Skip to content
Supply Chain Risk Management – Resilinc
  • Products
        • OUR OFFERINGS

        • Agentic AI SuiteAutonomous risk management and compliance
        • AI AgentsIndustry and use case-specific analysis and action
        • Multi-Tier Mapping and MonitoringComplete end-to-end supplier visibility
        • RiskShieldProactive supply chain risk protection
        • EventWatchAIReal-time global event tracking
  • Solutions
        • BY INDUSTRY

          • Aerospace and Defense
          • Healthcare and Life Sciences
          • Automotive and Industrial
          • High Tech and Semiconductor
        • BY ROLE

          • Supply Chain Risk and Compliance
          • Sourcing and Procurement
          • Executive Leadership
          • AI and Data Science
        • BY SERVICE

          • Advisory Services
          • Managed Services
  • Resources
        • LEARN

        • Blog
        • Special Reports
        • Case Studies
        • White Papers and Reports
        • Podcasts and Webinars
        • ROI Calculator
  • Company
        • ABOUT US

        • Careers
        • About Resilinc
        • Events
        • Press Releases
        • In the News
        • Partners
        • Contact Us
Sign In
Schedule Demo
Supply Chain Risk Management – Resilinc
  • Products
    • Agentic AI Suite
    • AI Agents
    • Multi-Tier Mapping and Monitoring
    • RiskShield
    • EventWatchAI
  • Solutions
    • By Industry
      • Aerospace and Defense
      • Healthcare and Life Sciences
      • Automotive and Industrial
      • High-Tech and Semiconductor
    • By Role
      • Supply Chain Risk and Compliance
      • Sourcing and Procurement
      • Executive Leadership
      • AI Data Scientists
    • By Service
      • Advisory Services
      • Managed Services
  • Resources
    • Blog
    • Special Reports
    • Case Studies
    • White Papers and Reports
    • Podcasts and Webinars
    • ROI Calculator
  • Company
    • About Resilinc
    • Careers
    • Events
    • Press Releases
    • In the News
    • Partners
    • Contact Us
  • Sign In
  • Schedule Demo
  • Products
    • Agentic AI Suite
    • AI Agents
    • Multi-Tier Mapping and Monitoring
    • RiskShield
    • EventWatchAI
  • Solutions
    • By Industry
      • Aerospace and Defense
      • Healthcare and Life Sciences
      • Automotive and Industrial
      • High-Tech and Semiconductor
    • By Role
      • Supply Chain Risk and Compliance
      • Sourcing and Procurement
      • Executive Leadership
      • AI Data Scientists
    • By Service
      • Advisory Services
      • Managed Services
  • Resources
    • Blog
    • Special Reports
    • Case Studies
    • White Papers and Reports
    • Podcasts and Webinars
    • ROI Calculator
  • Company
    • About Resilinc
    • Careers
    • Events
    • Press Releases
    • In the News
    • Partners
    • Contact Us
  • Sign In
  • Schedule Demo

Home / Blogs / The Solar Winds Hack and Your Supply Chain

Feature-image-Cyber-Security-scaled

The Solar Winds Hack and Your Supply Chain

Jan 12, 2021

Resilinc Editorial Team

Cyber, Proactive risk mitigation

For corporate IT and cybersecurity professionals, the 2020 holiday season was filled with stress and long days as teams scrambled to assess whether their networks were penetrated by the widespread and stealthy hack known as Sunburst. Even more unsettling: for at least nine months before it was detected in early December, the malware had been spreading through the networks of as many 18,000 users of Solar Winds’ Orion network management software.

In a recent webinar, Resilinc’s co-founder and CTO Sumit Vakil warned that supply chain managers should also be proactively investigating how Sunburst may have affected their suppliers—and what mitigations those potentially affected suppliers are undertaking. “Right now, your IT organization is in fire drill mode. This is a massive crisis the likes of which they’ve never seen before,” said Vakil. “Chances are they’re not going to have time to think about how your suppliers or vendors may have been impacted.”

