share_log

BlackBerry Research Reveals Software Supply Chain Vulnerabilities

BlackBerry Research Reveals Software Supply Chain Vulnerabilities

黑莓研究揭示軟件供應鏈漏洞
Business Today ·  07/30 15:42

BlackBerry Limited unveiled research at the NACSA Cybersecurity Summit, highlighting significant software supply chain cybersecurity vulnerabilities within Malaysian organisations. The study found that 79% of Malaysian IT decision-makers had received notifications of attacks or vulnerabilities in their software supply chains in the past year, exceeding the global average of 76%. Almost 38% of these organisations took up to a month to recover from such incidents.

黑莓有限公司在NACSA網絡安全峯會上發佈的研究結果,突出了馬來西亞組織中顯著的軟件供應鏈網絡安全漏洞。研究發現,79%的馬來西亞IT決策者在過去一年中收到了有關軟件供應鏈攻擊或漏洞的通知,超過了全球平均水平的76%。幾乎有38%的這些組織需要花費一個月才能從此類事件中恢復。

The survey, conducted in April 2024 by Coleman Parkes, followed the Malaysian Government's gazetting of the 2024 Cyber Security Act (Act 854) and the announcement of the National Semiconductor Strategy (NSS) in May. These initiatives aim to bolster Malaysia's position as a global semiconductor powerhouse and underscore the need for secure-by-design software practices and robust regulations to protect the IT supply chain. The report emphasised the critical importance of these measures in supporting Malaysia's ambitions in sectors like semiconductor manufacturing and Artificial Intelligence (AI).

2024年4月由Coleman Parkes進行的調查恰逢馬來西亞政府宣佈2024年網絡安全法(法案854)和5月制定國家半導體戰略(NSS)的公告。這些舉措旨在加強馬來西亞在全球半導體行業的地位,並強調採用安全設計軟件實踐和強有力的監管規定來保護IT供應鏈的必要性。報告強調這些措施對於支持馬來西亞在半導體制造業和人工智能領域的野心至關重要。

The study aimed to identify current procedures for managing security breaches in software supply chains. It revealed that nearly one-third of Malaysian respondents identified operating systems (30%) and IoT/connected components (19%) as the most at-risk areas, leading to significant financial loss (71%), reputational damage (66%), and data loss (59%) after an attack.

該研究旨在確定目前管理軟件供應鏈安全漏洞的程序。它揭示了近三分之一的馬來西亞受訪者認爲操作系統(30%)和物聯網/連接元件(19%)是風險最高的領域,這導致了攻擊後的重大財務損失(71%)、聲譽損失(66%)和數據丟失(59%)。

Ir. Dr. Megat Zuhairy Megat Tajuddin, Chief Executive, NACSA, presented at the media briefing during the NACSA Cybersecurity Summit 2024.

NACSA首席執行官Ir. Dr. Megat Zuhairy Megat Tajuddin在NACSA網絡安全峯會2024的媒體發佈會上發表了講話。

Dr. Megat Zuhairy bin Megat Tajuddin, Chief Executive of NACSA, stressed the importance of the Cyber Security Act 2024 in enhancing the cyber-resilience of Malaysia's National Critical Information Infrastructure. He highlighted Malaysia's commitment to becoming a leader in semiconductor manufacturing and AI, while also recognising the global responsibility to protect the software supply chain through improved compliance, technology adoption, and skills and training initiatives.

NACSA首席執行官梅加·祖海利·梅加·塔祖丁博士強調,網絡安全法2024年對於提高馬來西亞國家關鍵信息基礎設施的網絡韌性至關重要。他強調了馬來西亞致力於成爲半導體制造和人工智能領域的領導者,同時認識到通過改進合規性,採用技術和技能培訓舉措來保護軟件供應鏈在全球範圍內的責任。

BlackBerry Cybersecurity CISO, Christine Gadsby, noted the need for a comprehensive approach to cybersecurity, encompassing skilled workers, secure-by-design products, and modern AI monitoring tools. She acknowledged Malaysia's efforts to increase regulatory measures and investment in skills and technology to protect critical infrastructure and key industries from cyber-attacks.

黑莓網絡安全首席信息安全官克莉絲汀·蓋茨比指出,網絡安全需要全面的方法,涵蓋技能工人、安全設計產品和現代人工智能監控工具。她認可了馬來西亞加強法規措施和投資於保護關鍵基礎設施和關鍵行業免受網絡攻擊的技能和技術。

Malaysian organisations reported strict security measures, including security awareness training (58%), data encryption (48%), and multi-factor authentication (47%). However, only 40% prioritised Software Bill of Materials (SBOMs), despite international regulatory and compliance requirements likely increasing their importance in the coming years. Most IT leaders (95%) expressed confidence in their suppliers' cybersecurity policies, with many demanding compliance certification and third-party audits.

馬來西亞組織報告了嚴格的安全措施,包括安全意識培訓(58%)、數據加密(48%)和多重認證(47%)。然而,只有40%的人優先考慮軟件清單(SBOM),儘管國際監管和合規性要求可能在未來幾年內增加其重要性。大多數IT領導者(95%)對供應商的網絡安全政策表示信心,許多人要求合規認證和第三方審核。

The survey also highlighted challenges in maintaining regular software inventories, with factors such as a lack of technical understanding (58%), effective tooling (44%), visibility (41%), and skilled talent (40%) cited as barriers. More than three-quarters of respondents expressed a need for tools to improve software library inventories and visibility into software vulnerabilities.

調查還突出了維護定期軟件清單的挑戰,其中像缺乏技術理解(58%)、有效工具(44%)、可見性(41%)和熟練人才(40%)等因素被視爲障礙。超過三分之四的受訪者表示需要工具來改善軟件庫存和軟件漏洞的可見性。

Christine Gadsby, Chief Information Security Officer, BlackBerry Cybersecurity, presenting at the media briefing during the NACSA Cybersecurity Summit 2024.

黑莓網絡安全首席信息安全官克莉絲汀·蓋茨比在NACSA網絡安全峯會2024的媒體發佈會上發表了講話。

Christine Gadsby concluded that addressing human factors and leveraging AI-powered Managed Detection and Response (MDR) technologies could support organisations in managing emerging threats and complex security incidents. The full survey and further information on AI's role in protecting the software supply chain are available online, along with details on training courses at the Malaysia Cybersecurity Center of Excellence.

克莉絲汀·蓋茨比總結說,應對人爲因素和利用人工智能驅動的託管檢測與應對(MDR)技術可以支持組織管理新興威脅和複雜的安全事件。這項全面調查以及有關人工智能在保護軟件供應鏈方面所扮演的角色以及有關馬來西亞網絡安全卓越中心培訓課程的詳細信息都可以在網上獲得。

譯文內容由第三人軟體翻譯。


以上內容僅用作資訊或教育之目的,不構成與富途相關的任何投資建議。富途竭力但無法保證上述全部內容的真實性、準確性和原創性。
    搶先評論