Global supply chains held to ransom

Trend Micro research reveals visibility challenges as attack surface expands.

Cybersecurity leader Trend Micro has published new research that reveals global organizations are increasingly at risk of ransomware compromise via their extensive supply chains.

Trend Micro commissioned Sapio Research in May and June 2022 to poll 2,958 IT decision makers across 26 countries. The research revealed that 79% of global IT leaders believe their partners and customers are making their own organization a more attractive ransomware target. The challenge is particularly acute considering that potentially less well-secured SMBs make up a “significant” portion of the supply chain for over half (52%) of these organizations.

A year ago, a sophisticated attack on a provider of IT management software led to the compromise of scores of MSPs and thousands of downstream customers. Yet only 47% of organizations share knowledge about ransomware attacks with their suppliers. Additionally, 25% said they don’t share potentially useful threat information with partners.

This could be because organizations don’t have information to share in the first place. Detection rates were worryingly low for ransomware activities including:

Ransomware payloads (63%)

Legitimate tooling e.g., PSexec, Cobalt Strike (53%)

Data exfiltration (49%)

Initial access (42%)

Lateral movement (31%)

 

“We found that 52% of global organizations have had a supply chain organization hit by ransomware, potentially putting their own systems at risk of compromise”, said Bharat Mistry, Technical Director at Trend Micro. “But many aren’t taking steps to improve partner cybersecurity. The first step towards mitigating these risks must be enhanced visibility into and control over the expanding digital attack surface.”

The supply chain can also be exploited by attackers to gain leverage over their targets. Among organizations that had experienced a ransomware attack in the past three years, 67% said their attackers contacted customers and/or partners about the breach to force payment.

Commvault plans to acquire Satori Cyber Ltd to bolster its data security and AI governance...
Clumio Backtrack offers rapid, precise data recovery for DynamoDB, enhancing resilience for...
runZero teams up with Aqaio to enhance its exposure management platform in Germany, aiming to...
Cynomi's 2025 State of the vCISO Report reveals AI's profound impact on service delivery and the...
By Artur Martins, CISO | Cybersecurity Strategy Executive Advisor, Logicalis.
Alcatel-Lucent Enterprise introduces OmniVista Terra, offering combined on-premises and cloud...
NinjaOne unveils its automated endpoint management platform on Google Cloud Marketplace, enhancing...
Acronis partners with Metrofile Cloud to enhance disaster recovery, offering advanced solutions...