1
00:00:00,000 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,270
we're going to discuss supply chain attacks.

3
00:00:03,270 --> 00:00:04,886
As our globalized and digitized world

4
00:00:04,886 --> 00:00:07,080
brings about more interconnectivity,

5
00:00:07,080 --> 00:00:10,170
our supply chains grow even more dense and intertwined

6
00:00:10,170 --> 00:00:12,510
which can expand the attack service of our network

7
00:00:12,510 --> 00:00:14,280
that malicious actors are trying to exploit.

8
00:00:14,280 --> 00:00:15,300
So let's take a look

9
00:00:15,300 --> 00:00:17,190
at what a supply chain attack actually is,

10
00:00:17,190 --> 00:00:19,260
some real world examples of supply chain attacks,

11
00:00:19,260 --> 00:00:21,630
and how these attacks could have been mitigated.

12
00:00:21,630 --> 00:00:23,971
Now, to begin, let's talk about a supply chain attack

13
00:00:23,971 --> 00:00:25,830
and what it actually is.

14
00:00:25,830 --> 00:00:27,427
Simply put, a supply chain attack

15
00:00:27,427 --> 00:00:28,810
is an attack that involves targeting

16
00:00:28,810 --> 00:00:31,050
a weaker link in the supply chain

17
00:00:31,050 --> 00:00:33,570
to gain access to a primary target.

18
00:00:33,570 --> 00:00:36,810
So instead of attacking a well fortified entity directly,

19
00:00:36,810 --> 00:00:39,510
your adversaries may attempt to exploit vulnerabilities

20
00:00:39,510 --> 00:00:41,730
inside of their suppliers and service providers

21
00:00:41,730 --> 00:00:43,905
to pave their way into the organization's larger

22
00:00:43,905 --> 00:00:46,500
and otherwise more secure systems.

23
00:00:46,500 --> 00:00:48,210
Now, supply chain attacks have been happening

24
00:00:48,210 --> 00:00:49,860
for many, many years.

25
00:00:49,860 --> 00:00:51,870
Throughout the 2000s and 2010s,

26
00:00:51,870 --> 00:00:53,310
Cisco routers and switches

27
00:00:53,310 --> 00:00:55,170
were often the source of supply chain attacks

28
00:00:55,170 --> 00:00:57,120
that focused on selling counterfeit devices

29
00:00:57,120 --> 00:00:58,950
out on the secondary market.

30
00:00:58,950 --> 00:01:01,920
Basically, a counterfeiter would take an old Cisco chip,

31
00:01:01,920 --> 00:01:04,379
and then conduct something known as chip washing.

32
00:01:04,379 --> 00:01:05,532
Now, chip washing involves

33
00:01:05,532 --> 00:01:07,980
repackaging the contents of a microchip

34
00:01:07,980 --> 00:01:09,390
with a less expensive one

35
00:01:09,390 --> 00:01:11,850
or one that contains embedded malware.

36
00:01:11,850 --> 00:01:12,810
In the best case,

37
00:01:12,810 --> 00:01:14,820
your organization just bought a router or a switch

38
00:01:14,820 --> 00:01:16,050
that isn't going to work right

39
00:01:16,050 --> 00:01:18,263
and it's going to lead to some network failures or crashes.

40
00:01:18,263 --> 00:01:20,093
At worst, you just installed a router

41
00:01:20,093 --> 00:01:22,020
or switch that you thought you could trust

42
00:01:22,020 --> 00:01:24,240
but it actually has a counterfeit chip inside of it

43
00:01:24,240 --> 00:01:25,375
that contains malicious functionalities

44
00:01:25,375 --> 00:01:27,900
that turns your own network hardware against you

45
00:01:27,900 --> 00:01:29,490
and provides an always-on backdoor

46
00:01:29,490 --> 00:01:31,560
into your network for a given threat actor.

