Are you inadvertently the "weak link" in your biggest client's security chain?
There is an increasing risk that smaller SMEs are being targeted not for their own assets, but as a gateway to access larger supply chain companies. While big corporations often have enterprise-grade security, their smaller suppliers, who feed into their systems, often have a more relaxed approach to cybersecurity.
In this video, Simon Batchelar is joined by business strategist Paul Everington from Everwell Associates to discuss why hackers are turning their attention to the supply chain and what you can do to protect your business.
Why hackers are targeting SMEs
Hackers are becoming increasingly sophisticated. Rather than attacking a major corporation like Jaguar Land Rover directly, they identify the thousands of smaller suppliers that feed into that ecosystem. By compromising an SME, often through something as simple as a dormant employee login or a socially engineered email, they can gain a foothold into the larger, more lucrative target.
Key takeaways from our discussion:
-
The "Back Door" Route
How hackers use neglected accounts and simple malware to bypass the heavy security of prime contractors. -
Financial Liability
We discuss the financial reality: if a major client is hacked through your system and lacks insurance coverage, their legal team may come after you to recover the losses. -
The Value of Your Data
Why seemingly innocuous data, such as blueprints, drawings, or software files, allows criminals to reverse-engineer a larger client's security systems. -
The "We Aren’t Connected" Myth
Paul explains why you are still a risk even if you don't have a direct software link to your client, simply sending an invoice or a spreadsheet can be enough to cause an infection. -
Planning for the Worst
Why you need a "Resilience Plan" (not just a risk assessment) to ensure you know exactly what to say and do when things go wrong.
If you are concerned about where your business sits in the supply chain risk sequence, or want to start mapping out your resilience plan, please do get in touch.
Being seen as a credible, resilient supplier is also something you need to communicate. Our 3-step marketing process helps you make that credibility visible to the Tier 1 buyers vetting their supply chain. You can see this in our defence supply chain work, where we communicate exactly the resilience and assurance these buyers look for.
Read the video transcript
Simon Batchelar: Hello everybody and welcome to this video where we are gonna be talking about the risk of being hacked or compromised as a means to get to your supply chain at large. So what does this mean? Well, there's an increasing risk that smaller SMEs are being seen as a way to get access to the larger supply chain companies. So if your business does work for one of the big, big supply chains in the uk, then the SMEs are actually the weaker link in the chain because often these big companies have enterprise grade security in place, and then they have SME clients who feed into that system who let's say have maybe a slightly more relaxed approach to their cybersecurity and could be a much easier target for cybersecurity hacking and all these different things that come with that.
So before we get into the details of that my name is Simon Bachelar. I'm a marketing strategy consultant from Pallant Studio, and we work with engineering, manufacturing, and IT companies to help them generate more leads to help them open up their pipeline and connect with people outside of their network. I'm joined today by Paul. So Paul, do you wanna give us a quick intro?
Paul Everington: Hi. Yeah, Paul Everington from Everwell Associates. We work in the same sort of areas that you do, Simon, advising them on their business strategies, systems improving efficiency, but particularly looking at cyber and risk assessments and business resilience. What happens when things go wrong? What planning have you got in place?
Simon Batchelar: So me and Paul have been talking recently about two very high profile cases. Here in the UK, one of which is JLR or Jaguar Land Rover, and the other of which is co-op. There's also a third one, which is M&S, which is another food brand. And what these all have in common is that they have been supply chain hacks. So that is to say that JLR wasn't necessarily hacked because someone managed to get into JLR directly. What they did manage to do was use an SME whose cybersecurity wasn't up to the standard of JLR to get in and then gain access into the Jaguar Land Rover system that way. So this means that hackers are being very, very clever because what they're doing is they're looking at these big companies and then trying to work out, well actually these companies, so for example, Jaguar Land Rover has two and a half thousand suppliers just in the UK.
So that means there's potentially two and a half thousand ways in to their IT system. So as good as Jaguar Land Rover's IT system may be internally where that control starts to sort of loosen or goes beyond the scope of what JLR can do directly is when you get into that SME level supplier. So essentially what's happening here is it is where you have a team of maybe 50 to a hundred people and those people all have a login to their computer and then maybe someone leaves one of those companies and that login isn't deleted. It's sort of left lingering on the server. And then a clever hacker works out that actually there is this email address that is, no one's really paying attention to this because that person's left the company.
So what they do is they gain access to that account because it's fairly easy to guess or their password is available, let's say on maybe the dark web. And then they get into that company, they gain access to the local system and realise that actually that user still had admin access to the connection that went straight in to the back door to a company that has recently been hacked. I'm sure you can all join the dots between what I'm saying there.
So basically, even if you are sitting there thinking, well, I don't have much on my hard drive, that could be of any use, it might not be your system thereafter at all. Now, for example, JLR.
For one reason or another didn't have any cyber insurance, which means they're on the hook for about 3 billion quid.
Now the problem with that is that they don't have 3 billion quid in order to pay out. So you can guess where they're gonna be going next. They'll have a legal team who are saddling up right now to ride down to whatever the SME was, to talk to them about how good their cyber insurance is. 'cause you can be absolutely sure they are gonna start recovering some of this money from the people who let it happen. So that's the kind of big scary, oh my god, we work for this big supplier. I'm not entirely sure whether we've got cyber insurance. I don't know if we're using a password manager. Ah, definitely is time to start having a think about all this stuff.
