Supply Chain

The Defence Supply Chain Has More Doors Than You Think

The Defence Industry Base presents a broad and expanding attack surface for malicious cyber activity.

Cartoon: a castle wall with eleven doors and a guard at each one. The guards are variously asleep, reading, whistling and scanning the horizon with a telescope, while one unwatched door stands open with a dragon's tail disappearing inside.

As Defence information moves down the supply chain from primes to subcontractors and sub-subcontractors, it can pass through potentially hundreds of systems, users, interfaces and service providers. Each can expand the attack surface or introduce another access path that must be understood and protected.

Primes may share sensitive or classified information including drawings, specifications, test results and failure analyses. Their own environments may be mature and extensively assured, but those protections do not automatically follow the information into supplier systems.

Defence information passes through emails, document-management platforms, engineering and manufacturing applications, cloud services, backup environments and end-user devices. These systems are also connected through identities, interfaces, remote access and external service providers.

The attack surface includes the systems, identities, connections and third parties capable of providing a pathway to sensitive or Defence-related information. A vulnerability does not need to exist in the system holding that information. It may exist in another system, account permissions and privileges or services that provides an exploitable pathway.

For smaller suppliers, Information and Communications Technology (ICT) and security responsibilities are often concentrated among relatively few people, spanning manufacturing systems, enterprise resource planning (ERP), content management, infrastructure, desktop support and often limited cyber security capability. Maintaining deep expertise across every discipline can be difficult, particularly where those people also hold operational roles within the business.

Managed service providers may be engaged to augment internal teams and provide specialist technical capability. This further expands the attack surface.

The source organisation must understand how the provider secures its own environment, how privileged access is controlled, and whether its practices align with the supplier’s obligations for handling Defence information that is going to be shared.

Foreign adversaries understand these dependencies. Rather than attack a major Defence prime or major service provider directly, a supplier or service provider further down the supply chain may provide an easier route to sensitive information, intellectual property or operational capability.

For executives, the key issue is therefore not simply whether cyber controls exist. It is whether the organisation understands its actual attack surface and associated pathways.

They must understand which systems hold or can access Defence information?

Which systems provide a pathway to them?

Who administers them?

Which third parties hold privileged access?

Where is information copied, transmitted or backed up?

As people, systems, cloud services, suppliers and business processes change, the attack surface changes with them. These are areas the Defence Industry Security Program (DISP) seeks to assure on an ongoing basis.

Smaller suppliers do not need to maintain every specialist capability internally.

They do need access to sufficient expertise to understand the changing attack surface, assess the controls around it and provide executives with credible assurance that their Defence security obligations continue to be met.

Sources

Found this useful? Share on LinkedIn
Speak with us

Discuss your DISP, IRAP or security obligations.

We move from first conversation to active engagement in two to three weeks.