• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » What the SolarWinds Hack Tells Us About IoT and Supply-Chain Security

Think Tank
Think Tank RSS FeedRSS

What the SolarWinds Hack Tells Us About IoT and Supply-Chain Security

cyber data
Photo: Bloomberg
March 14, 2021
Matt Wyckhouse, SCB Contributor

No matter the industry, cybersecurity breaches seem to be escalating in size and scale. 

The sprawling hacking campaign launched by Russia three months ago — which impacted as many as 18,000 customers of the Texas-based software maker SolarWinds Corp. — is an egregious example of the far reach of a potential supply-chain attack.

The term “supply-chain risk” is a large umbrella that covers lots of security threats and vulnerabilities. In the SolarWinds case, the threat actors, believed to be working on behalf of a foreign government, trojanized the software updates to a popular tool SolarWinds Orion. The attack left potential backdoor access points to hundreds of companies and nine federal agencies. And that’s only what we know — we will likely be uncovering the effects of this breach for years to come.

Other supply-chain risks may manifest as security flaws baked into electronic devices. Manufacturers of smartphones, printers, routers, internet-of-things devices and critical infrastructure systems buy components from third parties. These components are shipped with embedded firmware that may have existing security flaws. What’s more, some of that firmware wasn’t written by the manufacturer, but comes from open-source code maintained by volunteers in the I.T. community.

Here’s what the broader supply-chain industry needs to know about cyberattacks.

Veiled Software

There’s a growing movement of purchasers that are demanding comprehensive lists of the software within a device — but for now, it’s rare for manufacturers to provide it. That list, known as a software bill of material (SBOM) is key to supply-chain security, but it’s important to note that it’s not a cure-all. For example, an SBOM would not have caught the SolarWinds backdoor. What was needed was for a security team member to analyze the final software files themselves, before it was released to customers.

A Back Seat

Software developers and device manufacturers have shifted to rapid development processes. On the software side, this agile development framework pushes numerous and rapid updates, sometimes to add new features, occasionally to fix security flaws. There’s a similar push on the device side of the equation — and this is especially true for IoT devices sold as commodity products in bulk. 

In either case, security often ends up taking a back seat. It’s up to an organization’s leadership to recognize the risk of not prioritizing security, and it's up to development teams to be proactive in mitigating those risks before they can be exploited. The reality is, attackers are well ahead of the industry. That has put organizations in a reactive posture and given rise to numerous regulations and standards. It’s more important than ever for companies, manufacturers and buyers alike, to take a proactive approach.  

Potential for Access 

Global supply chains have become particularly attractive targets due to their largely connected and often poorly secured systems. It's common practice to duplicate software in more than one device — meaning if a hacker finds a vulnerability in a doorbell camera, it might also be possible to exploit another brand of doorbell, a smart TV, a connected refrigerator or a home thermostat. 

For hackers, a vulnerability that affects a single device is insignificant, because it is hard to monetize those types of hacks, but pervasive supply-chain vulnerabilities can be much more valuable. For supply-chain executives, it’s important to think of all the devices in your business that could enable pivots to other systems.

The SolarWinds breach was a wake up call for many within the cybersecurity community and outside of it. For others, it was a confirmation of what we already knew, and what we have been working so hard to prevent. 

The most important takeaway from this attack is that we need to reevaluate the trust we put into vendors, software and devices. Regardless of where you are in the supply chain, from an enterprise user of software to an OEM to a software supplier, you likely are placing an incredible amount of trust in your vendors and their products. We need to rethink how we assess those trust relationships, and most importantly, we need to understand how we can verify the security of this software, firmware and hardware throughout the entire lifecycle.

Matt Wyckhouse is founder and CEO of Finite State.

Technology Cloud & On-Demand Systems Data Management (Big Data/IoT/Blockchain) Business Strategy Alignment Global Supply Chain Management Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • Businessman using AI agent system on laptop computer.

    AI in Supply Chain Can’t Succeed Without Foundational Systems

    Artificial Intelligence
  • A LARGE CYLINDRICAL OBJECT SHRINK-WRAPPED IN WHITE PLASTIC IS LOWERED BY CRANE ONTO A FLAT BED TRUCK ON A DOCK

    AI Boom Has European Buyers Paying Extra to Secure Gas Turbines

    Technology
  • DOMINO EFFECT FINANCIAL MONEY KNOCK-ON CONSEQUENCES iStock-Devrimb-1500012566.jpg

    Podcast | The Tariff Conundrum for Supply Chains: Pass Along, or Absorb?

    Supply Chain Finance & Revenue Management
  • 016_ai_and_data_transformation_in_distribution_v1-(540p).png

    Watch: AI and Data Transformation in Distribution

    Artificial Intelligence
  • A banknote of Chinese yuan is rolled up sitting on the map of South America

    A Question of Strategic Defense: The China Challenge in Latin America

    Regulation & Compliance

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing