When can a manufacturing company be cyberattacked and not cyberattacked at the same time?
The answer — anytime — is not a paradox like the famous thought experiment about Schrödinger’s cat. Manufacturers belong to supply chains and rely on vendors, many of which have digital connections that can be exploited by hackers. An attack on one company can become a way into another.
Cyber risk now radiates outward from large companies and prime contractors to subcontractors and vendors, from first- to second- to third-, fourth- and even fifth-party relationships.
Here’s an example of how a large organization can be attacked indirectly.
In December 2024, Chinese hackers broke into the U.S. Treasury Department. But they didn’t go in the front door. They first targeted the computers of BeyondTrust, a cybersecurity company that does work for the U.S. government.
According to industry reports, the hackers found a vulnerability in third-party software used by BeyondTrust, then broke into part of BeyondTrust’s cloud environment and stole a digital key that gave them access to software used by IT technicians to connect remotely to customers’ computers. The hackers used that access to enter several U.S. Treasury workstations and obtain unclassified documents.
Trace the path of exploitation in the above example: From (1) a vulnerable piece of third-party software into (2) BeyondTrust’s cloud environment, where (3) a digital key accessed (4) IT software that connected remotely into (5) Treasury Department workstations.