Friday, December 18, 2020

Lessons from the Solarwinds Orion Cyber Attack

 On December 13, 2020, SolarWinds CEO Kevin B. Thompson notified customers of a highly sophisticated supply-chain attack affecting Orion Platform software builds from versions 2019.4 through 2020.2.1.



The details were still emerging, but the attack appeared to involve malicious code inserted into software updates distributed to SolarWinds customers. Approximately 18,000 organizations may have installed the affected versions. The incident came to light shortly after cybersecurity firm FireEye disclosed that it had experienced a breach involving the theft of internal security tools.

This was a sobering moment for the cybersecurity community. The scope of the compromise extended beyond private companies, potentially affecting Fortune 500 organizations and government agencies, including entities responsible for national cybersecurity.

Why this attack matters

Most security conversations focus on attacks that come from outside an organization - such as denial-of-service attacks or penetration attempts - or attacks that exploit people and systems from within, such as phishing, ransomware, or malware.

The SolarWinds incident exposed a different and especially concerning risk: the compromise of a trusted software-development and delivery process. By inserting malicious code into legitimate software updates, attackers were able to take advantage of the trust customers placed in a widely used vendor.

The incident underscores an important reality: every organization may have vulnerabilities within its software development lifecycle. Even well-established processes can be compromised if appropriate safeguards, reviews, and monitoring are not in place.

For years, organizations have invested heavily in perimeter protection, intrusion detection and prevention, endpoint security, and network monitoring. Those controls remain essential. But this attack demonstrated that the software development process itself must also be treated as a critical security boundary.

The long-term impact will likely include stronger tools, more rigorous standards, and updated regulations designed to improve software supply-chain security.

What can be done?

Improve communication and information sharing

Effective response depends on timely, useful communication among companies, government agencies, and security professionals. Privacy and data-protection laws remain important, but organizations also need practical ways to share threat intelligence quickly and responsibly.

In a cybersecurity incident, early access to relevant information can help organizations contain an attack before it spreads. Coordination across agencies and industries is especially important when responding to threats with broad public and economic consequences.

Strengthen quality control and code review

Although the full technical details were still under investigation, the incident made clear that malicious code had entered the SolarWinds software delivery process. That should prompt every organization to review how code is developed, approved, tested, built, and released.



Agile development and automation can improve speed and consistency, but they do not eliminate the need for strong controls. Organizations should consider:

  • Independent code reviews and approval processes
  • Automated integrity checks between releases
  • Monitoring for unexpected code changes or behaviors
  • Secure, isolated test environments
  • Comprehensive audit logs for development and release activities
  • Regular reviews of third-party and open-source dependencies

Automation can help identify meaningful differences between code versions and flag suspicious changes for human review. It should support - not replace - clear accountability and sound engineering judgment.

Act now

Organizations should assess their current exposure and avoid assuming that any process is inherently secure. Review systems across the business, from software development and vendor management to finance and operational workflows.

A mature cybersecurity program may identify risks before they become incidents, but no single team or tool can protect everything. Security must be a shared responsibility across IT, engineering, leadership, legal, operations, and other business functions.

Breaking down departmental silos and examining the software development lifecycle honestly - even its weaknesses - is essential. Technology and standards will continue to improve, but organizations also need disciplined processes, open communication, and collective accountability to reduce the likelihood and impact of future attacks.

No comments:

Today, the world feels a little quieter, a little dimmer.

We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Pri...