Many IT decision-makers face a "significant challenge" as they try to secure their software supply chains against cyberattacks, according to a survey from BlackBerry.Here are the key takeaways from the survey:
Most IT decision-makers "have confidence that their software supply chain partners have policies in place of at least comparable strength to their own," BlackBerry VP of Product Security Christine Gadsby. However, a lack of granular detail often exposes software supply chain vulnerabilities that cybercriminals exploit.
Furthermore, 90% of IT decision-makers said it takes their organization up to a month to recover from a software supply chain attack, BlackBerry's survey revealed.
- 80% of IT decision-makers said their organization was notified about a cyberattack or vulnerability in its software supply chain in the last 12 months.
- 77% had discovered unknown participants within their software supply chain that they were not previously aware of and had not been monitoring for adherence to critical security standards in the last 12 months.
- A lack of skills (54%) and visibility (44%) were among the biggest factors that prevented IT decision-makers from frequently monitoring their organization's software supply chain.
How Software Supply Chain Attacks Disrupt Organizations
Among IT decision-makers who reported software supply chain attacks, most noted that these attacks had the biggest impact on their organizations' operating systems and web browsers, BlackBerry indicated.After a software supply chain attack, survey respondents reported the following issues:- Significant operational disruption (59%)
- Data loss (58%)
- Reputational impact (52%)
