When CTS, a managed service provider aimed squarely and uniquely at the legal sector, suffered a cyberattack last month, it was far from the only victim. As recently as 6 December, The Law Society reported that some law firms couldn’t access case management systems. Conveyancers couldn’t complete transactions, and clients couldn’t complete property deals.
James Watts, Managing Director at Databarracks, argues that the CTS attack highlights the dangers of a single supplier for your critical IT services. Even, as in the case of CTS, that managed service provider (MSP) comes replete with an excellent reputation that its widespread use within the legal sector illustrates.
โMSPs are attractive targets for attacks because a single breach can disrupt hundreds of its customers,โ said Watts. โThis demonstrates that even solid organisations with a commitment to cybersecurity are not immune to attacks.โ
The problem is that any single point of failure represents a weakness in an organisation. But, more often than not, a mix of convenience and cost rule the decision-making roost.
โWhen you keep all your eggs in one basket, and that supplier suffers a cyberattack or prolonged outage, your business is severely impacted,โ adds Watts, who recommends a multi-vendor approach wherever possible as a security golden rule. After all, you use this rule when applied to data storage, so why not data security?
โIn the world of supplier risk management, this is fundamental,โ Watts concludes. โYou diversify your supply chain to stop the failure of any single supplier preventing you from delivering for your customers.โ
Delivering this can be as simple as air-gapping people, processes and technology by having distinct suppliers for production and resilience, for example.
Ransomware group LockBit has been particularly associated with this initial access methodology. According to the November BlackFog State of Ransomware report, there were 89 publicly disclosed ransomware attacks that month. This represents the biggest number since the report started in 2020 and a 112% increase over the November 2022 numbers.
Who was behind the majority of these? LockBit and BlackCat.
โNo sector can ignore the risk any longer and must establish adequate policies and procedures to mandate minimum protections for any business they work with in the supply chain,โ says Darren Williams, CEO at BlackFog, predicting that the upwards trend will likely continue into 2024.
Ultimately, the responsibility over security within your organisation must also extend without. This means visibility over the supply chain must be included in your security positioning.
While you canโt do their jobs for them when it comes to security, you can, and should, contractually require them to meet specific security standards. At the very least, I suggest the NCSC CyberEssentials/CyberEssentials Plus certification.
Just as importantly, mandate regular checks that these standards are being met. If your supplier canโt or wonโt agree, then look elsewhere. If your MSP canโt or wonโt, run like the clappersโฆ
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.