47
00:01:31,560 --> 00:01:33,930
Now, another worrying trend is the deliberate embedding

48
00:01:33,930 --> 00:01:37,080
of root kits within devices by your overseas suppliers.

49
00:01:37,080 --> 00:01:38,850
These pre-installed malware tools

50
00:01:38,850 --> 00:01:40,770
can provide backdoor access to networks

51
00:01:40,770 --> 00:01:42,690
once the devices are active.

52
00:01:42,690 --> 00:01:43,950
Given that a significant portion

53
00:01:43,950 --> 00:01:46,170
of our tech manufacturing happens overseas

54
00:01:46,170 --> 00:01:47,970
and outside of the United States,

55
00:01:47,970 --> 00:01:50,850
this poses an enormous risk for our US-based companies

56
00:01:50,850 --> 00:01:52,260
and governments alike.

57
00:01:52,260 --> 00:01:53,190
This is another reason

58
00:01:53,190 --> 00:01:55,680
why conducting a good vendor assessment is important

59
00:01:55,680 --> 00:01:57,540
when you're determining which types of hardware,

60
00:01:57,540 --> 00:01:59,160
software, and service providers

61
00:01:59,160 --> 00:02:01,740
you're going to use inside of your organization.

62
00:02:01,740 --> 00:02:03,870
Now, in addition to these hardware-based attacks,

63
00:02:03,870 --> 00:02:05,880
we also have software-based supply chain attacks

64
00:02:05,880 --> 00:02:07,200
that we need to think about.

65
00:02:07,200 --> 00:02:09,479
Back in 2021, one of the largest

66
00:02:09,479 --> 00:02:10,860
software-based supply chain attacks

67
00:02:10,860 --> 00:02:12,390
that we've observed was seen

68
00:02:12,390 --> 00:02:13,920
and this involved the network monitoring

69
00:02:13,920 --> 00:02:16,680
and management software known as SolarWinds.

70
00:02:16,680 --> 00:02:17,700
During the attack,

71
00:02:17,700 --> 00:02:19,200
cyber criminals infiltrated

72
00:02:19,200 --> 00:02:21,630
the SolarWinds Orion software update system

73
00:02:21,630 --> 00:02:23,670
and used it to distribute their own malware

74
00:02:23,670 --> 00:02:25,980
to all of the company's wide range of clients

75
00:02:25,980 --> 00:02:27,210
including city, state,

76
00:02:27,210 --> 00:02:29,760
and national governments across the world.

77
00:02:29,760 --> 00:02:30,810
The attacker's goal here

78
00:02:30,810 --> 00:02:32,880
wasn't to infiltrate a single target,

79
00:02:32,880 --> 00:02:34,769
but instead they want to compromise the networks

80
00:02:34,769 --> 00:02:36,840
of thousands of organizations

81
00:02:36,840 --> 00:02:39,090
including various US government agencies.

82
00:02:39,090 --> 00:02:41,250
This incident was a really big wake up call

83
00:02:41,250 --> 00:02:42,780
for many organizations

84
00:02:42,780 --> 00:02:44,430
and it illustrates the indirect avenues

85
00:02:44,430 --> 00:02:45,660
that attackers could employ

86
00:02:45,660 --> 00:02:48,300
to bypass even the most robust security defenses

87
00:02:48,300 --> 00:02:51,090
like those that are used by the Department of Defense.

88
00:02:51,090 --> 00:02:52,496
Now, recognizing that supply chain risk

89
00:02:52,496 --> 00:02:54,960
can quickly turn into a supply chain attack,

90
00:02:54,960 --> 00:02:57,480
the US government passed a new piece of legislation

91
00:02:57,480 --> 00:03:00,360
back in 2022 called the CHIPS Act.

