Software supply chain - the main loophole for hackers: 10 main dangers for companies

Teacher

Professional
Messages
2,677
Reputation
9
Reaction score
632
Points
113
The rating shows what you need to pay attention to when planning cyber defense.

The European Cybersecurity Agency (ENISA) has updated its cyber threat forecast, highlighting the top 10 threats that will have the greatest impact by 2030.
  1. Compromising the software supply chain came first, albeit with a slight reduction in the level of risk. According to ENISA, this is a consequence of the increasingly close integration of third-party suppliers and partners in the supply chain, which leads to the emergence of new vulnerabilities.
  2. Lack of qualified specialists. The Agency expresses concern about the willingness of organizations to develop talent and bridge the educational gap in the field of cybersecurity.
  3. The human factor and vulnerable outdated cyberphysical systems.
  4. Operating uncorrected and outdated systems in an overloaded cross-industry technology ecosystem.
  5. The threat of digital surveillance and loss of privacy, which shows a slight decrease in impact and probability estimates.
  6. International ICT service providers as a single point of failure. Increased risks associated with dependence on international suppliers.
  7. Advanced disinformation campaigns that lead to manipulation of public opinion.
  8. The rise of advanced hybrid threats.
  9. AI abuse. This includes risks associated with the misuse of artificial intelligence.
  10. Physical impact of natural and environmental disturbances on critical digital infrastructure.

Excluded from the list were threats related to the lack of analysis and control of space infrastructure and targeted attacks, such as ransomware through infection of smart devices.

Experts who participated in the study expressed concerns about accelerated global connectivity, increased user data collection, and increased reliance on automated data analysis for decision-making.

Other trends included the growing number of satellites that require regulatory frameworks, challenges associated with controlling personal data, and increased energy consumption in digital infrastructure.

ENISA stressed the importance of continuous assessment of current threats and trends to achieve a higher level of cybersecurity and improve its future plans.

In the ENISA 2022 report, one of the most worrying trends was the rise in attacks on software supply chains, especially those affecting code repositories. According to ENISA, between 39% and 62% of organizations were affected by cyber incidents involving third parties. However, only 40% of companies surveyed said they understand the cybersecurity and privacy risks associated with third parties.
 
Top