Most security advice assumes the trouble starts with you. Somebody clicks a bad link, reuses a password, puts off an update.

But some of the worst breaches of the last five years did not start with the victim at all. They started at a company the victim trusted, and walked in through a door that was already open.

The attack arrives with a signature on it

A supply chain attack targets a vendor instead of you. A software company, a hardware manufacturer, a tool your IT team installed two years ago and forgot about. Once attackers are inside, they let the vendor deliver the attack for them, inside an update you approved, from a name you recognize. Nothing looks wrong, because as far as your systems can tell, nothing is wrong.

Four that made the news

SolarWinds, 2020. Attackers slipped malicious code into a routine update of a network monitoring tool used by 18,000 organizations, including federal agencies. Everyone who installed it let the attackers in without knowing.

3CX, 2023. Attackers compromised a third-party software package, used it to get inside 3CX (a business phone company), then poisoned 3CX’s own update to push malware to every customer. Two hops, enormous reach.

MOVEit, 2023. A flaw in a widely used file transfer tool let attackers quietly pull data from hundreds of organizations before anyone noticed. If you used MOVEit, you were exposed whether or not you did anything wrong.

GitHub Actions, early 2025. Attackers compromised automated build pipelines and stole credentials from development teams. They did not target the code, they targeted the tools developers trust to ship it.

Hardware is the harder version

Software at least leaves traces. Hardware often does not.

A compromised router, a tampered firmware update, or a component altered before it leaves the factory can create a backdoor that survives a reboot, a wipe, and a fresh install. The 2018 Supermicro reporting put that idea in front of a general audience, and while the specifics were disputed, the concern was not. Firmware sits underneath nearly everything you would use to detect a problem.

It is not only obscure vendors. Microsoft, Adobe, your antivirus, anything that updates itself is a path in. You trust the update because of the name on it, and that trust is the target.

The part worth saying plainly

You cannot audit Microsoft’s build pipeline. You cannot inspect the firmware on every device before it ships. You cannot see inside your vendor’s data center, and no amount of diligence on your end changes that.

That is not a failure on your part. It is what living in a connected, software-defined world costs.

So treat supply chain risk as a given. The question is not how to eliminate it, it is how to make sure that when something gets in, it does not get far.

Limiting the blast radius

If an attack reaches you, layered security decides whether it ripples through everything or hits a wall and stops.

Get your passwords out of the browser. When malware lands on a machine, the saved password list is one of the first places it looks. Use a real password manager instead.

Use a different password everywhere. One breach at one vendor should not open every other door. Reused passwords turn one compromise into a master key.

Turn on two factor authentication. A stolen password is then only half of what an attacker needs. It will not stop everything, but it stops a lot.

Back up off-site, and test it. Ransomware delivered through a trusted update does not care how good your firewall is. Backups are how you recover without paying, and the 3-2-1 rule is still the standard. A backup nobody has restored from is a hope, not a backup.

Hand out less access. Not every account needs administrator rights, and not every machine needs to reach every other machine. Segment so a problem in one corner does not become a problem everywhere.

You cannot stop the fire next door

The goal was never a perfect defense. It is to make your environment expensive to move through. Attackers take the path of least resistance, and layered security means there is no easy path.

You cannot keep your neighbor’s house from catching fire. You can make sure yours is not built out of kindling.

If you are not sure where your own weak points are, that is the kind of thing we help with. Reach out to DarkHorse IT any time.

We talk through this kind of thing every week. Join us Thursdays at 7:40 AM on KFGO 790 AM.