You might also be sitting there thinking, well, hang on Simon, this all sounds big and scary. But we don't have a connection straight into the back door of our biggest supplier. We just make a product for them. We just deliver a service for them. They're just a client in our accounting software. What could a hacker possibly want from us? So Paul, what could a hacker possibly want from an SME if they don't have that direct access in through like a software means.
Paul Everington: That is the most common explanation we get from people. No, we're not directly connected to them. What's the problem? Well, you are exchanging information with them. They are sending you some drawings. You're sending them a spreadsheet. So just sending a simple email could actually cause an infection.
Simon Batchelar: Just thinking about that data. 'cause what you described there is sort of using a sort of social engineering hack. So saying person from SME company is emailing the company, the bigger company and inadvertently putting some malware into it. So that would be a really good way of getting in and kind of infecting that bigger company through a trusted contact. The other thing that can happen is that actually the data that is within your business, so that could be drawings, it could be software that you are loading onto a product that you are delivering. It could be the blueprints to a building that you are making or part of the construction of.
All of that data might seem quite innocuous on its own, but remember if these hackers are going after maybe 50 to a hundred of these thousands of suppliers. They can start to build up a really in depth picture of the product or service that that end company is providing. So for example, you could have details on the security systems where the, you know, entry systems are, where the gates are gonna be, what spec those gates are, who's making the gate entry system. If you are trying to plan something or trying to do something nefarious, having all of that knowledge at hand is great. And actually it's gonna be really hard to get that from the end supplier.
But if you know, for example, well this company make the alarm and I can get the zip file which has the software on it that the alarm's made of, then you can reverse engineer that and that wouldn't be too hard to do. If you are going after an SME that doesn't even need a password manager, why would you bother trying to hack the end client when actually the people who are guardians of that knowledge, shall we say, who are supposed to be looking after it, aren't really paying attention?
Paul Everington: I think that's an excellent point, not just to link to cyber. There's, there's a, a temptation to go, oh, well it's all about cyber, it's all about email and so on. But someone who is making the sandwiches. For, you know, the big prime contractor, let's say you think, oh, where's the cyber risk? There?
Will be sending an invoice. There will be some other connection. So it's tempting for the SME, particularly the smaller ones in that group to think, well, you know, it's, it's not really a problem, but any one of those could be compromised and, and the hackers really are not daft. They will be tracking all of this sort of thing and say, yes, okay we may not directly attack the IT, let's do it by a different route, a more simple route.
Simon Batchelar: So I think there is that to consider. There is this sort of, your business is potentially the weakest link in the chain. Now. There's a couple of things you can do straight off the bat and what I would recommend is if you're not sure where you stand is to speak to whoever's looking after your IT, that's probably the easiest, simplest person to call straight away and say, this is what I'm concerned about. How can you help? And they should be able to quite quickly advise you on what they can do. If it's something that they don't really help with, then there are IT firms out there who can help. But at the very least do watch the other video that me and Paul made to kind of get some sort of base level tips on how you can sort of increase that cybersecurity protection for your business without it costing a lot of money or taking up too much time.
Paul Everington: I think the other thing I'd say is, is make a plan. People get confused by the phrase risk assessment. I mean, we make this assessment every day when we cross the road. A risk assessment is very, very straightforward. If nothing else, you take away from this, this video today, what is my risk? Actually, I am interfacing with a big prime contractor. What is the risk? Just give it five minutes and go, how could this happen? And then write a plan. Okay, simple plan that says, okay, what would I do in these circumstances? But actually there's a, a report on the BBC today talking about, okay, you've got companies who do really good plans, you know resilience plans against, you know, whether it's fire or, or cyber incidents or whatever.
And those plans are sitting in a safe a hundred miles away.
You going to do when it all goes horribly wrong. So they're saying, you know, write out your plans. I think realistically probably print out your plans. But you know, where is the plan whatcha going to do when it goes horribly wrong? I was always given the, the top tip of, at the subsequent court of inquiry as you mentioned about that JLR supply chain company, it's sort of when it goes wrong and you have to assume it will go wrong, what will you say? You've got to stand up and justify it. What will you say? And it's much better to say, well, we had a plan and, and actually, you know, we worked to that plan.
Yes, perhaps it could have been a bit better, but at least you've got a plan. You know, that's a marvelous first step.
Simon Batchelar: Yeah. Whereas just saying, well, we just sort of thought it wouldn't happen. That's not gonna work in your favour, is it? I've.
Exactly.
Yeah. Yeah, exactly. Well, yeah, I think that, you know, it's the old motto of plan for the worst and hope for the best
Paul Everington: Yeah.
Simon Batchelar: Is definitely the way to approach it. So I hope this video has got you thinking and hopefully it has made you think that perhaps you need to step back and have another, think about the risk and where you sit in that risk sequence for your supply chain, for your business, for your customers, and then what steps you can take to start to mitigate that then do reach out to either me or Paul. If you would like to get in contact with me. Then you can find me on LinkedIn, Simon Batchelar, or you can go to the website pallant.studio to learn more about what we do. And Paul, if people would like to get in touch with you specifically I think to think about that risk element and start to map out those risks 'cause that is something that you've got a lot of expertise in.
How can they get in touch with you, Paul?
Paul Everington: Yeah. They can get me on LinkedIn, Paul Everington, or our website, everwell.associates.
Simon Batchelar: Well, thanks very much everybody for listening and watching, and we'll see you next time.
Paul Everington: You next time. Cheers.