Former federal CISO Gregory Touhill warns that the coordinated supply chain attack on SolarWinds’ monitoring software – breaching the Departments of Commerce and Treasury among others – is a call to arms. “We need to be looking for further activity – not only in IT, but in operational technology, industrial controls systems and, arguably, in the code that is running a lot of our internet of things devices,” Touhill remarked during an interview with Information Security Media Group. Touhill also discusses:
- The potential scale of this supply chain attack
- Lessons to learn from this campaign
- Why this incident calls for “a more credible cyber deterrent strategy”
