Sony Pixel Power calrec Sony

Cyber Month: Thursday Thoughts with Thijs: Supply-chain attack

06/10/2022

All businesses have suppliers, fact. But have you ever considered the associated risk of a cyber-attack to your suppliers? Commonly known as either a supply chain attack or third-party risk.

My first musing of Cyber Security Month: what can you do to minimise the risk of a supply-chain attack?

Firstly, what do I mean by a supply chain-attack? Well, these attacks aren't carried out directly on a business, but on its suppliers, such as the Kaseya ransomware attack in 2021. Kaseya offers software that allows companies to manage other companies' IT infrastructure. To use this software, there must be a trusted connection between the vendor and the environment. However, unfortunately there was a flaw in the software that was then exploited by criminals - they only needed to launch their attack on one company in order to gain access to many others to conduct their criminal activities.

How can you minimise this risk?

Keep a register of all your suppliers. Look at the suppliers who have direct (and indirect) access to your environment. Often, access is requested by default due to convenience, either by a direct (continuous) connection or software used to achieve remote access (indirect connection). It's important to know who manages that connection and what software is used to provide remote assistance, as well as creating an overview and monitoring this in your list of suppliers.

Understandably, sometimes it isn't always feasible check in detail if your suppliers have everything in order with regards to information security. So, to try and combat this, I would highly recommend verifying that the supplier has a valid ISO/IEC 27001 certificate and check their statement of applicability.

For your most critical processes and components, you must meticulously go through your agreements with your suppliers - not only those with access agreements - and consider:

Is there a service level agreement (SLA) in place?

What action/reaction can you count on in case of an incident?

Which other suppliers does your supplier use?

Are there any suppliers that may pose a potential risk? For example, can the supplier still guarantee its services to you if one of their suppliers fail?

Another important aspect of supply chain security is checking whether a processor agreement is needed or not - if you need a hand with this, turn to your local Data Protection Authority (DPA) for guidance. If you do need one, make sure that you carefully read the agreement and check, for example, which sub-processors are already known. Don't forget to regularly check and review your agreements, at least on an annual basis, as nothing changes as quickly as the cyber security landscape.

Finally, it strikes me that outsourcing services or tasks to third parties has become commonplace. Most likely due to having to organise and source everything that makes a business run, things such as equipment, software and knowledge in-house, which can be quite expensive. It is therefore absolutely imperative, if you are involving third parties, to be well aware of who is outsourcing what. Outsourcing services does not absolve you of responsibility.

So, to recap my Thursday Thoughts regarding supply-chain attacks:

Keep a register of all your suppliers

Check at least for valid ISO/IEC 27001 certificates

Carefully go through your established agreements with your suppliers

Review your agreements on annual basis

Need some help going through the agreements with your suppliers in the field of information security? Resillion is more than happy to assist you. Contact us for more information.

lang: en_GB

Our Accreditations and Certifications
LINK: https://www.resillion.com/cyber-month-thursday-thoughts-with-thijs-sup...
See more stories from eurofins

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

06/09/2026

Dolby and MagentaTV Bring Fans Closer to the FIFA World Cup 2026 in Germany with Dolby Vision and Dolby Atmos

June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

27/06/2026

Through Their Lens: What Cinematographer Amy Vincent Saw at the 2026 Directors Lab

There's no doubt that you've seen the world through Amy Vincent's ey...

27/06/2026

UJAM release Retrocraft

Brings together saturation & lo-fi effects Following on from the release of their Voxcraft vocal-processing plug-in, UJAM have announced the launch of Retro...

27/06/2026

A record 4.84 million Australians choose SBS as the Socceroos advance at FIFA World Cup 2026

A record 4.84 million Australians choose SBS as the Socceroos advance at FIFA Wo...

27/06/2026

Apogee CRAS Symphony Mkii Education Feature Blog

Why CRAS Upgraded to Symphony I/O MK II When an audio school runs studios all day, every day, gear doesn't just need to sound good , it needs to survive rea...

27/06/2026

MultiDyne Acquires the Assets of MRMC

Share Copy link Facebook X Linkedin Bluesky Email...

