The little fix for big supply chain risks: You don’t need to connect everything

255 Views

Small and medium sized businesses (SMBs) – whether they like it or not – are inextricably embedded into a huge international web of commerce and digital connections. While that unlocks great possibilities for those SMBs, they’re also exposed to risks that emanate from the tiny mistakes and misconfigurations made far down their intricate and complex supply chains.

Take the CrowdStrike outage of 2024, in which a faulty update to the cybersecurity company’s Falcon software caused outages and paralysis in countless other companies – small and big – erasing millions in revenue in the process.

Mistakes aside, threat actors are busily targeting the supply chain, knowing that the best way to exploit a large enterprise or organisation is to exploit the SMB third parties and vendors that connect to them. In fact, Verizon’s 2026 Data Breach Investigations Report (DBIR), reports that these third parties are involved in nearly half of all breaches.

Supply Chain Scrutiny

The risk within the supply chain is growing and scrutiny is bearing down on every link. Enterprises are increasingly cognisant of the fact that every third party they connect to represents risk. Meanwhile, third party SMBs increasingly need to demonstrate that they won’t put their clients in danger. Audits are on the rise and Software Bills of Materials (SBOMs) are often required as a condition of engagement.

Regulators – through statutes like the Digital Operational Resilience Act (DORA) and Network Information Systems 2 (NIS2) – are now demanding that organisations take legal responsibility for the security of their supply chains. Insurers are also now making sure that policy holders regularly vet their third party suppliers in order to maintain their premiums and make sure that in the case of a breach, their claims are covered.

Supply chain risks are not only a security risk for enterprises and SMBs alike, but a compliance and business threat too. Still, that risk can be seriously mitigated by clamping down on a number of basic mistakes and misapprehensions that SMBs regularly make.

Stop Connecting Everything

The cardinal value of the digital world is speed and accessibility. Whether it be the API, the enterprise integration, the cloud native environment, or the SaaS provider, business technology of the last decades has been designed for agility and connectivity.

This has essentially provided a highway between – and into – the various businesses and organisations. Still, it’s those connections on which supply chain threat actors base their nefarious success.

Many SMBs rely on the agility that that connection provides. Indeed, many just connect up every app, service and SaaS product they have, granting them wide-ranging privileges and access rights. Unfortunately, the same connections that those things use legitimately will also be used by malicious parties to wreak havoc. The simple way to significantly mitigate supply chain risk is to simply stop connecting everything and strictly limit the scope of permissions of what must be connected to accomplish the desired result.

Finding What You Have

The first problem organisations face when they pursue this strategy is that they don’t actually know what they have or what it’s connected to.

This should be the first crucial step in mitigating supply chain risk: A thorough audit of all possessed digital infrastructure. From there, the connections and privileges of those various apps can be examined and understood by mapping the environments.

Network flow logs, endpoint agents and automated mapping tools can be useful here, providing crucial information about what assets are sending what information to where. As data is collected about an environment, you can start seeing where the dependencies lie, which components talk to which, which third party APIs lead to where, and which ports and protocols are in use.

Cutting Risky Connections

From there, an organisation can rifle through this complex web to establish what exactly needs to be connected and what doesn’t.

Third party connections, vendor access and APIs should be of primary focus. These are the connections that let outside entities into your environment and thus they must be closely examined to see what they can access, what they talk to, what privileges they possess and what kind of information they send or receive. Then, arbitrary internal connections can be examined in order to limit an attacker’s ability to move laterally within an environment.

Then those connections – once properly understood – can be severed where they represent undue risk. Load bearing connections between apps and services are important, severing them could cause huge outages and downtime for a business, so this needs to be done carefully. However, as many organisations will surely find, many of the connections aren’t necessary or even helpful and severing them will surely result in immediate mitigations in exposure.

The point is basic: Things that don’t need to talk to each other, must not talk to each other. An attacker can easily make use of a superfluous connection between an app and a service or between two organisations and this will be an especially frustrating problem if those connections don’t serve any clear value.

If you’re an enterprise, you rely on your third parties and SaaS vendors. But considering they are a prime target for supply chain attack; they’re also a huge risk vector and threaten to endanger your compliance and insurance status. For the SMBs supplying those enterprises, they need to make sure not to endanger their clients. Being the cause of a third party breach will surely send them running for the door.

In either case, understanding what assets you possess, and where they connect to is crucial to mitigate the risk of these attacks whether they target you, or use you as a vector.