Search

Popular Searches

Admissions Assessment and Certification Class Schedules Nursing Tuition & Fees Library and Tutoring Services
myFSCJ Request for Information Manta Rays Athletics Giving Student Notification
Florida State College at Jacksonville logo
Map | Apply

  • Home
    • Future Student
    • Current Student
    • Returning Student
    • Military/Veteran
    • Alumni
    • Transient Student
    • News & Events
    • Faculty/Staff
    • Business
    • Looking for A-Z List
    • Areas of Study
    • Catalog
    • Associate in Arts
    • Associate in Science Degrees
    • Bachelor's Degrees
    • Certificate Programs
    • Workforce Education
    • Adult/ESOL Education
    • Short Term Programs
    • Class Schedules
    • Credit for Prior Learning
    • FSCJ Course Syllabus Tool
    • FSCJ Online
    • Dual Enrollment
    • Honors Program
    • Admissions
    • Future Students
    • Steps to Enroll
    • Student Affairs & Enrollment Management
    • Orientation
    • Admissions Events Calendar
    • Transcripts
    • Academic Advising
    • First Year Experience
    • International Students
    • Student Records
    • Assessment and Certifications
    • Request for Information
    • Tuition and Fees
    • Financial Aid Services
    • Scholarships
    • Student Financial Services
    • Student Employment
    • Veterans Benefits
    • Veteran Tuition and Waivers
    • Career Development
    • Student Life
    • Personal Support Services
    • Student Support Services
    • Bookstore
    • Food Pantry
    • Child Care
    • Library and Tutoring Services
    • Student Computing Resources
    • FSCJ Police and Public Safety
    • Title IX
    • Discover FSCJ
    • FSCJ Digital Archive
    • Mission & Vision
    • Human Resources
    • Governance & Administration
    • Employee Directory
    • Community Engagement
    • Office of the President
    • District Board of Trustees
    • Policies & Procedures
    • Purchasing
    • Consumer Information
    • Center on Economic Education (CEFE)
    • Center for Civic Engagement
    • Vision Education & Rehabilitation Center
    • FSCJ Foundation
    • FSCJ Artist Series

TechTarget: Supply chain software poses security risks

Nov 1, 2022, 10:57 AM

Link to article: https://searcherp.techtarget.com/feature/Supply-chain-software-poses-security-risks

Poor internal security procedures and a lack of compliance protocols -- especially for small suppliers -- can introduce cybersecurity threats into global supply chains.

Information security risks in supply chain software are becoming increasingly prevalent, particularly as global companies have become more dependent on third-party vendors.

According to Symantec, more and more attackers are injecting malware into the supply chain to infiltrate organizations. In fact, there was a 200% increase in these attacks in 2017 -- one every month compared to four attacks annually in previous years.

Supply chain software offers a new arena to threat actors intent on penetrating enterprise networks, said Peter Nilsson, vice president of strategic initiatives at MP Objects, a provider of supply chain orchestration software in Boston.

"Previously, people had their ERPs behind their very tight firewalls, and no one from the outside could get in without being monitored by the hawk eyes of the IT department," he said. "Now, enterprises are saying, 'We need to collaborate with our partners and we have to open up our ERP and let them in.'"

But if those third parties don't have adequate security, attackers can infiltrate their systems to attack the enterprise.

Any time an enterprise introduces software into the mix of its supply chain, it runs the risk of cybersecurity issues, said Justin Bateh, supply chain expert and professor of business at Florida State College in Jacksonville, Fla. Most risks are caused by not having the proper controls in place for third-party vendors.

"There are many low-tier suppliers that will have weak information security practices, and not having clean and limited guidelines for these providers about security expectations will pose a significant threat," he said.

Causes of potential security risks

Poor internal security procedures and a lack of compliance protocols can also introduce potential threats, including marketing campaign schemes, privacy breaches and disruption of service attacks, according to Bateh.

In addition, smaller companies may use inadequate software coding practices. As such, larger enterprises can't be sure the software is being checked for quality as it goes through its development cycle, said Lisa Love, owner and president of LSquared, an information security consulting firm in Greenwood Village, Colo.