27/06/2026

Spectrum Intelligence Ventures Launches Latis

Share Copy link Facebook X Linkedin Bluesky Email...

27/06/2026

Krotos Video to Sound Plugin Now Available for Adobe Premiere Pro

Krotos Video to Sound Plugin Now Available for Adobe Premiere Pro Brie Clayton June 26, 2026 0 Comments Editors can analyze footage, generate synchron...

27/06/2026

Mirai Media Elevates Digital and Broadcast Productions with Blackmagic Design

Mirai Media Elevates Digital and Broadcast Productions with Blackmagic Design Brie Clayton June 26, 2026 0 Comments Studio uses Ultimatte 12 HD and Po...

27/06/2026

Lutra Cafe & Bakery Opens At American Tobacco Campus

DURHAM, N.C. - JUNE 26, 2026 - Lutra Cafe & Bakery has opened its first brick-and-mortar location at American Tobacco Campus after owner Chris McLaurin operated...

26/06/2026

SVG GameDay, Ep. 21: Minnesota Vikings Allan Wertheimer - Large-Scale Shows in Minny

In-venue and creative video staffers at the professional and collegiate level ha...

26/06/2026

Strike Fighter League Announces Second Online Tournament, Set for July 25 in Las Vegas

Strike Fighter League (SFL), a professional air combat digital sport combining f...

26/06/2026

InfoComm 2026: Wisycom Announces MPR60 Firmware Update, MATF Antenna Matrix, and PFL RFoF Box

Wisycom has announced three new additions to its professional wireless ecosystem...

26/06/2026

Eurovision Services Inaugurates Expanded Master Control Room in Madrid

Eurovision Services inaugurated an expanded Master Control Room (MCR) in Madrid on June 1, 2026, building on a broadcast hub the company has operated in the cit...

26/06/2026

Midco Sports and University of North Dakota Renew Broadcast and Sponsorship Partnership

Midco Sports and the University of North Dakota (UND) have announced a two-year ...

26/06/2026

G&D and VuWall Appoint Vutec as Exclusive South Africa Distributor

Guntermann and Drunck (G&D) and VuWall, both part of the Panoptec Technologies Group, have appointed Vutec (Pty) Ltd as exclusive distributor for their KVM and ...

26/06/2026

Visit Seattle Launches Drone Scoreboard at Space Needle for FIFA World Cup 2026

Visit Seattle, the official destination marketing organization for Seattle and King County, has launched what it describes as the world's first drone scoreb...

26/06/2026

CP Communications Provides RF and Wireless Support for 2026 NBA Draft at Barclays Center

CP Communications provided RF video, audio, and crew communications support for ...

26/06/2026

Reimagined MoonPay X Games League Kicks Off With Three-Day Event in Sacramento

Produced by longtime partner Echo Entertainment, the action-sports property is now a team-based year-round league The inaugural season of the MoonPay X Games L...

26/06/2026

MultiDyne Acquires MRMC, Expands into Camera Robotics and Motion Control

The deal establishes MultiDyne Robotics and Motion Control, maintaining the well-known MRMC brand.MultiDyne Video & Fiber Optic Systems has acquired the assets ...

26/06/2026

TNT Sports Heads Into Year 2 of NASCAR Return With New NEP Truck, Expanded In-Car Experience

PX1 will debut at Sonoma as TNT leans into super-slo-mo, drones, SMT data integr...

26/06/2026

Ratings Roundup: USMNT-Australia Draws 23M Viewers; Mexico-South Korea Is Most-Watched Spanish-Language Soccer Match Ever

Ratings Roundup is a rundown of recent rating news and is derived from press rel...

26/06/2026

David Kuckhermann brings calabash to Celemony Tonalic

Virtual session musician plug-in gains new percussion options Celemony's latest update for their virtual session musician platform complements the exist...

26/06/2026

Softube unveil the Console 1 Compact

Half-size model joins Console 1 line-up Shortly after the release of their new Flow Studio controller, Softube have announced the launch of another new surf...

26/06/2026

ELT Group and Rohde & Schwarz sign a cooperation agreement to explore commercial opportunities in electromagnetic warfare and defense

ELT Group and Rohde & Schwarz sign a cooperation agreement to explore commercial...

