Ukuhlaselwa kwe-Supply chain: Izigebengu ze-Cyber ​​ziqondise abahlinzeki besofthiwe

ISIKWELETU SESITHOMBE:
Isikweletu sezithombe
iStock

Ukuhlaselwa kwe-Supply chain: Izigebengu ze-Cyber ​​ziqondise abahlinzeki besofthiwe

Ukuhlaselwa kwe-Supply chain: Izigebengu ze-Cyber ​​ziqondise abahlinzeki besofthiwe

Umbhalo wesihlokwana
Ukuhlaselwa kwe-Supply chain kusongela izinkampani nabasebenzisi abaqondise futhi baxhaphaze isofthiwe yomthengisi.
    • About the Author:
    • Igama lomlobi
      I-Quantumrun Foresight
    • February 9, 2023

    Ukuhlaselwa kwe-Supply chain kuyinkinga ekhulayo yamabhizinisi nezinhlangano emhlabeni jikelele. Lokhu kuhlasela kwenzeka lapho isigebengu se-inthanethi singena echungechungeni lokunikezela ngempahla lwenkampani futhi silisebenzisela ukufinyelela amasistimu noma idatha yenhlangano eqondiwe. Imiphumela yalokhu kuhlasela ingaba mibi kakhulu, okuhlanganisa ukulahlekelwa kwezimali, ukulinyazwa kwesithunzi senkampani, ukonakala kolwazi olubucayi, nokuphazamiseka kokusebenza. 

    Umongo wokuhlaselwa kwe-Supply chain

    Ukuhlasela kwe-supply chain wukuhlasela kwe-inthanethi okuqondise isofthiwe yomuntu wesithathu, ikakhulukazi leyo ephethe amasistimu noma idatha yenhlangano eqondiwe. Ngokombiko wango-2021 othi “Threat Landscape for Supply Chain Attacks”, amaphesenti angama-66 okuhlaselwa kwe-supply chain ezinyangeni eziyi-12 ezedlule aqondise ikhodi yohlelo lwabahlinzeki, amaphesenti angu-20 edatha eqondiwe, kanye namaphesenti angu-12 aqondise izinqubo zangaphakathi. Uhlelo olungayilungele ikhompuyutha bekuyindlela esetshenziswa kakhulu kulokhu kuhlasela, okubalelwa kumaphesenti angama-62 wezigameko. Nokho, izingxenye ezimbili kwezintathu zokuhlaselwa kwamakhasimende zasebenzisa ithuba lokuthembela kubahlinzeki babo.

    Isibonelo esisodwa sokuhlaselwa kwe-supply chain ukuhlasela kwe-2017 enkampanini yesofthiwe, i-CCleaner. Izigebengu ze-inthanethi zikwazile ukufaka ebucayini uchungechunge lokunikezwa kwesofthiwe yenkampani futhi basabalalisa uhlelo olungayilungele ikhompuyutha ngezibuyekezo zesofthiwe, ezithinte izigidi zabasebenzisi. Lokhu kuhlasela kugqamise ubungozi obungaba khona bokuthembela kubahlinzeki bezinkampani zangaphandle kanye nokubaluleka kwezinyathelo zokuphepha eziqinile zokuvikela kulokhu kuhlasela.

    Ukwethembela okwandayo kubahlinzeki bezinkampani zangaphandle kanye namanethiwekhi ayinkimbinkimbi ochungechunge lokunikezela ngedijithali yiwona obambe iqhaza elikhulu ekukhuleni kobugebengu bochungechunge lokunikezela ngedijithali. Njengoba amabhizinisi ekhipha okwengeziwe ngemisebenzi yawo namasevisi, inani lezindawo ezingaba khona zokungena zabahlaseli liyakhula. Lo mkhuba uphathelene ikakhulukazi uma kuziwa kubahlinzeki abancane noma abavikeleke kancane, njengoba bangase bangabi nalo izinga elifanayo lezinyathelo zokuphepha njengenhlangano enkulu. Esinye isici ukusetshenziswa kwesofthiwe nezinhlelo eziphelelwe yisikhathi noma ezingashicilelwe. Izigebengu ze-inthanethi zivame ukuxhaphaza ubungozi obaziwayo kusofthiwe noma amasistimu ukuze zithole ukufinyelela ochungechungeni lokunikezela ngedijithali lwenkampani. 