92
00:03:00,360 --> 00:03:01,440
Now, the CHIPS Act,

93
00:03:01,440 --> 00:03:04,380
also known as the Chips and Science Act of 2022,

94
00:03:04,380 --> 00:03:05,622
is a US federal statute

95
00:03:05,622 --> 00:03:09,690
that provides roughly $280 billion in new funding

96
00:03:09,690 --> 00:03:10,860
in order to boost research

97
00:03:10,860 --> 00:03:12,780
and manufacturing of semiconductors

98
00:03:12,780 --> 00:03:15,030
within the borders of the United States.

99
00:03:15,030 --> 00:03:17,880
This act includes $39 billion in subsidies

100
00:03:17,880 --> 00:03:20,010
for chip manufacturing on US soil,

101
00:03:20,010 --> 00:03:22,620
along with a 25% investment tax credit

102
00:03:22,620 --> 00:03:25,050
for cost associated with manufacturing equipment,

103
00:03:25,050 --> 00:03:27,000
and another $13 billion

104
00:03:27,000 --> 00:03:29,970
for semiconductor research and workforce training.

105
00:03:29,970 --> 00:03:32,940
The CHIPS Act was designed to minimize supply chain risk

106
00:03:32,940 --> 00:03:34,740
by reducing the United States' reliance

107
00:03:34,740 --> 00:03:36,720
on foreign made semiconductors.

108
00:03:36,720 --> 00:03:38,580
Semiconductors are essential components

109
00:03:38,580 --> 00:03:39,930
in a wide range of products

110
00:03:39,930 --> 00:03:41,370
from smartphones and cars

111
00:03:41,370 --> 00:03:42,985
to medical devices and defense systems

112
00:03:42,985 --> 00:03:45,450
like missile systems and airplanes.

113
00:03:45,450 --> 00:03:47,220
The global semiconductor supply chain

114
00:03:47,220 --> 00:03:49,320
is really complex and interconnected,

115
00:03:49,320 --> 00:03:50,730
and disruptions to the supply chain

116
00:03:50,730 --> 00:03:53,777
can have significant economic and security implications.

117
00:03:53,777 --> 00:03:56,460
This is one of the reasons the CHIPS Act was designed.

118
00:03:56,460 --> 00:03:57,660
It was there to help strengthen

119
00:03:57,660 --> 00:03:59,730
the domestic semiconductor supply chain

120
00:03:59,730 --> 00:04:02,100
and make it more resilient to disruptions.

121
00:04:02,100 --> 00:04:03,840
By investing in our domestic manufacturing

122
00:04:03,840 --> 00:04:05,190
and research capabilities,

123
00:04:05,190 --> 00:04:07,440
the CHIPS Act is going to help ensure the United States

124
00:04:07,440 --> 00:04:10,320
has a reliable supply of semiconductors to meet its needs

125
00:04:10,320 --> 00:04:12,480
and will help to minimize supply chain risks,

126
00:04:12,480 --> 00:04:15,570
create jobs, and boost the US economy overall.

127
00:04:15,570 --> 00:04:17,500
So I told you about the problems with the supply chain

128
00:04:17,500 --> 00:04:18,890
and some of the things that the government

129
00:04:18,890 --> 00:04:20,519
is doing to step in and help,

130
00:04:20,519 --> 00:04:22,590
but what can you and your organization do

131
00:04:22,590 --> 00:04:25,230
to safeguard yourself against supply chain attacks?

132
00:04:25,230 --> 00:04:27,750
Well, it really comes down to four things:

133
00:04:27,750 --> 00:04:30,540
vendor due diligence, regular monitoring and audits,

134
00:04:30,540 --> 00:04:32,010
education and collaboration,

135
00:04:32,010 --> 00:04:34,290
and incorporating contractual safeguards.

136
00:04:34,290 --> 00:04:36,630
First, we have vendor due diligence.

137
00:04:36,630 --> 00:04:38,724
Organizations must practice rigorous due diligence

138
00:04:38,724 --> 00:04:40,560
when onboarding their vendors,

139
00:04:40,560 --> 00:04:43,740
especially those with access to critical systems or data.

