all things cyber episode

4

The hidden connections putting your business at risk

Why vendor scores don't show your real exposure, and what Digital Proximity changes.

Stephane Konarkowski

What do we talk about?

Robin de Vries

We talk about how TPRM is broken. Well, it's the risk scoring that's broken. It's not just about an attack or something.

Stephane Konarkowski

Welcome to the fourth episode of All Things Cyber. So, Robin, first time on the podcast. How do you feel today?

Robin de Vries

Yeah, I'm good, actually. We've got a good new setup today. It’s different, but you remain the same. We've got an anchorman, so that's good.

Stephane Konarkowski

So today we're in Amsterdam. Just to change things up a little: the first episode was in Portugal, the second in London, and today Amsterdam, not too bad, at the headquarters of ThingsRecon.

Robin de Vries

Oh, nice, my hometown.

Stephane Konarkowski

So today, the buzzword: supply chain. What do you think about supply chain today? How’s it being tackled by companies? We've been talking to a lot of companies recently about supply chain, or what they consider supply chain. What do you think the main takeaway is here?

Robin de Vries

What's interesting, and I've been in IT for a long time, is that with how supply chain is developing now, and how everything is connected, it's quite difficult to look at companies as single companies. Everything is connected. It's a balance between being pragmatic and connecting everything, but also asking what risk you're bringing in-house, and whether you have visibility of it. Companies struggle with that, because they connect everything and it's so easy. With Zapier and Make you can connect anything, even services you don't host in-house. But at the same time: how are you connected? I don't know what you've seen with companies doing that. Is it becoming a Wild West?

Stephane Konarkowski

I think so. Everyone wants to be integrated, share data, use platforms left and right, connect through APIs, so everything's really connected. The major problem is understanding how you're connected, what data you're sharing, and where your data is. Before, your data was sitting inside your organization; today it travels from your organization to the supplier. But does it stay there? Is it moving somewhere else? Is anything else involved? That whole supply chain has become bigger and bigger, because everyone is connected.

Robin de Vries

Yeah. So, like I said, at some point you end up eating your own tail. It comes back to you. It bites you.

Stephane Konarkowski

From a supply chain perspective, it's very much about understanding how your organization is digitally connected to your suppliers; those are the paths we look at to understand what risk you're bringing in by connecting or configuring things a certain way. So there's a whole new world out there that isn't yours, it's someone else's, but it's now part of your organization. It's an extended attack surface. But how do you think attackers look at that? They love it.

Robin de Vries

Of course, there are the obvious targets, attacking Microsoft. But is that the way to go? They're looking at a completely different path.  

Stephane Konarkowski

What's the point of attacking Microsoft directly? There isn't one. You go for the little one out there that's connected to a bigger organization and has weaknesses, where the security posture maybe isn't at the same level, because that gives them access potentially to the first door, then the second door, then the third door.

Robin de Vries

You're right. We're both doing so many POCs with customers that have thousands of suppliers, and in the top five there's always Cloudflare, AWS, Microsoft, the obvious ones. So is the risk in being connected to those suppliers, or is it somewhere else?

Stephane Konarkowski

It's a different risk. What we've seen recently was more operational. Cloudflare: something goes down, and then half the internet is down; no one can work. I think that was the worst day in terms of production for organizations, because they couldn't do anything. But supply chain isn't just about an attack, it could be someone disconnecting a cable from a server, and suddenly, boom, blackout.

Yeah, so it's more operational. But how does it affect the blast radius? If something happens, how does it affect you? How does it affect your suppliers? How could your suppliers affect someone else, and so on. It's really a chain of what's going to happen.

And you've seen it many times in recent months: an airport goes down because of some luggage system, or a patch somewhere causes a problem. And potentially someone uses a supplier to get in and take the crown jewels. So it's a very widespread set of techniques... or not techniques, but ways to disturb the cyber hygiene. It's really interesting.

Robin de Vries

And if you talk about critical national infrastructure, two weeks ago I was in Albania, we're going to help them with their critical national infrastructure. We come into organizations that have no idea yet how they're connected. They have a high-level idea, but if you really ask them about the connections, and which services they're connected to, most of them are blank. They're going to have to fill in the gaps.

