Back to news

June 17, 2019 | International, Security, Other Defence

How contractors can guard against cyber intrusions

By:

Contractors, facing an increasing barrage of cyber intrusions by foreign entities, should protect themselves using traditional regulatory approaches but also new techniques such as blockchain and artificial intelligence, according to a new report from Deloitte.

As companies in the defense supply chain began following the Defense Federal Acquisition Regulation Supplement (DFARS) cybersecurity regulations and the Department of Defense started to assess how adoption went, “we started to form our own ideas on what we see as emerging issues and solutions that [can] ... improve the cybersecurity posture against our enemies,” Jeff Lucy, managing director in cyber risk services practice at Deloitte, told Fifth Domain.

On the regulatory side, the report, titled “Third-party risk management: Cybersecurity in the Defense Industrial Base,” says prime contractors must comply with the defense regulations measuring their companies' compliance with national cybersecurity standards. They should also create awareness among their subcontractors and smaller companies by providing training. Third, primes should create third party assessment programs for performing cybersecurity evaluations of their suppliers.

However, the paper also suggests non-regulatory approaches, including automating supply chain functions, integrating blockchain to boost cybersecurity and using artificial intelligence to gain real time visibility into the threat landscape.

Lucy noted that the Pentagon is beginning to take these regulations seriously and the problems aren't going away.

“In 2019 we've seen that the DoD has started to move forward, start to take action to enforce their expectations around the DFARS requirements,” he said. “It's clear now with the steps that we're seeing with [Undersecretary of Defense for Acquisition and Sustainment] Ellen Lord getting the [Defense Contract Management Agency] on board to start auditing the suppliers processes for assessing their suppliers.”

Cyber intrusions into the supply chains of defense contractors have become more prevalent in recent years. In a recent example, the Chinese government was blamed for a series of hacks and while the information they stole was not technically classified, in aggregate, it was considered to be quite damaging to the U.S.

This year's Department-wide annual report on Chinese military activity included a new section highlighting that China's exfiltration of sensitive military information from the defense industrial base could allow it to gain a military advantage.

Ultimately, Lucy said the solution to the supply chain and cybersecurity for the defense industrial base is manageable.

“Most primes, from what I've seen with interactions with our customers, have put some level of the basic elements for a supplier assessment program in place already,” he said. “They've done some level of canvassing their suppliers, critical suppliers, taking a risk based approach to understand whether their suppliers are in adopting” standards.

https://www.fifthdomain.com/industry/2019/06/14/how-contractors-can-guard-against-cyber-intrusions/

On the same subject

  • Inflation, Supply Problems Could Push F-35 Cost Higher Than Expected, Lockheed Says

    April 24, 2022 | International, Aerospace

    Inflation, Supply Problems Could Push F-35 Cost Higher Than Expected, Lockheed Says

    Negotiations continue on three batches of jets—Lots 15 to 17—that were expected to be finalized last year.

  • Airbus livre le premier A330 MRTT à l'OTAN

    June 30, 2020 | International, Aerospace

    Airbus livre le premier A330 MRTT à l'OTAN

    Le premier avion ravitailleur MRTT (Multi Role Tanker Transport, avion militaire de transport et de ravitaillement en français) doit s'envoler ce 30 juin pour la base militaire d'Eindhoven, aux Pays-Bas, depuis l'usine d'Airbus de Getafe, en Espagne. Sous l'égide de l'OTAN il s'agit du premier appareil sur les huit commandés dans le cadre du programme MMF (Multinational MRTT Fleet initiative, en français, l'initiative de ravitaillement en vol) réunissant six pays européens (Allemagne, Pays-Bas, Luxembourg, Belgique, Norvège et République Tchèque). Le contrat, qui lie Airbus Defence and Space et les pays initiateurs du MMF depuis 2016, prévoit la livraison des sept autres appareils d'ici 2024, avec des options portant sur trois appareils supplémentaires. L'Usine Nouvelle du 29 juin 2020

  • Collaborative relationship will deliver major order with UK MOD for High Mobility Transporters

    February 24, 2023 | International, Land

    Collaborative relationship will deliver major order with UK MOD for High Mobility Transporters

    The HMT platform vehicle has also proven itself internationally and is in service in Denmark, Australia, New Zealand, Norway, and Estonia

All news