Consequently, something as unintentional as bad scripting can introduce vulnerabilities into the providers' supply chain software, as well as into the enterprise, which attackers could then exploit, she said.

Jason Rhoades, a principal at Schellman & Co., a provider of attestation and compliance services in Tampa, Fla., agreed that in recent years the enterprise's attack surface has increased along with the tremendous growth in the supply chain.

"Looking at the recent Equifax breach confirms that vendor and supply chain software poses a true security risk that the enterprise cannot ignore," he said.

Equifax blamed its 2017 breach on a flaw in the third-party software it was using. And the massive breach of Target's systems in 2013 was caused by attackers who stole the login credentials of its HVAC contractor and used them to infiltrate Target's network.

Jonathan Wilson, a partner at the law firm Taylor English Duma LLP in Atlanta, agreed that many security risks come from the data connections and handoffs in the supply chain moving from smaller to larger providers.

"A lot of these small companies and startups don't have robust data security systems," said Wilson, who has represented a Fortune 500 international supply chain logistics provider. "They get a breach or some sort of exploitation is involved, and by working their way up the chain, the attacker can utilize the permissions that the smaller vendors get to obtain access to the larger company's system."

Another way hackers could introduce risk into an enterprise is via the supply chain software itself, according to Michael O'Malley, vice president of strategy at Radware, a provider of cybersecurity services in Mahwah, N.J. Most supply chain applications have some type of web interface with a login page to ensure that only the right people are authenticated and allowed to access the application.

Attackers can also use credential stuffing to infiltrate an enterprise via an unprotected web interface, he said. The attackers can hack into the interface, enter a legitimate username and password, and pose as someone else.

"Or they do something else offline through a phishing email scam to get users of the software to click on a link or respond to an email and dupe them into sharing their credentials," O'Malley said. "They can then use those credentials to log in or break into the application."

Another way attackers can penetrate an enterprise's network via the supply chain is from the inside, according to O'Malley. This is where IoT devices come into play. More and more of these supply chain software applications -- particularly in high-tech manufacturing -- are part of an IoT network that provides different diagnostics and information about the machines on a factory floor.

These devices are providing all this real-time input back to the supply chain management software application. However, they can be easily compromised because they tend to be very inexpensive Linux-based devices that weren't designed with security in mind, and they don't have the necessary protections against hacking, he said.

"What we commonly see is that within minutes of these devices being connected to the internet, someone infiltrates them and puts a piece of malware or a bad bit of code on them," O'Malley said. "And those are then used later as an attack on something else or in an attack on the software application itself."

FSCJ Logo

Florida State College at Jacksonville empowers students to achieve their goals by providing exceptional learning experiences that promote intellectual growth, civic engagement, and workforce connections.

Academics
Workforce/Certificate Programs Associate in Arts Degree Associate in Science Degree Bachelor's Degrees Online Learning Academic Calendar Catalog Library and Tutoring Services
Admissions
Apply Now Tuition & Financial Aid Scholarships Campus Tours International Students Transfer Students Military and Veterans Services
Contact Us
(904) 646-2300
welcome@fscj.edu
Mon - Thur: 8 a.m. - 6 p.m. (Summer Hours)

© 2026 Florida State College at Jacksonville. All rights reserved.

Privacy Policy Acceptable Use Policy
Aspen Prize Top 150
SACS Accredited
Military Friendly School Logo

Florida State College at Jacksonville is accredited by the Southern Association of Colleges and Schools Commission on Colleges (SACSCOC) to award associate and baccalaureate degrees. Florida State College at Jacksonville also may offer credentials such as certificates and diplomas at approved degree levels. Questions about the accreditation of Florida State College at Jacksonville may be directed in writing to the Southern Association of Colleges and Schools Commission on Colleges at 1866 Southern Lane, Decatur, GA 30033-4097, by calling (404) 679-4500, or by using information available on SACSCOC’s website (www.sacscoc.org). Florida State College at Jacksonville does not discriminate against any person on the basis of race, disability, color, ethnicity, national origin, religion, gender, age, sex, sexual orientation/expression, marital status, veteran status, pregnancy or genetic information in its programs, activities and employment. For more information, visit the Office of Civil Rights Compliance page.

Ask Rayzor