“Even if your own organization is secure, all the emails and documents that you’ve shared with suppliers, including those with sensitive IP such as instructions, build plans, and other trade secrets could become available to the hackers,” said Vakil. “Even if your communications go through a secure FTP server, chances are your supplier downloads them and puts them on Microsoft Sharepoint, which can be accessed by Sunburst.”

Vakil added that this risk extends to more than suppliers of services, parts, and materials. “Vendors who manage employee data or even your accounting firms could be impacted by this.”

Considered an “advanced persistent threat” (APT) likely originating from Russian-sponsored cyberwarfare actors, Sunburst “takes over whatever server it’s installed on and steals administrative level permissions from Microsoft Active Directory,” explained Vakil. “Then it can access the emails of high-level executives, IT staff, and others and exploit that access to work its way deeper into the network.”

Sunburst’s existence was revealed December 1 by the security firm FireEye, which announced that hackers had stolen some the firm’s “red team” tools—software used by teams of experts who act like hackers, trying to attack networks in search of vulnerabilities. Over the ensuing weeks, the extraordinary extent of Sunburst’s penetration was revealed as companies from Microsoft to Deloitte announced their networks had been hacked.

For security reasons, most companies that have been hacked will not reveal it publicly, and the full extent of the penetration may never be known. According to Vakil only a few attacks have been discovered but there’s a good chance there are a lot of latent hidden attacks that are yet to be discovered. What’s more, experts don’t fully understand the scope of the problems that Sunburst could have introduced into a network.

Still, there are mitigation measures available, including those recommended by CISA, the Cybersecurity and Infrastructure Security Agency, and Microsoft.

For supply chain practitioners and teams, Vakil recommends contacting suppliers and vendors – starting with their most critical ones – to inquire whether they run the Solar Winds’ Orion software and—if yes—what mitigations they’ve implemented (Resilinc customers can access a Sunbust supplier risk assessment survey through their account).

“It is not easy to figure out if a network has been compromised, so it’s a good idea to focus on whether your suppliers have implemented the mitigations recommended by CISA and Microsoft,” said Vakil. “As more suppliers start implementing these recommendations, some of the known issues will be addressed and we can have some level of confidence that supplier companies are doing something to address the hack. And it they are one of the approximately 18,000 companies that could be impacted, they’re putting in mitigations so the known attacks can no longer leak data.”

While this is a good starting point, companies need to remain vigilant on an ongoing basis: security experts agree that the scope of this attack could be far broader than what has been identified so far.

According to Vakil: “Supply chain teams will need to ensure that their suppliers are constantly monitoring their active directories to watch for fake accounts, elevated permissions, and other indications of a hack. You’ll need to make sure you and your suppliers are on top of the latest findings about Sunburst and implementing the most up-to-date recommended mitigations. This is the only way to make sure your suppliers are doing everything they can to protect your IP and your sensitive data.”

***

For more details on the Sunburst hack and risk management best practices, please listen to our recent webinar: SUNBURST: SolarWinds Orion Cybersecurity Attack Update.

For more information on Resilinc’s supplier assessment services – which include risk assessments for cybersecurity – please contact us.

climate change supply chain Ads-spot

Get Ahead of Hurricane Season

Prepare for Climate Change Supply Chain Disruptions

Learn how our supply chain risk management solutions help monitor climate change related disruptions.

Learn More

Recent Posts

Resilinc at Reuters Supply Chain USA 2025: Turning Disruptions into Competitive Advantage with AI Agents for Supply Chain Risk

Resilinc at ISM World 2025: Reinventing Supply Chain Risk Management with Agentic AI

The Future of Resilience: Agentic Supply Chain Risk Management Explained

5 Supply Chain Strategies for Riding the Tariff Roller Coaster

4 Supply Chain Trends from the Gartner® Supply Chain Symposium/Xpo™ 2025

Resilinc Named a Leader in the Gartner® Magic Quadrant™ for Supplier Risk Management

What Spend Matters’ Spring 2025 SolutionMap Tells Us About Supply Chain Risk Management & Compliance

How to Prepare Your Supply Chain for Tariffs: Tariff Risk Mitigation Techniques

About Resilinc

We’re the world’s leading supply chain monitoring, mapping, and resiliency solution. Over 100k organizations partner with us to take their SCRM programs from reactive to resilient.

