Skip to content

Comment on N. Korean hackers breached 10 defense contractors in South for months

Comments

..outsourcing relationships with them..

One of my latest gigs was on Third-Party Security. For years and years companies (especially banks) were giving little to no attention to third-party security/privacy. I've happily seen that over the past 5 years most (mega-big) banks have taken it "all the way up to 11".

Hackers are smart people, why hack company X with 50 people on their SOC and not hack a vendor that is lazy and clumsy? (and in some cases it's 5 guys with laptops behind a cheap never-hardened router in some random country)

Third Party Risk is a big deal these days. Especially with the rise in supply chain attacks

Oh and then when they get breached they will send me a letter informing me and say it was their vendor's fault.

No, buddy. That's still on you.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.