Threat

Supply Chain Attack

A supply chain attack targets an organisation through a trusted supplier, software, or service provider with access.

A supply chain attack targets an organisation through a supplier, service provider, or software it trusts. The attacker exploits this established trust to reach their intended target.

How it works

There are several methods. Attackers might manipulate a vendor's software updates, infecting many customers at once. They can compromise an IT service provider and use their remote access to clients. Or they inject malicious code into an open-source library. Supplier email inboxes also serve as an entry point for activities like invoice fraud.

For example, an IT service provider supports 50 SMEs with a remote maintenance tool. Attackers take over a technician's account. They use the tool to distribute ransomware to multiple clients overnight. At one client, the SOC detects unusual program launches from the tool and isolates the systems.

What to look out for

  • Catalogue which suppliers have access to your systems or data.
  • Limit remote access for service providers and protect it with MFA.
  • Monitor service provider account activity as you would for your own admins.
  • Review software dependencies, especially in custom-developed applications.
  • Use contracts to define the supplier's incident reporting obligations.

Switzerland and regulation

FINMA requirements, for example on outsourcing and the management of operational risks, require risks from service providers to be taken into account. For firms with EU ties, NIS2 and DORA set explicit supply chain security requirements. Many Swiss companies experience these requirements as suppliers to EU clients.

Why it is difficult

Actions from a trusted supplier initially appear legitimate. Signatures and authorisations are often correct. Behavioural monitoring is therefore particularly helpful. It can detect when an update suddenly creates unusual network connections.

Typical mistakes

Service providers often have permanent, broad access with no time restrictions. A second mistake is a lack of monitoring due to trust in the partner.

How we implement it

We monitor service provider access and the activities of common software in our SOC. We treat suspicious activity like any other attack.

How ANOMAL implements this