Cybersecurity issues in small and medium-sized companies in the defense industry make both the companies themselves and other larger organizations in the supply chain vulnerable to cyberattacks.

researchers at BlueVoyant surveyed hundreds of small to medium-sized organizations in the defense industry and found that more than half had serious vulnerabilities in their networks, including unsecured ports and outdated software. These security gaps leave companies vulnerable to attacks, including data breaches and ransomware.
The defense industry is a favorite target for hackers (and government hacking groups) in general, as they try to steal intellectual property and other sensitive data. Cybercriminals are always on the lookout to exploit any weakness that will allow them to gain access to organizations' networks.
See also: Hackers combine ransomware and DDoS attacks to target victims
Unsecured ports, including remote administration tools and RDP ports, represent one of the most common vulnerabilitiesthat allow criminals to gain access to systems.

Attackers can relatively easily gain access to these services remotely if they are protected only with default or “weak” credentials. In addition, access can also be achieved through a phishing attack.
See also: New phishing campaign abuses Google Docs/Drive
The researchers also found that many of the defense organizations were using software that had not been updated to the latest version, which meant that the systems were vulnerable to older vulnerabilities that could be exploited by hackers.
Cybercriminals often exploit known vulnerabilities in an attempt to gain access to organizations’ networks. In the case of the defense industry, a vulnerable small company could lead to a breach of a larger company in the supply chain.
See also: Anom app: Greek criminals secretly chatting on an FBI trap app?
"A simple compromise of a valid email address can serve as a good vector for spreading a malicious attachment to all supply chain partners or simply putting a less prepared organization at risk," Austin Berglas, an executive at BlueVoyant, told ZDNet.

Many times, small and medium-sized companies don't care about cybersecurity, and it's often said that larger organizations should help smaller ones in a supply chain secure their networks. The argument is that by helping, everyone's networks will be protected.
According to Berglas, protecting the supply chain, implementing continuous monitoring, and proactively identifying threats to organizations will contribute to the security of the defense industry, which is a vital element of national security.
Source: ZDNet
