Trending Topics

Learn your Pokemon lesson: Either take your supply chain security seriously or face the fallout
Customers of the Pokemon Center in the UK and Germany are the latest to be affected by a breach. Not by the company they deal with directly, but by someone further down the supply chain. And there are lessons here for every organisation to learn.
In this case, the vendor used by Pokemon Center to ship products to customers in those two regions. But it could just as easily have been, oh, I don’t know, a customer relationship management organisation, such as the one whose breach a couple of weeks ago affected hundreds of charities in the UK.
As David Neeson, SOC Deputy Team Lead at Barrier Networks told me: “Supply chain attacks are becoming a lucrative source of information for attackers to enable further fraud, and even breaches that seem relatively minor can have serious impacts for affected customers.”
If you ignore that warning, then, frankly, the consequences, including potential reputational harm and legal action, are on you and nobody else. Blame the supplier all you like, but if you haven’t heard of due diligence and third-party risk assessment, then your conscience is not clear.
Due diligence on suppliers
“The incident also acts as a reminder on the importance of conducting due diligence on suppliers before contracts are signed,” said Dónnan Mallon, Threat Intelligence Analyst at Talion Cyber Security.
He added that “organisations must understand the steps suppliers take to protect their environments, see evidence of their compliance with regulations, and understand the controls they have adopted to detect and block malicious access”.
“Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work,” states an August 7 notice from the Charity Commission regarding the UK charities supply chain incident. Which isn’t wrong. Nor is the fact that this takes additional resources to address.
No ifs, no buts. Organisations have to assume that credentials will be exposed and so build their security processes and procedures accordingly.
“That means tightly controlling and continuously monitoring privileged access, automatically detecting and rotating leaked secrets, applying least-privilege principles, strengthening cloud security controls,” said Jamie Akhyar, CEO and Co-Founder of CyberSmart, “and ensuring third-party suppliers are held to the same standards.”
Keep on checking
This cannot be a once-and-done procedure, however, but an ongoing effort.
“It needs to be conducted regularly to ensure security remains a key priority,” Mallon said, “because when a key supplier suffers a cyber incident, as we are seeing here, more often than not their partners will also face the repercussions.”
Just as important, however, is your security response following any such supply chain incident.
Vigilance, both immediately and in the months that follow, is vital. “Block and report suspicious entities, follow the advice from reputable authorities, look for and implement two-factor authorisation opportunities wherever they are available on apps and devices,” advised Brian Higgins, a security specialist at Comparitech.