140
00:04:43,740 --> 00:04:45,360
This involves not only understanding

141
00:04:45,360 --> 00:04:47,070
the vendor cybersecurity posture,

142
00:04:47,070 --> 00:04:48,900
but also their own supply chain management

143
00:04:48,900 --> 00:04:50,370
and security practices.

144
00:04:50,370 --> 00:04:53,010
Second, we have regular monitoring and audits.

145
00:04:53,010 --> 00:04:54,780
Continuous monitoring and periodic audits

146
00:04:54,780 --> 00:04:55,620
of your supply chain

147
00:04:55,620 --> 00:04:57,510
are considered to be essential.

148
00:04:57,510 --> 00:04:59,760
This will help you have an early detection mechanism

149
00:04:59,760 --> 00:05:02,070
for any suspicious activities or vulnerabilities

150
00:05:02,070 --> 00:05:04,470
that may be exploited by an attacker.

151
00:05:04,470 --> 00:05:07,260
Third, we have education and collaboration.

152
00:05:07,260 --> 00:05:08,730
By keeping the broader ecosystem

153
00:05:08,730 --> 00:05:10,590
informed about the latest security threats,

154
00:05:10,590 --> 00:05:12,450
vulnerabilities and best practices,

155
00:05:12,450 --> 00:05:14,730
we can ensure that our industry, as a whole,

156
00:05:14,730 --> 00:05:16,290
remains better protected.

157
00:05:16,290 --> 00:05:18,720
Collaborating with other organizations and industry groups

158
00:05:18,720 --> 00:05:20,880
can really provide you with a more holistic view

159
00:05:20,880 --> 00:05:22,110
and a joint defense strategy

160
00:05:22,110 --> 00:05:25,020
against these kinds of supply chain attacks and threats.

161
00:05:25,020 --> 00:05:26,010
Fourth and finally,

162
00:05:26,010 --> 00:05:28,590
we have incorporating contractual safeguards.

163
00:05:28,590 --> 00:05:31,020
Now, when engaging with suppliers or service providers,

164
00:05:31,020 --> 00:05:32,250
you're going to use a contract

165
00:05:32,250 --> 00:05:34,230
and that contract shouldn't beg clauses

166
00:05:34,230 --> 00:05:36,240
related to cybersecurity within them.

167
00:05:36,240 --> 00:05:38,370
This type of contract language can help to ensure

168
00:05:38,370 --> 00:05:40,740
that vendors adhere to stipulated security standards

169
00:05:40,740 --> 00:05:42,150
and that there are legal repercussions

170
00:05:42,150 --> 00:05:44,370
if they don't meet your standards or requirements

171
00:05:44,370 --> 00:05:46,200
as outlined inside of that contract.

172
00:05:46,200 --> 00:05:49,410
So remember, in the expanding web of global supply chains,

173
00:05:49,410 --> 00:05:50,880
we are exposing our organizations

174
00:05:50,880 --> 00:05:53,460
to a host of new challenges every single day.

175
00:05:53,460 --> 00:05:54,420
In today's world,

176
00:05:54,420 --> 00:05:55,500
a single vulnerability

177
00:05:55,500 --> 00:05:57,510
in a seemingly insignificant component

178
00:05:57,510 --> 00:05:59,220
could have massive ripple effects,

179
00:05:59,220 --> 00:06:02,130
causing worldwide disruptions on a massive scale.

180
00:06:02,130 --> 00:06:04,110
Therefore, securing our supply chains

181
00:06:04,110 --> 00:06:05,554
isn't just about the information technology

182
00:06:05,554 --> 00:06:07,770
or cybersecurity department anymore.

183
00:06:07,770 --> 00:06:10,830
It really is everyone's business inside of our organization

184
00:06:10,830 --> 00:06:11,850
because it is at the heart

185
00:06:11,850 --> 00:06:14,010
of our very survival and integrity

186
00:06:14,010 --> 00:06:16,173
of our organizations and our nations.

