A new report from SecurityScorecard has found that 90% of the world's 48 largest energy companies have suffered a supply chain data breach in the last year.

The security firm analyzed the cybersecurity posture of the largest coal, oil, gas, and electricity in various regions of the world, including the US, UK, France, Germany, and Italy. In addition to the companies themselves, they also looked at their suppliers.
The resulting report, “Energy Sector Third-Party Cyber Risk Report,” identified 264 breach incidents related to supplier breaches in the last 90 days alone.
See also: HSE: Slovenian electricity company suffered ransomware attack
All 10 top US energy companies (100%) experienced a third-party breach in the past year.
UK energy companies received the highest average security rating, with 80% holding a B or above. Overall, a third of global energy companies had a C rating or lower, indicating a higher likelihood of a breach.
Interestingly, of the 2000+ third-party vendors analyzed in this research, only 4% experienced breaches themselves. However, this small percentage had a huge impact on the security of their customers.
It is no surprise that the vulnerability in the MOVEit was the most exploited vulnerability in the last six months.
The report also highlighted the risks of so-called “fourth-party” breaches – that is, breaches at suppliers of suppliers.
See also: The Rhysida Ransomware Group Invaded the Network of a Chinese Energy Group
All US and UK companies experienced a third-party breach last year, and 92% of global energy companies have been exposed to such incidents.
According to experts, the risk of supplier breaches is increasingly important for large businesses.

“Hope and prayer can be helpful, but they are clearly not sustainable strategies,” argued former Fortune 500 CISO and chairman of the SecurityScorecard Cybersecurity Advisory Board, Jim Routh.
Energy companies can strengthen their security against cyberattacks by implementing a comprehensive security plan. This includes developing and adhering to security policies and procedures, as well as training staff on cybersecurity issues. Raising awareness of threats and basic security practices is crucial to protecting a company’s systems.
See also: Hackers breach US nuclear energy research lab
In addition, strengthening physical security is equally important. Energy companies should implement strict prevention measures, such as controlling access to facilities and installing technologies such as cameras and motion detection systems. In addition, periodically assessing system vulnerabilities and implementing updated security technologies are essential to prevent and detect potential cyberattacks.
Finally, working with external experts and security organizations can help energy companies strengthen their security. Experts can provide training, offer advice on developing security policies, and monitor the performance of security measures. In addition, working with other energy companies to share information and develop common security practices can enhance awareness and protection against cyberattacks.
Source: www.infosecurity-magazine.com
