Today's organizations struggle with a paradox: we live in the most technologically advanced period of history. Yet, while we all use technology to make our personal and professional lives better, our trust in those technologies has never been lower.
This is a major problem for government contractors who are handling classified or controlled unclassified information (CUI) - especially those in the defense industrial base (DIB). Targeted cyberattacks, ransomware, and foreign espionage are just a few of the security threats they must fend off on a daily basis.
As the cyberthreat landscape advances, Epoch Concepts is committed to providing our clients with high-trust solutions and employing supply chain risk management (SCRM) principles from development through implementation. To explain how, first we must explain what supply chain security is and why it matters so much to modern federal contractors.
2021 has been a major year for cyberattacks across every category, some of them orchestrated through common software vendors. The unprecedented scale of these attacks has drawn much needed attention to supply chain security and third-party risk.
Today, government agencies and enterprises alike depend on hundreds of third-party suppliers to drive business functionality and essential processes. But it doesn't stop at software: physical hardware like servers, networking and communications equipment requires third-party manufacturers, resellers and technicians too.
So, what’s the problem? At the point of manufacturing, design oversights can lead to out-of-the-box security flaws. Before a product reaches customers, it can also be compromised through the introduction of rogue chips and the injection of malicious code.
The incidence of supply chain attacks has risen dramatically in recent years, leading to increased vigilance from legislators and industry professionals. At least three factors are largely responsible for this rise:
Ultimately, just like one vulnerable device can cause a weak link in an organization’s IT ecosystem, a single poor vendor can become the weak link in your hardware or software supply chain.
Prior to 2020, the U.S Government Accountability Office (GAO) issued a series of recommendations regarding supply chain security in 2018. Later that year, the Federal Acquisition Supply Chain Security Act passed into law, requiring that government agencies assess and meaningfully address supply chain risks.
In December 2020, the GAO issued another 145 recommendations to 23 government agencies – but as of summer 2021, none of the agencies were in full compliance. This prompted the Biden administration to issue Executive order 14028, titled ‘Executive Order on Improving the Nation’s Cybersecurity’.
Under the new order, government agencies must exercise greater vigilance in protecting their software supply chains. In response, the National Institute of Standards and Technology (NIST) produced guidelines for software testing and use, which will likely become federal policy. Until then, supply chain security is the order of the day – and Epoch Concepts is one step ahead.
To ensure compliance with security specifications and quality standards, we vet our partners carefully and monitor our technology components as they pass hands from manufacturing to final delivery.
The single most important principle of SCRM is trust. We do not partner with a product vendor or OEM unless they demonstrate a commitment to manufacturing quality, secure product design, and delivery. Important criteria include:
As value-added resellers, we hold ourselves to the same strict standards that we apply to our partners.
At Epoch Concepts, we design, source and integrate solutions to empower our customers. From storage to infrastructure, cybersecurity and cloud solutions, we architect fully customizable IT solutions and offer continual customer support. Above all, we put the security of our customers first and work to create an impenetrable supply chain they can trust. In a cybersecurity landscape full of risk, Epoch Concepts is here to give you peace of mind and help you every step of the way. Contact us to learn more.