Cybersecurity Glossary
Supply Chain Attack
Compromising a supplier, a plugin or an update in order to reach that supplier's customers.
What Supply Chain Attack means
Rather than attacking a well defended organisation directly, the attacker compromises something it already trusts: a software update, a managed service provider, a plugin author, a billing platform. The malicious code then arrives through a channel the target has every reason to trust.
Why Supply Chain Attack matters for small businesses and nonprofits
Small organisations sit downstream of many suppliers and rarely have the leverage to audit them. The realistic response is not vendor auditing; it is limiting what any single supplier connection can reach and noticing when it behaves oddly.
What to do about Supply Chain Attack
- Inventory who has remote access to your systems and remove what is no longer needed
- Ask suppliers with access what their own security and notification commitments are
- Limit supplier accounts to the systems they actually need
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.