybercriminals managed to steal an Otelier employee’s login credentials. With this information, they were able to uncover login credentials for accounts throughout the supply chain, making off with 7.8 TB of data, including documents such as hotel reports, guest reservations, employee emails and guests’ names, addresses and phone numbers.

Another recent high-profile supply chain attack involved Blue Yonder, a supply chain management software provider. This time, the threat actors carried out a ransomware attack on the vendor’s managed services-hosted environment. From there, they were able to compromise back-end processes, leaving some businesses unable to pay employees or manage schedules.

Stealing sensitive data and bringing business operations to a halt aren’t the only ways bad actors can impact retail and hospitality organizations through a supply chain attack. Financial loss from software supply chain cyber attacks alone is expected to cost the global economy almost $81 billion in revenue and damages by 2026. At the same time, organizations can face reputational damage and even legal consequences if they’re subject to lawsuits.

For bad actors keen on infiltrating retailers’ and hoteliers’ supply chains, there are many methods of entry, but hackers do seem to have a favorite: phishing attacks. Once confined primarily to email, these attacks now also commonly occur via phone calls or text messages. 

In fact, 58% of all cyberattacks against retailers are the result of phishing, which is defined as a type of social engineering attack where bad actors pose as an authority figure and trick employees into handing over data or login credentials. For example, a thief might contact a supplier’s employee for “an urgent security update,” duping the employee into granting them network access. 

Malware is another common entry point, where cyber thieves again fool unsuspecting employees. For example, a vendor may open an email and download what looks like an invoice — but it’s really a malicious file that will create a backdoor and give hackers full network access.

These social-engineering attacks are a prime attack method, but hackers do have other tactics. They can also exploit weak passwords, outdated software or known security flaws to gain access to a supplier’s network. From there, they can easily jump to a retailer’s or hotelier’s network to compromise or steal data. 

Strategies for Protection

Supply chain cybersecurity threats are diverse, and the repercussions severe. How can retail and hospitality organizations protect themselves? 

To help fend off social engineering attacks, make cybersecurity education a priority. Train everyone in your organization, from top to bottom, to spot suspicious activity so they can detect and deflect phishing schemes. Meanwhile, verify all software is up to date to prevent cyber attackers from exploiting network vulnerabilities. 

It’s also wise to regularly audit your third-party vendors’ security postures to screen for risks and find areas for improvement. 

In addition to your third-party vendors, turn to your fellow retail and hospitality organizations. The best defense against cyber attackers is putting up a united front and bolstering the entire supply chain. You can collaborate with other retailers and hoteliers via RH-ISAC, the global cybersecurity community, created specifically to help retail and hospitality organizations share cyber intelligence and cybersecurity best practices. Its new LinkSECURE Program offers a membership for small- to mid-size vendors and service providers to help those with limited IT or cyber resources mature their cybersecurity operations. The new program gives every participant an evaluation of their cybersecurity posture, along with a dedicated success manager to guide them through 18 critical security controls and safeguards. 

Retail and hospitality organizations rely heavily on third-party vendors, but at the same time, this supply chain network can leave them vulnerable to cyberattacks. By working with industry peers and prioritizing cybersecurity education, retailers and hoteliers can build a secure, united defense against third-party cyberattacks and create a stronger supply chain for all.

Pam Lindemoen is chief security officer and vice president of strategy with RH-ISAC.

Related Content

Related Videos

Featured Product

Page 1 of 583
Next Page

Visit Our Sponsors