Stephane Konarkowski

Yeah. If you go and ask any organization, “Do you know who your suppliers are?” They might have a list somewhere. But do you know about all your suppliers? The ones that matter most are the digitally connected ones. And we've seen that when you were showing organizations results recently: “look, this is what we're seeing from the outside, in terms of which vendors you're working with”. They were surprised.  

Robin de Vries

But how do you prioritize them nowadays, which vendors do you need to send questionnaires to? What's the priority?

Stephane Konarkowski

I think it has to be a combination. Is it a critical supplier for the organization, for various reasons? But from our side, what we look at is how they're connected to you: that's the digital proximity we talk about. It lets us understand the context of how you're using them, and how you could prioritize suppliers based on that context. Some suppliers will be much closer to your organization, because you're using a lot of their tools or services. Others you might use for just one service, but that could be a very critical service.  

So it's about how you use them, and how you know which of your suppliers are critical and which aren't. We look at the depth of connectivity that exists between you and them, and we base it on that proximity to help the organization understand what the biggest impact would be if one of the suppliers got hacked.  

Robin de Vries  

But if you look at digital proximity is more than just a risk rating on how they're integrated. In the end, you want to constantly look into that ecosystem and have a dynamic view of what's happening.

Stephane Konarkowski

Yeah. Because you were telling me just before that today's supply chain is broken.

Robin de Vries

I think TPRM is broken. The supply chain itself isn't broken, but TPRM is. We talk to a lot of organizations still struggling with questionnaires and Excel files, and also with regulatory challenges like NIS2 and DORA. What we see is that organizations are still quite immature. There's a lot of human energy and workload involved in getting those questionnaires out, understanding how you work with a supplier and how you're connected, and then getting the information back, which is often accepted on trust, and often driven by legal and insurance purposes.  

If I have good control over my supply chain and third parties, I might get a better premium on my insurance. But that's not where the risk lies, in my opinion. The risk lies in what's happening today: Cloudflare goes down, and I want to know how I'm impacted. If there's an outage of AWS in the US East region, suddenly half the world can't use any payment providers. So how am I impacted as a business? I'm not going back to those Excel or ServiceNow questionnaires to figure out how I'm impacted. I think that's an important shift we're making here. You constantly want to know how you're connected, and how you're working with them.

One of our customers is a chemical company, and one of their favorite suppliers to work with in terms of people, culture, and how involved they are with our customer, turned out, when we ran an analysis, to have one of the highest risk ratings in their whole supply chain. Quite shocking for them, and an eye-opener at the same time.  

Stephane Konarkowski

How are they going to go to that supplier and say, “Hey, you need to fix this”?  

Robin de Vries

At least you can have a conversation, once you know it. But it doesn't come from a questionnaire.

Stephane Konarkowski

That's the thing. A questionnaire is very static. You probably do it once a year, because, to be honest, it's quite boring. You need to continuously check that kind of stuff, from the outside, because suppliers change, just as your surface changes, they change theirs. One little mistake, and there you go. So it's about moving toward continuous monitoring of your suppliers, while understanding how they're connected, so you know what the impact will be. That's the most important thing here.

In terms of supply chain again, do you think the supply chain is just “a vendor over there,” or is there more to it? Where does it start? I think you shift left a little.

Robin de Vries

Look at what happened with — I can't even pronounce the name — the Shai-Hulud thing, with the npm packages.

Stephane Konarkowski

Yeah, that one.  

Robin de Vries

They could've picked an easier name. But anyway, it was this week: the npm packages, another one, and a big one. And then you see that it doesn't start with your suppliers; it already starts in the code. If you're coding and using all those dependencies, then suddenly within, I think, half an hour, all the npm packages were infected, or at least new infected packages were created. It starts at coding, and then you go from code, to cloud, to your supply chain. But it's all one.

Stephane Konarkowski

It's all connected. And the packages thing is funny, because you were talking about it on Monday, and I went and looked at GitHub to see what was happening there. It was just fake accounts being created, JSON files with some hash stuff in them. Every two minutes something new was coming in. It's like, wow, OK, definitely something's working in there. But the impact: how do you know if you're using those packages? And it's already in production, so that's interesting in terms of monitoring. So supply chain isn't just your vendor, like you said. It starts at the code and moves from left to right.  

