Skip to main content
Shaping Europe’s digital future logo
News article | Publication

ENISA published its Threat Landscape for Supply Chain Attacks

The EU Agency for Cybersecurity published a report - Threat Landscape for Supply Chain Attacks, which analysed 24 recent attacks. The report reveals that strong security protection is no longer enough for organisations when attackers have already shifted their attention to suppliers.

Cover page: ENISA Threat Landscape for Supply Chain Attacks

ENISA

According to this report, an organisation could be vulnerable to a supply chain attack even when its own defences are quite good. The attackers explore new potential highways to infiltrate organisations by targeting their suppliers. Moreover, with the almost limitless potential of the impact of supply chain attacks on numerous customers, these types of attacks are becoming increasingly common.

In order to compromise the targeted customers, attackers focused on the suppliers’ code in about 66% of the reported incidents. This shows that organisations should focus their efforts on validating third-party code and software before using them to ensure these were not tampered with or manipulated.

For about 58% of the supply chain incidents analysed, the customer assets targeted were predominantly customer data, including Personally Identifiable Information (PII) data and intellectual property.

For 66% of the supply chain attacks analysed, suppliers did not knowor failed to report on how they were compromised. However, less than 9% of the customers compromised through supply chain attacks did not know how the attacks occurred. This highlights the gap in terms of maturity in cybersecurity incident reporting between suppliers and end-users.

 

The report is available online.