Request Demo

Recent Blogs

Loading...
Resilinc at Reuters Supply Chain USA 2025: Turning Disruptions into Competitive Advantage with AI Agents for Supply Chain Risk
Jun 13, 2025
3 MIN READ
Resilinc Editorial Team

Resilinc at Reuters Supply Chain USA ...

From our CEO’s powerful speaking session, to demos at our booth of our...
AI, Events
Resilinc at ISM World 2025: Reinventing Supply Chain Risk Management with Agentic AI
Jun 10, 2025
2 MIN READ
Resilinc Editorial Team

Resilinc at ISM World 2025: Reinventi...

Resilinc made a powerful impact at ISM World 2025—highlighting how AI-driven foresight and...
AI, Events, Supply Chain Resilience, Tariffs and Trade
The Future of Resilience: Agentic Supply Chain Risk Management Explained
May 23, 2025
3 MIN READ
Resilinc Editorial Team

The Future of Resilience: Agentic Sup...

Discover how Resilinc’s agentic supply chain risk management is transforming disruption response with...
AI, Supply Chain Resilience
Read All Blogs
resilinc logo footer

Join the ranks of successful companies that rely on Resilinc to proactively protect their supply chain, safeguard their balance sheet, and gain a competitive edge.

Company

  • About Resilinc
  • Careers
  • Events
  • Press Releases
  • In the News
  • Partners
  • Resilinc Academy
  • About Resilinc
  • Careers
  • Events
  • Press Releases
  • In the News
  • Partners
  • Resilinc Academy

Products

  • Agentic AI Suite
  • AI Agents
  • Multi-Tier Mapping
  • RiskShield
  • EventWatchAI
  • Agentic AI Suite
  • AI Agents
  • Multi-Tier Mapping
  • RiskShield
  • EventWatchAI

Resources

  • Blog
  • Special Reports
  • Case Studies
  • White Papers
  • Podcasts and Webinars
  • ROI Calculator
  • Glossary
  • Blog
  • Special Reports
  • Case Studies
  • White Papers
  • Podcasts and Webinars
  • ROI Calculator
  • Glossary

Support & Legal

  • Customer Support
  • Contact Us
  • Legal
  • Customer Support
  • Contact Us
  • Legal
resilinc logo footer

Join the ranks of successful companies that rely on Resilinc to proactively protect their supply chain, safeguard their balance sheet, and gain a competitive edge.

Company

  • About Resilinc
  • Careers
  • Events
  • Press Releases
  • In the News
  • Partners
  • Resilinc Academy
  • About Resilinc
  • Careers
  • Events
  • Press Releases
  • In the News
  • Partners
  • Resilinc Academy

Products

  • Agentic AI Suite
  • AI Agents
  • Multi-Tier Mapping
  • RiskShield
  • EventWatchAI
  • Agentic AI Suite
  • AI Agents
  • Multi-Tier Mapping
  • RiskShield
  • EventWatchAI

Resources

  • Blog
  • Special Reports
  • Case Studies
  • White Papers
  • Podcasts and Webinars
  • ROI Calculator
  • Glossary
  • Blog
  • Special Reports
  • Case Studies
  • White Papers
  • Podcasts and Webinars
  • ROI Calculator
  • Glossary

Support & Legal

  • Customer Support
  • Contact Us
  • Legal
  • Customer Support
  • Contact Us
  • Legal
X-twitter Linkedin Facebook

© 2025 Resilinc Corporation. All rights reserved.

Data Security

Privacy Statement

The Supply Chain
Risk Management Maturity Model

Discover your position on the supply chain maturity curve and learn how you can reach an antifragile state of resiliency.

    Learn More