So, where do you think supply chain is going now, in terms of cyber? Where are we heading, and what do we need to do better?

Robin de Vries

Well, where we're going is that we'll be more connected than ever. It started years ago with OT, and with cameras. Everything's got a camera in it now; there are too many cameras here. We want to connect everything, even our watches. So it's going to increase steeply, the number of things we want to connect, and also need to control. But you need to be supported by tools, solutions, and people around you who can help you prioritize. Because if you log onto a platform and see 10,000 high-priority risks, then nothing is a priority anymore. The first analysis of your ecosystem is a snapshot, but then it's dynamic, changing every day; a risk today can be a different risk tomorrow.

So the whole point is remediation, working with your suppliers. My father always said, “Stay close with your suppliers, because one day you'll need them.” And that's true. It's not just any analysis you run on your third or fourth parties; it's about becoming stronger together, working together and making sure that together you're more secure. But at the same time, you depend on each other more. Even in our internal processes we try to automate as much as possible, and internally, if you look at how many applications you're connected to, meaning how many third parties, and how you depend on them… We're buying tools almost every week.  

In the end, I think you'll end up in ecosystems, like Apple, Google, or Microsoft: you choose an ecosystem, and then hopefully within it you understand how you're connected. But large organizations, if you ask them how many suppliers they're connected to, often can't answer that question. And which suppliers do you need to dig deeper on to understand how you're connected, and what you're using them for? I think they can't answer that either.  

Stephane Konarkowski

No, that's one of the big issues. The other issue — talking to practitioners — is this: when you have a supplier and there's a risk, how do you communicate that to the supplier? How do you make sure they fix it?  

Most of the time, you as the organization have much better security knowledge than they do, hopefully. But how do you go to a supplier and say, “Look, you need to fix that”? Certain suppliers, I can imagine you can apply some pressure. But others won't budge. So what do you do? How do you work with your suppliers to make sure that what you're doing helps your organization, but at the same time helps them too?

So I think that level of communication, of how you communicate with your suppliers, is something that maybe needs to change a little. We were talking about those questionnaires: now imagine you're the supplier and you receive a questionnaire of a hundred-something questions. Do you really want to fill that in?  

Robin de Vries

There are tools out there that help you fill it in, AI is being used more and more there, but it's still a static snapshot of a company.  

Stephane Konarkowski

Yerah, same problem. Still, it's an interesting conversation: trying to figure out how you protect yourself and, at the same time, make all of this better, which I think is a good thing. And I think the larger organizations should lead with that. You're not going to ask a smaller supplier to lead this. In terms of knowledge, practices, and how you do your security, that's something you could shift right, to the supplier, to help them get better. If you do better with a supplier, you're not just helping yourself, you're also helping other organizations that use the same supplier. It's quite cool.

Robin de Vries

If you look at Gartner, when you founded the company, ThingsRecon was very much focused on the external attack surface, the “360 view,” as we call it now. What do you see? We've been looking into all the supplier connections. Are we still able to look only at ourselves first, and then at our third parties? Or is it all just blending in? How have you seen that change?

Stephane Konarkowski

It's completely blended. If you don't do it, you're basically exposing yourself to a lot of things. We've seen that on many occasions, even when you use a supplier with good security, and you have good security yourself, just one mistake, one misconfiguration somewhere, could expose a big amount of data. But that's not on the supplier. It's more about how you train your people not to make those mistakes, because these are human mistakes.

Robin de Vries

Do you have an example of that, something you've seen recently?

Stephane Konarkowski

Well, recently there was just a configuration of an item on the supplier side in a SaaS platform, misconfigured, that exposed the whole list of customers of that specific organization. But that's not on the supplier; that lens is within your organization, because you're responsible for how you configure your supplier. So it's interesting: it could be the supplier, it could be you, but it could also be that thing between you and the supplier.

