Targeted supply chain attacks and new regulatory requirements in Ukraine, such as the State Service of Special Communication and Information Protection Order No. 836 of December 17, 2023 1, demand that Ukrainian companies rethink their approaches to IT component procurement and integration. This will help avoid embedded vulnerabilities and malicious software.
Why IT infrastructure supply chain security is critical for Ukrainian businesses
Cyber threats originating from supply chains are recognized as some of the most dangerous. Incidents like the SolarWinds attack, which affected hundreds of large enterprises 2, and Ukraine's experience with the NotPetya virus, which spread through a бухгалтерської program update server 2, demonstrate the devastating consequences of supply chain compromise. These attacks highlight that even companies with robust internal cybersecurity defenses can be vulnerable through their suppliers.
In Ukraine, cybersecurity requirements for suppliers working with the public sector and critical infrastructure facilities have been strengthened. The State Service of Special Communication and Information Protection Order No. 836 of December 17, 2023 1 establishes four risk levels for suppliers. For businesses, this means that compliance with these requirements is becoming a mandatory condition for participating in government procurement.
Hidden threats: Where vulnerabilities can hide in hardware and software
The IT infrastructure supply chain is multi-stage and complex, creating numerous points for potential compromise. Vulnerabilities can be hidden in both hardware and software at various stages: from development and manufacturing to delivery and integration.
- Hardware: Risks include the use of counterfeit components, modification of equipment with malicious firmware or backdoors, and flaws in manufacturing processes. For example, attackers can replace legitimate components with malicious ones during transportation or storage.
- Software: Threats encompass embedded backdoors, undocumented features, the use of vulnerable open-source components, and the compromise of update mechanisms, as happened with NotPetya 2. Malicious software can be integrated during development or added through compromised repositories.
Reduced visibility and understanding of how technologies are developed, integrated, and deployed, as well as the processes, procedures, and standards used to ensure their security, reliability, and integrity, are key challenges.
Effective vetting of IT solution providers: What to ask and what to look for
To minimize risks, Ukrainian companies must implement a systematic approach to evaluating IT solution providers. This includes verifying their security practices and transparency regarding the components they supply.
- Security practices and certifications: Demand confirmation from suppliers of compliance with international information security standards, such as ISO 27001 or SOC 2. The presence of such certificates indicates the maturity of the supplier's information security management system. It is also important to evaluate their vulnerability response policies and transparency regarding their own component supply chain.
- Availability of SBOM (Software Bill of Materials): An SBOM is a complete list of all software components included in a product, including versions, licenses, and dependencies 3. It provides transparency in the software supply chain, allowing for quick identification of vulnerabilities and application of patches. Require suppliers to provide an SBOM for the software supplied.
- Hardware attestation mechanisms: For hardware components, it is important to understand how the supplier guarantees their authenticity and integrity. This may include the use of Hardware Root of Trust technologies, secure bootloaders, and firmware integrity verification mechanisms.
- Incident response plans: Assess how quickly and effectively the supplier can respond to cyber incidents related to their products or services. The presence of clear response and communication plans is critically important for minimizing damage in the event of an attack.
Component verification methods: How to ensure the security of purchased software and hardware
After procuring components, it is important to conduct technical verification to ensure the absence of embedded threats.
- Internal audit and penetration testing (pentest): Regular internal audits and independent pentests of hardware and software allow for the identification of vulnerabilities and potential points of compromise. This includes checking configurations, patches, and overall security policy.
- Third-party certifications and independent laboratories: Engaging independent experts or certified laboratories to verify component security can provide an additional level of assurance. This is especially important for critical systems.
- Tools for code and component analysis:
- SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing): These tools help automatically detect vulnerabilities in software code during development and testing phases. SAST analyzes code without executing it, while DAST tests the application during its operation.
- SCA (Software Composition Analysis): SCA tools analyze software composition, identifying open-source components and known vulnerabilities within them.
- Firmware and microcode integrity verification: Using cryptographic methods to verify the integrity of hardware firmware and microcode helps ensure they have not been maliciously modified.
Implementing a supply chain security strategy: From policy to practice
An effective supply chain security strategy requires a systematic approach and integration into the company's overall cybersecurity management system.
- Development of internal procurement policies and procedures: Create clear policies that include requirements for supplier and component security, as well as procedures for their verification and risk assessment. This should become an integral part of the procurement process.
- Staff training: Provide regular training for personnel responsible for procurement, IT operations, and cybersecurity on supply chain threats and methods for their detection and prevention.
- Continuous monitoring and supplier risk management: Implement mechanisms for continuous monitoring of the security status of suppliers and their products. This includes tracking new vulnerabilities, changes in their security practices, and responding to incidents. Supplier risk management is critically important for business continuity.
- Integration with the overall cybersecurity management system: Supply chain security principles should be integrated into existing cybersecurity frameworks, such as NIST SP 800-161 4, which provides guidance on Cyber Supply Chain Risk Management (C-SCRM) 5. This standard helps identify, assess, and mitigate risks originating from suppliers, including hardware, software, and services.
Checklist for evaluating IT solution providers and component verification methods
| IT solution provider evaluation criteria | Component verification methods |
|---|---|
| Presence of ISO 27001 or SOC 2 certifications | Internal audit and penetration testing (pentest) |
| Provision of SBOM in machine-readable format | Engagement of third-party certifications and independent laboratories |
| Use of Hardware Root of Trust technologies | Code analysis tools (SAST, DAST) |
| SLA metrics for incident response | Component analysis tools (SCA) |
| Vulnerability management policies | Firmware and microcode integrity verification |
Softline IT, as a system integrator, understands the importance of IT infrastructure supply chain security and helps plan and implement cybersecurity solutions: from auditing the current state to an agreed-upon plan for changes.
Softline IT helps teams plan and implement cybersecurity, from an assessment of the current environment to an agreed change plan.
