Software and IT vendors responsible for 67% of energy sector breaches, according to Intelligent CISO

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Report on Surge in Supply Chain Risks in the Energy Sector amid Growing Vendor Dependence

In a recent report released by SecurityScorecard and KPMG LLP, it has been revealed that the energy sector is facing a surge in supply chain risks as it becomes increasingly dependent on vendors. The report, titled “A Quantitative Analysis of Cyber Risks in the U.S. Energy Supply Chain,” delves into the cybersecurity vulnerabilities across the energy sector and its supply chains.

As regulatory bodies worldwide are ramping up cybersecurity requirements, the timing of this report couldn’t be more critical. The report aligns with global efforts to strengthen cybersecurity in the energy supply chain, following commitments made during the June 2024 G7 summit to enhance defenses against cyber threats.

Recent initiatives such as the International Counter Ransomware Initiative (CRI) and the US Department of Energy’s Supply Chain Cybersecurity Principles underscore the urgency of addressing cybersecurity risks in the energy sector.

Ryan Sherstobitoff, Senior Vice President of Threat Research and Intelligence at SecurityScorecard, highlighted the industry’s vulnerability due to its growing dependence on third-party vendors. The report found that third-party risks drive almost half of breaches in the energy sector, significantly higher than the global average. Additionally, vulnerabilities are concentrated in key risk factors such as application security and network security.

With the energy sector undergoing a generational transition and facing evolving threats, it is crucial for organizations to quantify these risks and strengthen cybersecurity measures. By taking decisive action now, the industry can mitigate the risks posed by cyber threats and ensure a smooth transition towards a more secure and interconnected energy grid.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

US Senator Requests NSA Guidance on Best Practices for VPN Use Against Foreign Surveillance

A prominent US senator is urging the National Security Agency (NSA) to provide public guidance on best practices for using virtual private networks (VPNs)...

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...

BREEZE COMET Threat Actor Targets Brazilian Financial Sector with Sophisticated Attacks

BREEZE COMET: A Rising Threat to Brazil's Financial Sector In 2024, Mandiant began investigating a series of cyber compromises targeting Brazilian financial services, retail, and...

Dropbox Reports Compromise of 5,000 Accounts Due to Legacy Login Vulnerability

Dropbox has reported that approximately 5,000 accounts were compromised last month due to a legacy login vulnerability associated with Lenovo IDs. This breach allowed...