{"id":116783,"date":"2024-10-10T08:12:00","date_gmt":"2024-10-10T07:12:00","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2024\/10\/09\/blackberry-reveals-limited-visibility-of-software-supply-chain-leaving-uk-public-sector-exposed-to-attacks\/"},"modified":"2024-10-09T12:34:22","modified_gmt":"2024-10-09T11:34:22","slug":"blackberry-reveals-limited-visibility-of-software-supply-chain-leaving-uk-public-sector-exposed-to-attacks","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2024\/10\/10\/blackberry-reveals-limited-visibility-of-software-supply-chain-leaving-uk-public-sector-exposed-to-attacks\/","title":{"rendered":"BlackBerry reveals limited visibility of software supply chain leaving UK public sector exposed to attacks"},"content":{"rendered":"\n<p><em>The BlackBerry-commissioned study reveals more than half (51%) of software supply chains in the public sector were exposed to cyberattacks in the last 12 months.<\/em><\/p>\n\n\n\n<p>BlackBerry has revealed new research exposing the magnitude of software supply chain cybersecurity vulnerabilities in the UK public sector.<\/p>\n\n\n\n<p>More than half (51%) of UK IT decision-makers across healthcare, education and government organisations received notification of an attack or vulnerability in their supply chain of software in the last 12 months. Worryingly, it took more than two-in-five (42%) of organisations more than a week to recover.&nbsp;<\/p>\n\n\n\n<p>The survey of 200 IT decision-makers and cybersecurity leaders across the\u202fUK comes at a time when critical infrastructure attacks are increasing, particularly those targeting government, education and&nbsp;healthcare industries.&nbsp;&nbsp;<\/p>\n\n\n\n<p>As such, the latest BlackBerry analysis \u2013 conducted in April 2024 by Coleman Parkes \u2013 drew insights from almost a quarter of the total UK survey respondents across government, education and healthcare&nbsp;to identify the procedures their organisations have in place to manage the risk of security breaches from software supply chains. &nbsp;<\/p>\n\n\n\n<p>The latest findings show that operating systems (38%) and web browsers (17%) continue to create the biggest impact for public organisations. Following a software supply chain attack, public sector IT leaders confirmed a high level of impact in terms of financial loss (71%), data loss (67%), reputational damage (67%), operational impact (50%) and intellectual property loss (38%).&nbsp;<\/p>\n\n\n\n<p><strong>Software supply chain blind spots contradict security measures&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>UK organisations across government, healthcare and education confirmed having strict security measures in place to prevent attacks in their software supply chain, including data encryption (51%), training for staff (49%) and Multi-Factor Authentication (34%).&nbsp;&nbsp;<\/p>\n\n\n\n<p>Meanwhile, almost three-in-five (58%) public sector IT leaders believe their software supplier\u2019s cybersecurity policies are comparable or stronger (38%) than those implemented at their organisation. Furthermore, 96% of respondents were confident in their suppliers\u2019 ability to identify and prevent the exploitation of a vulnerability within their environment.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Yet, when it comes to the collection of evidence that attests to a supplier\u2019s level of software security to underpin this level of trust, less than half (47%) of IT decision-makers in the public sector said they ask for confirmation of compliance with certification and Standard Operating Procedures. Meanwhile, even fewer ask for third-party audit reports (38%) and evidence of internal security training (32%).&nbsp;<\/p>\n\n\n\n<p>Additionally, more than half (51%) of respondents had, in the last 12 months, discovered unknown participants within their software supply chain that they were not previously aware of, and that they had not been monitoring for security practices.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Enabling more impactful software supply chain inventories&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>Encouragingly, many UK IT decision-makers confirmed they perform an inventory of their software environment in near-real time (15%) or every month (28%). However, almost two in five (39%) respondents only complete this process every 1-3 months, while almost one-in-10 say they complete this process every 3-6 months (9%) or once a year (9%).&nbsp;&nbsp;<\/p>\n\n\n\n<p>However, companies were prevented from more frequent monitoring by several factors, including limited visibility across their software supply chain (53%), as well as a lack of technical understanding (49%), effective tooling (38%) and skilled talent (38%). More than a fifth (21%) also identified a lack of funding as a challenge preventing more frequent monitoring.&nbsp;&nbsp;<\/p>\n\n\n\n<p>As such, more than two-thirds (68%) said they would welcome tools to improve the inventory of software libraries within their supply chain and provide greater visibility to software impacted by a vulnerability.&nbsp;&nbsp;<\/p>\n\n\n\n<p>&#8220;Our latest research comes at a time when cyberattacks against the UK public sector are increasing in both volume and sophistication,\u201d said Keiron Holyome, VP of UKI &amp; Emerging Markets at BlackBerry. \u201cAs such, pressure is increasing to address software supply chain security vulnerabilities, which is a key focus for the UK government\u2019s \u2018Code of Practice for Software Vendors\u2019, given the huge risk they pose to the services that UK citizens rely upon daily.&nbsp;<\/p>\n\n\n\n<p>\u201cWhile it\u2019s positive to see more organisations within the public sector proactively monitoring their software supply chain environment,\u201d added Holyome. \u201cVisibility remains a key issue that IT leaders must tackle or risk exposing vulnerabilities for cybercriminals to exploit. Ultimately, how an organisation monitors and manages the security of its software supply chain must rely on more than just trust. Modern AI-powered Managed Detection and Response (MDR) technologies can provide 24\/7 threat coverage, empowering IT teams across the public sector to tackle emerging threats in their software supply chain and navigate complex security incidents with enhanced visibility and confidence.\u201d&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The BlackBerry-commissioned study reveals more than half (51%) of software supply chains in the public sector were exposed to cyberattacks in the last 12 months. BlackBerry has revealed new research exposing the magnitude of software supply chain cybersecurity vulnerabilities in the UK public sector. More than half (51%) of UK IT decision-makers across healthcare, education [&hellip;]<\/p>\n","protected":false},"author":50,"featured_media":116788,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17482,57,6617,93],"tags":[9120,183,1032,6852,6539,5006],"class_list":["post-116783","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-enterprise-security","category-research","category-top-stories","tag-blackberry","tag-cyberattacks","tag-public-sector","tag-research","tag-supply-chain","tag-uk"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/116783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=116783"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/116783\/revisions"}],"predecessor-version":[{"id":116786,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/116783\/revisions\/116786"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/116788"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=116783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=116783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=116783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}