So, resilience. We talk about resilience a lot in supply chain. I think the shift needs to be around how you protect yourself based on those connections. When you have a connection with a supplier, that's your resilience; if something breaks there, it could be on your side or on the supplier's side, so you need to look at both angles. And that's the interesting part: when you look at a supplier in general, you can say, “Look at those guys, they're doing pretty well on security.” But what about the specific thing you're connected to within that supplier?  

Take risk scoring, or risk rating: it'll say that supplier is an A. But the thing you're actually connected to is an F. So how do you handle that?  

Robin de Vries

We say TPRM is broken, but the risk scoring is broken too.  

Stephane Konarkowski

Again, it's that general view of a supplier. But what about you and the supplier — that relationship, that partnership, that integration? That needs to be looked at as well, because it's potentially a much bigger risk, the closest risk to you. Let's take a really good example. Say you have a supplier, and you learn that supplier got hacked, and you're using them. First, imagine you're the CISO of the organization. Where do you go first? Who do you talk to first?

Robin de Vries

Procurement?  

Stephane Konarkowski

Potentially, yeah. Maybe GRC teams, if you have them. Procurement, legal. They'll say, “We have a contract with them. Do we work with them? Where do we work with them? Which people in our organization work with them?” There are a lot of questions to answer before you even get to the facts about how this impacts you.  

So that's a really interesting thing. You're basically creating CMDBs of your suppliers. And we love CMDBs. A CMDB of a supplier: do you have enough data today about that supplier to understand the impact it'll have on your organization? Beyond just “yeah, it got hacked”.  

Robin de Vries

No, you need to know how you're connected.  

Stephane Konarkowski

That's the first thing I'd look at.  

Robin de Vries

Of course, if a company got hacked because of email risk, a bad email score, but I don't use them for email, then I shouldn't care. But if I use their applications or software, I want to look at the software risk.

Stephane Konarkowski

Yeah, I mean, there are always two angles to it. Of course. And that's completely true, you need to have a mix. In terms of, say, a ransomware attack on your computer, where you go, “oh, ****, what do I do?” Well, you disconnect the cable. That's the first thing you do.  

So here it's, “OK, we'll disconnect the supplier.” But where? That's the thing. Maybe he's not even connected to you. Or maybe he's not connected, but he's got some data about you. So you need to understand what the supplier has, and what kind of data they use, store, or play with. This is a really interesting subject. But anyway, we could talk about it all day.

Robin de Vries

Are we going to crack the code? No, maybe it's good. We're coming to the end of 2025, and I think supply chain has become a real hot topic. What do you think is next on the agenda for 2026? What's going to make the headlines?

Stephane Konarkowski

A big exposure in AI, that could be very interesting. ChatGPT, or other AI platforms, leaking information: that would be quite interesting. They haven't been in the news yet, but development there is going crazy. Obviously a lot is being built with AI, and everyone's using it. I'm not giving any hints to anyone, but you might want to look at those. So I think it's going to be a very big subject next year, and unfortunately we're going to see a lot of other problems around supply chain.

Robin de Vries

Are we ready for it? The knock-on effect is already huge. If you look back at Jaguar Land Rover, that was, I think, one and a half billion in knock-on effect, at least. Are we ready? Are companies resilient enough?

Stephane Konarkowski

I'd love to say yes, but we're not. We need to go faster in how we do things, to support our organizations and, I'll say it again, the suppliers in other organizations, to make it safer, but also more resilient. Because, like I said from the beginning, it's not just about the attack; it could be anything, a cable unplugged, and that's it. So it's going to get even bigger next year.

Robin de Vries

I think of our role in that: we work with partners, and the partners work with the customers. I hope the supply chain is well connected to tackle these problems, because I think it's very necessary that we understand that, and that we work together to fix it.

Stephane Konarkowski

I really like the last word: togetherness. Well, Robin, it was great to have you today on the podcast. I think it's your first one, and you did well. Well done. And, as always, thank you for listening. We'll see you next time, in whatever location you want to join us for the next podcast.

Robin de Vries

Yeah. We need some guests!

Stephane Konarkowski

And, surprise, we'll probably do it in another country. So who knows! But yeah, thank you very much. See you later, alligator.

Thank you! You are now susbribed to The Recon Log
Oops! Something went wrong while submitting the form.