• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Protecting the Paths to an Organization’s Data

Think Tank
Think Tank RSS FeedRSS

Protecting the Paths to an Organization’s Data

Data Management
September 3, 2021
Peter Klimek, SCB Contributor

Across the globe, businesses of all sizes and across all industries are undergoing some form of I.T. transformation. In fact, companies have accelerated the digitization of their internal and external business operations by three to four years since a pandemic upended the world. While COVID-19 can be considered a major accelerant for this change, organizational leaders are also recognizing the strategic importance of embedding technology throughout their businesses.

For many, transformation will be driven by the adoption of third-party commercial off-the-shelf software deployed in-house, software-as-a-service (SaaS) applications that host sensitive data, and open-source third-party libraries that are used to build software. While the introduction of modern technology is a sign of needed progress, businesses shouldn’t overlook the potential security risks that come with all of this innovation. The preponderance of software supply chains will expose unsuspecting businesses in new and complex ways, pushing the boundaries of traditional security defenses.

Vulnerable software supply chains have even caught the attention of the U.S. government, confirming the urgency of this growing cybersecurity risk. In May, government leaders took the first step toward proactively addressing the potential threats lurking in a growing ecosystem of third-party dependencies. Executive Order 14028 outlines a plan calling for the government “to make bold changes and significant investments in order to defend the vital institutions that underpin the American way of life.” The E.O. puts particular emphasis on the security of critical software” which, the government notes, “lacks transparency, sufficient focus on the ability of the software to resist attack, and adequate controls to prevent tampering by malicious actors.”

The National Institute of Standards and Technology (NIST) outlined the security measures for protecting critical software, placing a sharp focus on the defenses that are needed to protect data, not just the systems and network around it. This approach, which focuses on protecting the data and all paths to it, recognizes the intractable problem of third-party software applications and libraries that have direct access to sensitive data. As evidenced in the successful attacks carried out over the past several months, enterprise organizations must account for a vendor’s vendor or third-party software that underpins their applications and interfaces if we’re going to truly mitigate the threat of software supply chain attacks.

A Complex Ecosystem

Historically, companies have focused on the risk introduced by their immediate set of vendors and the critical software they rely on. That posture is no longer sufficient, as I.T. transformation pushes the boundaries of the traditional network and makes legacy controls less effective.

While a business may have the right security controls in place, it doesn’t mean its vendors across the software supply chain do. The security strategy can no longer rely on trusting everything from the ecosystem, even from partners and vendors. The expanding software supply chain, along with the complexity of modern applications, means vulnerabilities will be introduced at a greater velocity. To help address the growing scale of attacks within the software development lifecycle, organizations need to adopt a threat model that includes all parts of the supply chain, including nth-party code.

Modern applications are powered by a complex ecosystem of application programming interfaces (APIs), microservices and serverless functions. With more ephemeral workloads and distributed architectures, there’s no silver bullet for pre-production software analysis. Even in the most rigorous software development lifecycle (SDLC), the complexity of development means vulnerabilities will be introduced. This is again why protecting all paths to the data must be the fundamental strategy for organizations.

Tackling the Issue Head-On

Evidenced by earlier software supply chain attacks, bad actors are stealthily maneuvering within the software supply chain by exploiting the vulnerability in a third-party software connection, using it to move laterally and ultimately gain access to the target’s data.

Web application security must evolve and focus more on identifying run-time application behavior, such as whether third-party code is responsible for unwanted actions. Only by blocking unexpected behaviors can one prevent novel attack behavior. This will be critical as enterprise I.T. evolves into diverse, modern application environments.

Application scanning tools are great, but unlikely to identify compromised third-party software embedded in applications. Perimeter tools can be deceived by seemingly innocuous traffic from applications until the signatures are published. Lastly, while many businesses deploy endpoint security, this technology is often blind to application attacks, as they rarely need to touch user devices in the early stages.

Instead, businesses need to deploy runtime application self-protection (RASP) to detect and prevent attacks in real time and from within an application. This technology, recommended in NIST SP 800-53 Revision 5, can pinpoint attacks down to an exact line of code and automatically stop exploitation of a vulnerability, giving organizations the time needed to patch vulnerabilities on their own schedule.

To enable innovation and maintain a competitive edge, organizations will need to modernize their operations. Much of this transformation will be dependent on third-party applications and services.

However, software and application vulnerabilities are fundamental security issues, and companies need to take note. As such, they should put emphasis on their defenses, particularly the APIs underpinning their digital transformation.

With attackers finding stealthy ways to evade defenses and get access to the underlying data, it’s essential that the right controls are in place and the proper tools are being utilized to truly protect data and all paths to it.

Peter Klimek is director of technology, Office of the CTO, with Imperva.

Technology Data Management (Big Data/IoT/Blockchain) Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • A GROUP OF NINE PEOPLE STAND SMILING IN A ROW IN THE SUNSHINE BENEATH A SIGN SAYING PORT OF LOS ANGELES

    Transportation Secretary Announces American Supply Chain Sovereignty Initiative

    Global Gateways
  • Ebook_TransformingSupplyChain_thumbnail.jpg

    Transforming Your Supply Chain From Cost Center to Growth Driver

    Forecasting & Demand Planning
  • TWO WORKERS DISCUSS DATA SHOWN ON COMPUTER SCREENS

    Gartner: Gap in SC AI Talent Cannot Be Closed by Hiring Alone

    Artificial Intelligence
  • A pair of hands reaches towards a cluster of icons showing global logistics network distribution and transportation

    CSCMP's State of Logistics Report: Get Used to the Fog

    Logistics
  • tankers and container cargo ships clustered in aerial 3D illustration render.

    Ships, Seafarers Stuck in Gulf Face Tough Choices

    Global Gateways

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing