Blog Risk management

Supply chain attacks: How to protect yourself from cyber threats via suppliers

Attackers have long realised that breaching a well-protected large company is difficult. Instead, they compromise its software supplier, IT service provider or outsourcing partner. Supply chain attacks are now one of the most dangerous and hardest-to-detect threats.

5 January 2026 · 10 minutes reading · Risk management

Imagine your company investing millions in firewalls, EDR, SIEM and security training. Then an attacker gains access via the IT management software you use, software to which you inherently had to grant administrative rights over the entire infrastructure. This is precisely how the 2020 SolarWinds attack worked, affecting over 18 000 organisations including US government agencies.

Supply chain attacks are insidious precisely because they exploit trust. The attacker does not need to breach your defences; they pass through the gates you opened yourself for a legitimate supplier.

Anatomy of a supply chain attack: How they work

A supply chain attack is the compromise of software, hardware or a service that is subsequently used to attack the supplier's customers. There are several basic patterns:

Compromise of the software update mechanism (SolarWinds)

The Russian APT29 group (Cozy Bear) infiltrated the SolarWinds build pipeline and inserted malware (the Sunburst backdoor) directly into a legitimate update for the Orion platform. Customers who automatically applied the updates, as recommended, inadvertently installed the backdoor. The malware remained undetected in systems for months, giving attackers unrestricted access to the victims' critical infrastructure.

Key finding: the update's digital signature was valid because the malware was inserted before signing. Traditional security checks failed to detect it.

Intentional sabotage of an open-source project (XZ Utils 2024)

The XZ Utils case from 2024 revealed another dimension of the threat. An attacker (operating under the pseudonym JiaT75) spent nearly two years systematically building trust within the open-source project community for XZ Utils: a compression library present in practically every Linux distribution. They then deliberately inserted an obfuscated backdoor into the release version, which would have enabled unauthorised SSH access to systems running installed versions 5.6.0 or 5.6.1. The attack was discovered by chance just before mass deployment into distributions.

Compromise of open-source packages (typosquatting, dependency confusion)

Less sophisticated but very widespread attacks target npm, PyPI and other package registries. Attackers upload a package with a similar name (typosquatting: requests location requests) or exploit dependency confusion by uploading a public package with the same name as the company's internal private package but with a higher version number.

Third parties as an attack vector: What threatens you

It is not just about software. Supply chain risks come from many directions:

NIS2 and supply chain security

The NIS2 Directive explicitly addresses supply chain risks in Article 21. Obligated entities must implement security measures including security of the supply chain and third-party relationships. This is not a recommendation. It is a legal obligation.

Specifically, this means:

Failure to meet these requirements may result in fines of up to 10 million EUR or 2% of global turnover, with liability that cannot be delegated to suppliers. It is your risk.

How to assess a supplier: A practical guide

Supplier categorisation by criticality

Not all suppliers carry the same level of risk. Start with classification:

Security due diligence

For Tier 1 and Tier 2 suppliers, carry out:

Contractual safety requirements

Every contract with a critical supplier should include:

Technical measures for protection against supply chain attacks

Contractual and procedural measures are not enough. You also need technical safeguards:

Compiling a comprehensive third-party security management programme is a complex project. SecureOn.cz assists organisations with supplier inventory, their assessment and the implementation of contractual and technical measures in compliance with NIS2.

Conclusion: Security is only as strong as its weakest link.

Supply chain security is not an extra. It is a basic requirement for managing the modern threat landscape. Attackers are pragmatic: they strike where resistance is lowest. If your direct suppliers do not have an adequate security level, they become your weakest link.

Start with what is feasible: map critical dependencies, request security certifications from key suppliers, and incorporate basic requirements into new contracts. Gradually build a comprehensive programme. NIS2 provides both the obligation and the framework to do so.

Do you need advice on cybersecurity?

Our experts are ready to assess your situation. The first consultation is free of charge.

Get a free consultation