26/06/2026

Lightware Powers Teddy Swims UK And Europe Tour With Adva...

For Teddy Swims sold-out I've Tried Everything But Therapy tour, event technology specialists, PRG, provided video, automation and lighting across 19 date...

26/06/2026

Taurus TPN powers AV workflows at NurnbergMesse

Modern exhibition and event venues face the challenge of seamlessly integrating traditional conference technology, professional broadcast workflows and IP-based...

26/06/2026

FCC Adopts New Cybersecurity Requirements for Alerting Systems

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Study: Roku Most Used But Not Highest Rated Streaming Platform

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Samsung Ads Announces First Shoppable CTV Partners

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Gray Media Names Annie Cordell General Manager of WMBF

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Neko Oji: The Guy That Got Reincarnated as a Cat Edited with DaVinci Resolve Studio

Neko Oji: The Guy That Got Reincarnated as a Cat Edited with DaVinci Resolve Stu...

26/06/2026

Adobe to Acquire Topaz Labs

Adobe to Acquire Topaz Labs Brie Clayton June 25, 2026 0 Comments Adobe has seen strong demand for its AI products for creatives, including Adobe Fire...

26/06/2026

Berklee Students Earn Dedicated Section at Raindance Film Festival in London

Berklee Students Earn Dedicated Section at Raindance Film Festival in London Five documentary short films produced in the Africana Studies Department screen a...

26/06/2026

Keeping Pace with the Race

How IMS Productions and FOX Sports scaled coverage of the 109th Indianapolis 500. The last lap of this year's Indianapolis 500 delivered the kind of ending...

26/06/2026

Prison Wives of TikTok is Locked In for U and U&W

Flicker Productions to produce five-part docu-reality series following women who have fallen for men in prison and have become TikTok sensations, with brands an...

26/06/2026

Automating post-production workflows with Baselight, Daylight, Nara & FilmLight API. New York. 8 July 2026

Catch up on the latest developments across Baselight and Daylight v7, Nara and F...

26/06/2026

DFT installs second Polar HQ at China News Film Confirming Position as China's Leading 8K Film Preservation Partner

26. June 2026 News DFT is pleased to announce that a second Polar HQ film s...

26/06/2026

New documentary Freedom Founder: Thomas McKean and the American Revolution comes to RT

New documentary Freedom Founder: Thomas McKean and the American Revolution airs ...

25/06/2026

Launching a Career in Broadcast Engineering: Academic Paths and Essential Certifications

Launching a Career in Broadcast Engineering: Academic Paths and Essential Certif...

25/06/2026

SVG Students To Watch: Jude Kieffer, Ball State University

This superstar shooter/storyteller from Central Indiana hopes to make his mark in the blossoming sports-documentary and -features space In the live-sports-vid...

25/06/2026

Presidio and NHL Renew Multiyear North American Technology Partnership

Presidio and the National Hockey League have announced a multiyear renewal of their North American partnership. Presidio will remain an Official Technology Inno...

25/06/2026

Strike Fighter League Hits the Industry as First Professional Air Combat Sport

Strike Fighter League (SFL) is the world's first professional air combat digital sport that combines elite human performance and physical immersion with cut...

25/06/2026

Rise Reveals 2026 Worldwide Mentoring Cohorts to Support Future Industry Leaders

Rise, the award-winning advocacy group for gender diversity in the broadcast and media technology sector, is pleased to announce the global mentoring cohort for...

25/06/2026

MLB Network To Air American Association of Professional Baseball All-Star Game for First Time on July 15

The 2026 American Association of Professional Baseball (AAPB) All-Star Game will...

25/06/2026

Mediaproxy Partners with HVS for U.S. Broadcast Market

Mediaproxy has named Heartland Video Systems (HVS) as its exclusive partner for US television broadcasting. The Wisconsin-based systems integrator will represen...

25/06/2026

Backblaze Inks Five-Year Multi-Exabyte Data Storage Agreement with CoreWeave

Backblaze has formed an agreement with CoreWeave to create The Essential Cloud for AI. Under the multi-exabyte, $335 million agreement, Backblaze will provide...