Back to news

June 17, 2019 | International, Security, Other Defence

How contractors can guard against cyber intrusions

By:

Contractors, facing an increasing barrage of cyber intrusions by foreign entities, should protect themselves using traditional regulatory approaches but also new techniques such as blockchain and artificial intelligence, according to a new report from Deloitte.

As companies in the defense supply chain began following the Defense Federal Acquisition Regulation Supplement (DFARS) cybersecurity regulations and the Department of Defense started to assess how adoption went, “we started to form our own ideas on what we see as emerging issues and solutions that [can] ... improve the cybersecurity posture against our enemies,” Jeff Lucy, managing director in cyber risk services practice at Deloitte, told Fifth Domain.

On the regulatory side, the report, titled “Third-party risk management: Cybersecurity in the Defense Industrial Base,” says prime contractors must comply with the defense regulations measuring their companies' compliance with national cybersecurity standards. They should also create awareness among their subcontractors and smaller companies by providing training. Third, primes should create third party assessment programs for performing cybersecurity evaluations of their suppliers.

However, the paper also suggests non-regulatory approaches, including automating supply chain functions, integrating blockchain to boost cybersecurity and using artificial intelligence to gain real time visibility into the threat landscape.

Lucy noted that the Pentagon is beginning to take these regulations seriously and the problems aren't going away.

“In 2019 we've seen that the DoD has started to move forward, start to take action to enforce their expectations around the DFARS requirements,” he said. “It's clear now with the steps that we're seeing with [Undersecretary of Defense for Acquisition and Sustainment] Ellen Lord getting the [Defense Contract Management Agency] on board to start auditing the suppliers processes for assessing their suppliers.”

Cyber intrusions into the supply chains of defense contractors have become more prevalent in recent years. In a recent example, the Chinese government was blamed for a series of hacks and while the information they stole was not technically classified, in aggregate, it was considered to be quite damaging to the U.S.

This year's Department-wide annual report on Chinese military activity included a new section highlighting that China's exfiltration of sensitive military information from the defense industrial base could allow it to gain a military advantage.

Ultimately, Lucy said the solution to the supply chain and cybersecurity for the defense industrial base is manageable.

“Most primes, from what I've seen with interactions with our customers, have put some level of the basic elements for a supplier assessment program in place already,” he said. “They've done some level of canvassing their suppliers, critical suppliers, taking a risk based approach to understand whether their suppliers are in adopting” standards.

https://www.fifthdomain.com/industry/2019/06/14/how-contractors-can-guard-against-cyber-intrusions/

On the same subject

  • No title found

    April 1, 2021 | International, Aerospace

    No title found

    France Preparing to Offer Rafale Jets to Ukraine as MiG-29 Replacement

  • L'Inde commence l'assemblage du prototype de l'AMCA, son avion de combat multi rôle de 5ème génération

    March 18, 2022 | International, Aerospace

    L'Inde commence l'assemblage du prototype de l'AMCA, son avion de combat multi rôle de 5ème génération

    L'entreprise d'état indienne HAL (Hindustan Aeronautics Ltd) a annoncé la fabrication du premier bord d'attaque du prototype de l'avion de combat multi rôle indien 5ème génération AMCA (Advanced Medium Combat Aircraft). Le premier vol est prévu « pour 2024-2025 avec une mise en production début 2030 », selon Air & Cosmos. L'AMCA, d'une masse de 25 tonnes, aura une charge utile interne de 1.5 tonne et une charge utile externe de 5.5 tonnes en addition de 6.5 tonnes de carburant. Il sera disponible en version furtive et non furtive. Concernant ses deux moteurs, ses variantes connaîtront deux étapes : une version MK1 équipée des moteurs GE414 qui équipent le LCA Tejas (génération précédente d'avions de combats indiens), puis une version MK2 équipée d'une motorisation plus puissante (110kN, légèrement en dessous du NGF). « Un accord de collaboration devrait être signé prochainement avec Safran ou Rolls-Royce pour le développement de ce moteur », souligne Air & Cosmos, qui rappelle que Safran a déjà travaillé avec HAL sur le développement du moteur Shakti de son hélicoptère ALH. Air & Cosmos du 18 mars

  • Lawmakers seek national coordination, support for maritime industry

    January 30, 2024 | International, Naval

    Lawmakers seek national coordination, support for maritime industry

    A group of lawmakers is asking the White House to create a maritime policy coordinator and invest in the U.S. shipbuilding and shipping industries.

All news