Articles

Third-Party Risk Is Now Fourth- and Fifth-Party Risk

When can a manufacturing company be cyberattacked and not cyberattacked at the same time?

The answer — anytime — is not a paradox like the famous thought experiment about Schrödinger’s cat. Manufacturers belong to supply chains and rely on vendors, many of which have digital connections that can be exploited by hackers. An attack on one company can become a way into another.

Cyber risk now radiates outward from large companies and prime contractors to subcontractors and vendors, from first- to second- to third-, fourth- and even fifth-party relationships.

Here’s an example of how a large organization can be attacked indirectly.

In December 2024, Chinese hackers broke into the U.S. Treasury Department. But they didn’t go in the front door. They first targeted the computers of BeyondTrust, a cybersecurity company that does work for the U.S. government.

According to industry reports, the hackers found a vulnerability in third-party software used by BeyondTrust, then broke into part of BeyondTrust’s cloud environment and stole a digital key that gave them access to software used by IT technicians to connect remotely to customers’ computers. The hackers used that access to enter several U.S. Treasury workstations and obtain unclassified documents.

Trace the path of exploitation in the above example: From (1) a vulnerable piece of third-party software into (2) BeyondTrust’s cloud environment, where (3) a digital key accessed (4) IT software that connected remotely into (5) Treasury Department workstations.

That is why cybersecurity is a team sport. Threats can travel up the supply chain or sideways across customer relationships. Everyone has a role to play in protecting systems and operations.

“How far down the food chain can risk matter? Further than most people assume,” said Michael Tanji, director of cybersecurity for MxD, the National Center for Cybersecurity in Manufacturing as designated by the U.S. Department of War (DOW).

Using defense industry supply chains as an example, Tanji said that prime contractors are best-positioned to defend against cyberattacks. They are large organizations with direct ties to the DOW, so they have contractual obligations and dedicated staff. Major subcontractors (Tier 1) also may have contractual obligations, such as those contained in CMMC 2.0.

But further down the supply chain and across vendor relationships, the situation gets dicey. Companies may be digitally connected while lacking cybersecurity expertise or falling short on their commitments.

“The real danger zone lies between Tier 2 through Tier 4,” Tanji said. “Tier 1 subs are usually capable enough to have some sort of security program. Below Tier 4, the subcontractor’s systems are often so removed from the prime that a compromise there doesn’t have much of a path upward. It’s the middle tier where a company has enough access to be useful to an attacker and not enough of a security budget to stop one.”

Below, Tanji answers questions about managing third-party cyber risk especially within the defense industrial base (DIB). 

Q: Is it too much to ask for suppliers to also feel responsibility for their own subcontractors and third-party vendors’ cybersecurity hygiene?

Michael Tanji: There are three schools of thought.

The first says prime contractors in the DIB should own it, full stop, because they have the money, expertise, and the contractual leverage. The problem is that primes often don’t have visibility into Tier 3 and Tier 4. They rely on Tier 1 suppliers to do their own diligence, and that diligence can get thinner the further down the supply chain you go.

The second puts the burden on the subcontractors themselves: If you want defense revenue, security is the cost of admission. I understand the logic, but it can be detached from reality. A 12-person precision machine shop in Ohio making a single bracket for a missile system doesn’t have a chief information security officer (CISO). It has an office manager who also does IT on Tuesdays. Telling that company, “Your responsibility, figure it out,” can produce exactly the outcome we’re trying to avoid: paper compliance and real vulnerability.

A third option is a tiered-responsibility model. The prime sets the floor and provides the tools; the subcontractor is responsible for operating within that floor.

Practically, this looks like primes pushing down flow-down clauses (e.g. DFARS 252.204-7012) along with shared threat intelligence, discounted access to endpoint detection and response, and templates for documents such as a System Security Plan (SSP) and Incident Response (IR) plan.

Q: What does the ideal cybersecurity relationship look like between a prime contractor and its supply chain?

M.T.: If a prime opens the relationship with nothing but boilerplate flow-down clauses, the subcontractor may see them as a compliance tax, not a security obligation. A lot of people pinky-swear that they’ll meet requirements and count on the fact that audits are rarely conducted. That can create a false sense of security for the prime.

A better approach is for the prime’s program manager or supply chain security lead to have an actual conversation early in the relationship: What does your network look like? Where does our data live once it’s on your systems, Who else touches it?

That conversation can surface things a contract clause never will, such as a subcontractor outsourcing its IT help desk to a third party overseas. That discovery starts a whole new conversation about risk.

A contract still needs to exist, because you need enforceable language for the subs who won’t engage honestly. But a collegial approach is more likely to drive the change you want.

Q: What are the specific targets of attack and methods that cybercriminals use to get into supply chains?

M.T.: Phishing, credential stuffing and exploited remote-access software remain the workhorses. What’s different about supply chain attacks is the target selection. Instead of hitting the well-defended prime, attackers go after software or platforms that many companies trust.

The Oracle E-Business Suite compromise this year is an example. A single exposed system, exploited as a zero-day vulnerability before a patch existed, turned into a mass event with downstream victims across many organizations that had nothing to do with each other except sharing that one platform.

That pattern is likely to repeat because it’s efficient for attackers: One flaw, hundreds of victims.

Q: Describe the steps a supplier should take in managing cybersecurity in order to account for third-party risk.

M.T.: First, document who has access to your network and why.

Second, treat your own sub-tier vendors the way your prime treats you: Flow your requirements down. You don’t have to absorb all the risk yourself.

Third, ask your software suppliers for a software bill of materials (SBOM). SBOMs can help track software components and identify exposure to vulnerabilities.

Fourth, run a tabletop exercise with your suppliers. It doesn’t have to be long or complicated. Knowing who to contact when things go sideways can make a significant difference when they do.

More News

Articles

MxD Expands Casting & Forging Modernization Efforts With $2.4 Million in U.S. Department of War Awards

Read More
Webinars

MxD Cyber Webinar: AI Is Changing Cybersecurity, but the Fundamentals Still Matter

Read More
Articles

MxD Awarded $67 Million from U.S. Department of War to Advance Ongoing Modernization of the Organic Industrial Base

Read More