Case study
Case Study - Solarwinds
5 slides · 2 min read · Domain 2
Case Study: Solarwinds
The Solar Winds cyberattack, discovered in December 2020, was a sophisticated supply chain attack that targeted the Solar Winds Orion software, a widely used IT infrastructure monitoring and management tool.
The incident raised significant concerns about the security of software supply chains and highlighted the potential risks associated with a breach in a widely used software platform.
Threat actors compromised the software's development process, injecting malicious code into software updates distributed to SolarWinds customers. This code allowed the attackers to gain unauthorized access to the networks of numerous organizations, including government agencies and major corporations.
Managing Requirements
This incident emphasized the importance of managing requirements related to secure software development and the necessity of strict controls in the software supply chain.
Data Security Restrictions
The attackers exploited vulnerabilities in the software's development process, leading to unauthorized access to sensitive information within the compromised networks. The incident highlighted the need for robust data security restrictions, emphasizing the principle of least privilege to prevent unauthorized access to critical systems and data.
Safeguarding Privacy
As the compromised software was widely used, the incident raised concerns about the potential exposure of sensitive data. Safeguarding privacy became a crucial aspect, urging organizations to enhance monitoring, encryption, and access controls to ensure that personal and confidential information remains protected even in the event of a supply chain compromise.
Asset Retention
The SolarWinds incident involved a prolonged compromise where the threat actors retained access to networks for an extended period. It underscored the importance of effective asset retention practices, emphasizing the timely identification and removal of unauthorized elements to prevent persistent threats and unauthorized access.
Categorization and Possession of Data
SolarWinds Orion, being a network monitoring tool, possessed extensive data related to network configurations, performance, and vulnerabilities. The breach demonstrated the need for meticulous categorization of data based on sensitivity. Ensuring that only essential data is retained and categorizing it according to its importance helps limit the potential impact of a security incident.
