How to Reduce IT and OT Supply Chain Risk

TL;DR
Supply chain security must cover every third party involved throughout the life cycle of hardware, software, and services, including manufacturing environments and open-source components. As IT and operational technology converge, organizations should assess how suppliers protect production systems, understand what their software contains, and work in partnership to prevent altered components, tainted software, and unauthorized modifications from reaching customers.
Transcript
Good afternoon, folks. Thank you for attending the last session in this room today. We have a great presentation ahead of you. Just a couple of housekeeping items before we start. I'm the room host for the afternoon. There's a competition amongst the room hosts for least amount of trash in each room at the end of the day. If you could help me win, ... Read More
Key Insights
- Supply chain risk extends through the complete product life cycle because hardware, software, and services can involve many third parties. A weakness in any participating organization can affect its direct customer and potentially pass through that customer to others.
- IT and operational technology convergence increases exposure by connecting factories and industrial systems to internet services, cloud providers, analytics platforms, and remote support. These connections deliver operational benefits, but they also create more opportunities for outside parties to observe, influence, or disrupt functions.
- Operational function is an important attack surface because adversaries may target where an organization actually operates, not only the data it holds. The consequences become particularly significant when connected technology controls industrial processes, chemical recipes, production equipment, infrastructure, or safety-related functions.
- Third-party assessments are incomplete when they examine only a manufacturer's enterprise IT environment. Buyers of manufactured products should also determine whether the supplier maintains a security program for the production environment in which those products are built.
- Connected products bring third-party risk directly into organizations and homes because purchased computers, phones, printers, appliances, and industrial equipment originate in another party's manufacturing environment. Evaluating those upstream environments is therefore relevant even for organizations that do not operate their own factories.
- Remote industrial services create dependencies across organizational boundaries because suppliers may respond to equipment alerts or patch a customer's operational environment. Organizations must recognize these providers as part of the security ecosystem surrounding essential production functions.
- Software composition visibility is necessary for understanding supply chain exposure because organizations cannot adequately assess software risk without knowing what the software contains. The discussion identifies a standardized software bill of materials as an industry approach being considered by multiple groups.
- Supply chain security requires partnership because no single enterprise controls every third party involved in its products and services. Security professionals need comparable ways to assess diverse participants and must combine policy, operations, and technology to address altered components, tainted software, and unauthorized modifications.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How should organizations assess IT and OT supply chain risk?
Organizations should assess every third party involved throughout the life cycle of the hardware, software, and services they use or provide. For manufacturers, an assessment should cover both the corporate IT environment and the production environment where products are made. It should also consider connected operations, cloud analytics, remote services, software composition, altered components, tainted software, and opportunities for unauthorized modification.
Q: Why should third-party reviews include supplier factories?
Supplier factories matter because computers, phones, printers, industrial equipment, and other purchased items are produced inside operational environments. A review limited to the supplier's enterprise IT systems can miss risks within the manufacturing process. Organizations buying manufactured products should therefore determine whether the producer has a security program that protects its production environment and the products moving through it.
Q: How does IT and OT convergence change cybersecurity risk?
IT and operational technology convergence connects physical operations with internet services, cloud providers, analytics, remote support, and other digital capabilities. This increases the number and variety of parties that can observe, affect, or change devices and software. It also makes operational function a significant attack surface because disruption can reach factories, infrastructure, connected homes, industrial processes, and safety-related equipment.
Q: What is the supply chain attack surface in connected operations?
The supply chain attack surface includes the third parties, components, software, manufacturing environments, services, and connections involved in delivering and operating a solution. It can include cloud-based analytics, remote maintenance, software patches, open-source software, factories, and shipments. Risk arises when these elements allow altered parts, tainted software, diverted shipments, or unauthorized modifications to enter systems relied upon by customers.
Q: Why is a software bill of materials important?
A software bill of materials provides visibility into what software contains, which is necessary for understanding dependencies and evaluating software supply chain exposure. The discussion notes that MITRE, NTIA, ENISA, and other groups were considering a standardized approach. Without a clear account of software contents, organizations have difficulty assessing third-party components consistently across a broad and diverse ecosystem.
Q: What third parties belong in a technology value chain?
The technology value chain includes any third party participating anywhere in the life cycle of a hardware product, software product, or service. It is broader than a narrow list of direct suppliers and can include manufacturers, service providers, cloud providers, remote support organizations, software sources, and other parties that can influence what customers ultimately receive, install, connect, or operate.
Q: How can remote industrial services introduce supply chain risk?
Remote industrial services connect a provider to a customer's operational environment so the provider can perform activities such as responding to equipment alerts or applying patches. These services create useful operational capabilities, but they also form dependencies and access paths across company boundaries. Customers should treat the provider and its security practices as part of their third-party and supply chain risk program.
Q: How can organizations reduce unauthorized technology modifications?
Organizations can reduce the risk by combining policy, operational practices, and technology across the full third-party ecosystem. They should assess suppliers' production environments, examine risks throughout hardware, software, service, and shipment life cycles, seek visibility into software contents, and collaborate with value-chain partners. These measures address the opportunities for altered components, tainted software, diverted shipments, and other unauthorized modifications.
Summary & Key Takeaways
-
IT and operational technology convergence expands the attack surface beyond information and data to the functions that enterprises, governments, factories, infrastructure, and households depend on. Connected devices, cloud analytics, remote services, and internet-enabled production systems create paths through which outside parties can observe, affect, or change essential operations.
-
Third-party risk management should examine more than a supplier's corporate IT environment. When an organization buys computers, phones, printers, industrial equipment, or other manufactured products, it also depends on the factories producing them. Supplier assessments should therefore address security controls within production environments as well as conventional enterprise systems.
-
The relevant ecosystem includes every third party participating anywhere in the life cycle of hardware, software, or services. Effective protection requires partnership across this diverse value chain, visibility into software contents through approaches such as a software bill of materials, and coordinated policy, operational, and technical measures against tampering and unauthorized modification.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator