Threat actors could be coming for your organization via third-party vendors—a danger in a cybersecurity landscape where IT teams and budgets are often stretched, necessitating outside help.
RSA Security CEO Rohit Ghai sees backdoor attacks on vendors as a major concern, he told IT Brew, likening it to healthcare workers taking appropriate hygiene precautions.
“The world may not be security first, but the cybersecurity vendors better be. The doctors better be washing their hands,” Ghai said.
Vend on. But IT teams are not an easy get, at least not compared to the potential infiltration hackers can achieve by attacking vendors, which can service multiple organizations. Plus, attackers can use disruption tactics to undo faith in cybersecurity as a whole.
“Fear is a weird kind of emotion, and these guys prey on people’s fear, confusion, and all of that, so by targeting cybersecurity vendors and breaching them, they’re actually eroding confidence in the cyber industry at large,” Ghai said.
Cybersecurity vendor funding has declined in recent months. IT Brew reported in April that some industry businesses are seeing a precipitous drop in investment—mostly the ones that are trying to overpromise on what they can deliver.
To keep reading IT Brew’s story on third-party vendor cybersecurity risk, click here.—EH
|