Security Breach: Following Up 30 Days Later
Editor's note, October 2026: This article was first published in January 2021 as the second part of our Security Breach series, following Security Breach: It Could Happen to You. The compromised vendor was SolarWinds: attackers had inserted malicious code into updates for its Orion network monitoring platform, and according to SolarWinds, fewer than 18,000 customers had installed an affected version (SolarWinds security advisory). In April 2021, the US and UK governments attributed the campaign to Russia's Foreign Intelligence Service (SVR). CISA closed its emergency directive on SolarWinds Orion (ED 21-01) in January 2026. Supply chain security has since become a legal obligation for many organizations: the EU NIS2 Directive requires it explicitly, and Germany's NIS2 implementation act has been in force since 6 December 2025. The series continues with Security Breach: Patch or Clash.
Almost a month has passed since an industry leader announced that its network and product had been compromised by a highly sophisticated state-sponsored adversary. In the meantime, much has been discovered about how the attack was carried out.
How the attack worked
Attackers managed to inject malicious code into the vendor's software updates, which customers routinely install without question. The update came from the vendor's own update servers, was signed with the vendor's legitimate code-signing certificate and was installed like any other update. This gave the threat actors direct access to customer infrastructure, and the repercussions of that access are still being uncovered today.
Major breaches like this are unsettling, but they remind us that any company is potentially at risk. We cannot prevent a high-level hack like this one, but we can all implement security best practices and take protective measures to minimize risk and, hopefully, avoid being affected.
What you can do
Perform due diligence
Validate the business relationship with all your vendors to ensure that data is handled safely and in line with applicable legislation, and that their own environment is secure and regularly updated. Certifications such as ISO/IEC 27001 and SOC 2 Type II show that a partner's security controls have been audited by an independent party against recognized standards. In other words, make sure all indicators are green before you treat partners as trusted and allow their software into your environment. The same goes for any required connection between their network and yours, such as an update server or a secure proxy or gateway.
Stay tuned in
If their software is affected directly or indirectly, most vendors can push out a security update, usually a quick fix, to mitigate the impact or prevent it entirely. Some provide their own update system; otherwise the update has to be downloaded manually from the vendor portal for later deployment. Make sure you are subscribed to all security notifications from your vendors, that they do not end up in a spam folder, and that the right team acts on them. In some highly secure environments, a formal change process validates every software update before installation. That takes time, and time is critical in a scenario like this.
Do not blindly accept every update
The easy thing would be to trust and install any update from your vendor. Why wouldn't you? Still, it is worth reviewing updates first where possible: analyze the possible impact, define acceptance criteria and prepare a rollback plan in case of issues. Only download security updates from trusted sources validated by your software vendor (HTTPS, valid certificates), keeping in mind that in this case the update itself was genuine and validly signed, so these checks alone would not have stopped it.
Follow official recommendations
Government agencies publish practical guidance on securing the supply chain, for example the UK National Cyber Security Centre's supply chain security guidance and the German Federal Office for Information Security (BSI) with its IT-Grundschutz framework.
Questions about vendor risk or how quickly you can roll out an urgent update across your endpoints? Our team supports endpoint management and endpoint security projects, and ISEC7 SPHERE shows patch levels and known vulnerabilities of the connected systems. Contact us.