Supply Chain Attacks: Why Your Vendors Are Your Biggest Security Risk
The SolarWinds attack in 2020 made supply chain security a board-level conversation at organisations that had previously ignored it. Attackers compromised the build infrastructure of a widely-used IT management software provider and inserted malicious code into a legitimate software update. Eighteen thousand organisations downloaded and installed the compromised update. The breach affected US government agencies, technology companies, and critical infrastructure.
For most SMEs, that scale of attack feels remote. But the logic of supply chain attacks applies to businesses of every size, and the threats at the SME level are more immediate and more common than you might think.
What a Supply Chain Attack Is
A supply chain attack exploits trusted relationships between organisations. Rather than attacking your business directly — where you have defences — attackers compromise a supplier, software provider, or service partner who has legitimate access to your environment. The trusted relationship is the vulnerability.
The attacker's goal is to use that trusted access to get into your systems without triggering your security controls. Because the access comes through a legitimate channel — a software update you've approved, a support session from your IT provider, a file from a trusted business partner — it doesn't look like an attack.
The Types of Supply Chain Attack Most Relevant to SMEs
Software supply chain attacks involve compromising software your business uses — either by modifying the software itself (as in SolarWinds) or by attacking the infrastructure that delivers updates. For most SMEs, the practical risk comes from open-source software dependencies, smaller software vendors with less rigorous security, and software as a service providers that have direct integration with your systems.
Managed service provider (MSP) attacks are particularly significant. Your IT provider, managed security provider, or software-as-a-service vendor typically has privileged access to your systems. They may have credentials for administrative access, the ability to deploy software, and visibility into your entire environment. If they're compromised, attackers inherit that access. MSP attacks have become an explicit focus for criminal groups because compromising one MSP can provide access to dozens of their clients simultaneously.
Business email compromise through supplier impersonation exploits trusted email relationships. An attacker who has compromised a supplier's email account can send convincing instructions — updated bank details, payment requests, requests to click links — that appear to come from a trusted source. These attacks have caused significant financial losses to businesses of all sizes.
Third-party application integrations are increasingly common in business operations. Cloud applications that have read or write access to your data, API integrations between systems, and SaaS tools that store business data all represent potential exposure if those services are compromised.
Why Supply Chain Risk Is Growing
The attack surface of a modern business extends far beyond your own systems. The average SME uses dozens of cloud applications, multiple service providers, and various software tools — all of which represent potential supply chain risk.
At the same time, attackers have recognised that attacking the periphery of a target — suppliers, software, and service providers — is often easier than attacking the target directly. Security investment at the target organisation has improved; security investment at smaller suppliers and software vendors is often less mature. Attackers follow the path of least resistance.
Managing Supply Chain Risk Practically
Know your suppliers. This sounds obvious but many businesses lack a complete picture of their supplier relationships, particularly for software tools and cloud services adopted by individual departments without IT involvement. Shadow IT — tools used by staff without formal approval — is a supply chain risk you don't know you have.
Conduct an audit of the applications and services your business uses. For each, understand what access they have to your data and systems, what their security practices look like, and what your contractual rights are if they're breached.
Ask questions of your key suppliers. Particularly for suppliers with significant access to your systems — your IT provider, your accountant, your legal team — ask about their security posture. Do they hold Cyber Essentials or ISO 27001 certification? How do they protect the credentials they use to access your systems? What is their incident response process if they're compromised?
A supplier that resists security questions or can't answer them competently is a risk signal.
Apply least privilege to supplier access. The principle of least privilege applies to suppliers as much as to your own staff. Your IT provider should have access to what they need to manage your systems — not to your financial records, HR systems, or other sensitive data they don't need to touch. Review and limit supplier access permissions regularly.
Monitor supplier access. Know when suppliers are accessing your systems, what they're doing, and whether that activity is consistent with their support role. Anomalous activity — access at unusual times, from unusual locations, to systems outside the scope of support — should be flagged.
Software update practices. While it's generally correct to apply security patches promptly, very large updates to critical systems benefit from a brief delay and review, particularly if the vendor has not confirmed the update through their usual process. A balance between promptness and caution is appropriate.
Contractual protections. Your supplier contracts should include security obligations — minimum security standards, notification requirements if they're breached, and clarity on your rights to audit security practices. Standard terms often don't include these; they need to be negotiated.
Supply chain security is an area where many SMEs have significant unmanaged risk. If you want to understand your supply chain exposure and what to do about it, we can help you work through the assessment. Get in touch.