    Umthelela ophazamisayo

    Ukuhlaselwa kwe-Supply chain kungaba nomonakalo omkhulu wesikhathi eside. Isibonelo esisezingeni eliphezulu ukuhlasela kwe-inthanethi kwango-December 2020 ku-SolarWinds, ehlinzeka ngesofthiwe yokuphatha i-IT kuma-ejensi kahulumeni namabhizinisi. Izigebengu zisebenzise izibuyekezo zesofthiwe ukusabalalisa uhlelo olungayilungele ikhompuyutha kumakhasimende enkampani, okuhlanganisa nezikhungo eziningi zikahulumeni wase-US. Lokhu kuhlasela kwakubalulekile ngenxa yesilinganiso sokuyekethisa kanye neqiniso lokuthi akuzange kubonwe izinyanga ezimbalwa.

    Umonakalo uba mubi nakakhulu uma inkampani eqondiwe ihlinzeka ngezinsizakalo ezibalulekile. Esinye isibonelo sasingoMeyi 2021, lapho inkampani yokudla emhlabeni wonke i-JBS ihlaselwa ukuhlasela kwe-ransomware okwaphazamisa ukusebenza kwayo emazweni amaningi, okuhlanganisa i-US, Canada, ne-Australia. Lokhu kuhlasela kwenziwe yiqembu lezigebengu elaziwa nge-REvil, elasebenzisa ubungozi besoftware yenkampani yangaphandle. Lesi sigameko sithinte namakhasimende akwa-JBS, okuhlanganisa izindawo zokupakisha inyama nezitolo zokudla. Lezi zinkampani zibhekane nokushoda kwemikhiqizo yenyama futhi kwadingeka zithole enye imithombo noma zilungise ukusebenza kwazo.

    Ukuvikela ekuhlaselweni kwe-digital supply chain, kubalulekile ukuthi amabhizinisi abe nezinyathelo zokuphepha eziqinile nezivumelana nezimo. Lezi zinyathelo zihlanganisa ukucophelela okuphelele kubahlinzeki bezinkampani zangaphandle, ukuvuselela njalo nokunamathisela isofthiwe nezinhlelo, nokusebenzisa izinqubomgomo nezinqubo zokuphepha eziqinile. Kubalulekile futhi ukuthi izinkampani zifundise abasebenzi bazo ukuthi bangahlonza futhi bavimbele kanjani ukuhlaselwa okungase kube khona, okuhlanganisa nemizamo yobugebengu bokweba imininingwane ebucayi.

    Imithelela yokuhlaselwa kwe-supply chain 

    Imithelela ebanzi yokuhlaselwa kwe-supply chain ingase ihlanganise:

    • Ukusetshenziswa okuncishisiwe kwesofthiwe yenkampani yangaphandle kanye nokuthembela okukhulu ezisombululweni zangaphakathi zedatha ebucayi, ikakhulukazi phakathi kwezikhungo zikahulumeni.
    • Ukwenyuswa kwesabelomali sezinyathelo ezithuthukiswe ngaphakathi zokuphepha ku-inthanethi, ikakhulukazi phakathi kwezinhlangano ezihlinzeka ngezinsizakalo ezibalulekile njengezinsiza kanye nezokuxhumana.
    • Ukwanda kwezigameko zabasebenzi ababa yizisulu zokuhlaselwa kobugebengu bokweba imininingwane ebucayi noma ukwethulwa kohlelo olungayilungele ikhompuyutha bengahlosile ezinhlelweni zezinkampani zabo.
    • Ukuhlasela kwezinsuku eziyize kuba yinsakavukela umchilo wesidwaba njengoba izigebengu ze-inthanethi zisizakala ngabathuthukisi be-software abenza izibuyekezo ezivamile, ezingaba nezimbungulu eziningi lezi zigebengu ezingazisebenzisa.
    • Ukusetshenziswa okwandayo kwezigebengu ze-ethics eziqashelwe ukucinga ubungozi ezinqubweni zokuthuthukisa isofthiwe.
    • Ohulumeni abengeziwe abaphasisa imithetho edinga ukuthi abathengisi bahlinzeke ngohlu olugcwele lwabahlinzeki babo bezinkampani zangaphandle, kanye nokucwaninga okungase kube khona kwezinqubo zokuthuthukisa isofthiwe.

    Imibuzo ongaphawula ngayo

    • Zingaki izinhlelo zokusebenza zezinkampani zangaphandle othembele kuzo ngebhizinisi lansuku zonke, futhi kungakanani ukufinyelela okuvumelayo?
    • Singakanani isibambiso okholwa ukuthi sanele abathengisi bezinkampani zangaphandle?
    • Ingabe uhulumeni kufanele angenelele ukuze aphoqelele izindinganiso zokulawula kubathengisi bezinkampani zangaphandle?

    Izinkomba zokuqonda

    Izixhumanisi ezilandelayo ezidumile nezikhungo zibhekiselwe kulo mbono: