---
title: Steps for Medium Sized Businesses to Address Cyber Supply Chain Risk
description: Any business operating on the internet with internet accessible services provides an opening for anyone else on the internet - good, bad, or indifferent - to interrogate those services and see what’s running.
image: https://blog.nisos.com/hubfs/Badactors_seccompanies-01.png
---

[![NISOS_logo_high_res_horiz-black](https://blog.nisos.com/hs-fs/hubfs/NISOS_logo_high_res_horiz-black.png?width=3357&height=674&name=NISOS_logo_high_res_horiz-black.png "NISOS_logo_high_res_horiz-black")](https://www.nisos.com/)

- [Home](https://www.nisos.com/)
- Solutions 
    - [Manage Human Risk](https://nisos.com/solutions/human-risk/)
    - [Protect Online Platforms](https://www.nisos.com/solutions/trust-safety/)
    - [Manage Cybersecurity Risks](https://www.nisos.com/solutions/cybersecurity/)
    - [Protect Executives, Assets, and Reputation](https://www.nisos.com/solutions/corporate-security/)
    - [Secure the Employee Lifecycle](https://nisos.com/solutions/workforce-risk/)
- Services 
    - [Human Risk](https://nisos.com/services/human-risk/) 
          - [Employment Shield](https://nisos.com/services/employment-shield/)
          - [Executive Shield](https://nisos.com/services/executive-shield/)
          - [Third-Party Intelligence Solutions](https://nisos.com/services/third-party-intelligence-solutions/)
          - [Insider Threat Intelligence Solutions](https://nisos.com/services/executive-shield/)
    - [Risk Assessment](https://www.nisos.com/services/risk-assessments/) 
          - [Threat Landscape](https://www.nisos.com/services/threat-landscape-assessment/)
    - [Threat Monitoring](https://www.nisos.com/services/threat-monitoring/) 
          - [OSINT Monitoring & Analysis](https://www.nisos.com/services/osint-monitoring-and-analysis/)
    - [Investigations](https://www.nisos.com/services/investigations/) 
          - [Adversary Investigation](https://www.nisos.com/services/adversary-insights/)
- Company 
    - [About Us](https://nisos.com/company/about-us/)
    - [The Nisos Difference](https://nisos.com/company/the-nisos-difference/)
    - [Client Success](https://nisos.com/company/client-success/)
    - [Careers](https://www.nisos.com/company/about-the-company/careers/)
- Resources 
    - [News](https://www.nisos.com/newsroom/)
    - [Blog](https://www.nisos.com/nisos-blog/)
    - [Events](https://www.nisos.com/events/)
    - [Resource Library](https://www.nisos.com/resources/library/)
    - [Podcasts](https://www.nisos.com/podcasts/)
- [Contact](https://www.nisos.com/contact/)

- [Home](https://www.nisos.com/)
- Solutions 
    - [Manage Human Risk](https://nisos.com/solutions/human-risk/)
    - [Protect Online Platforms](https://www.nisos.com/solutions/trust-safety/)
    - [Manage Cybersecurity Risks](https://www.nisos.com/solutions/cybersecurity/)
    - [Protect Executives, Assets, and Reputation](https://www.nisos.com/solutions/corporate-security/)
    - [Secure the Employee Lifecycle](https://nisos.com/solutions/workforce-risk/)
- Services 
    - [Human Risk](https://nisos.com/services/human-risk/) 
          - [Employment Shield](https://nisos.com/services/employment-shield/)
          - [Executive Shield](https://nisos.com/services/executive-shield/)
          - [Third-Party Intelligence Solutions](https://nisos.com/services/third-party-intelligence-solutions/)
          - [Insider Threat Intelligence Solutions](https://nisos.com/services/executive-shield/)
    - [Risk Assessment](https://www.nisos.com/services/risk-assessments/) 
          - [Threat Landscape](https://www.nisos.com/services/threat-landscape-assessment/)
    - [Threat Monitoring](https://www.nisos.com/services/threat-monitoring/) 
          - [OSINT Monitoring & Analysis](https://www.nisos.com/services/osint-monitoring-and-analysis/)
    - [Investigations](https://www.nisos.com/services/investigations/) 
          - [Adversary Investigation](https://www.nisos.com/services/adversary-insights/)
- Company 
    - [About Us](https://nisos.com/company/about-us/)
    - [The Nisos Difference](https://nisos.com/company/the-nisos-difference/)
    - [Client Success](https://nisos.com/company/client-success/)
    - [Careers](https://www.nisos.com/company/about-the-company/careers/)
- Resources 
    - [News](https://www.nisos.com/newsroom/)
    - [Blog](https://www.nisos.com/nisos-blog/)
    - [Events](https://www.nisos.com/events/)
    - [Resource Library](https://www.nisos.com/resources/library/)
    - [Podcasts](https://www.nisos.com/podcasts/)
- [Contact](https://www.nisos.com/contact/)

# Blog

## Steps for Medium Sized Businesses to Address Cyber Supply Chain Risk

 by [Landon Winkelvoss](https://blog.nisos.com/blog/author/landon-winkelvoss)  | Aug 17, 2020 | [Cybersecurity](https://blog.nisos.com/blog/tag/cybersecurity), [cyber5](https://blog.nisos.com/blog/tag/cyber5), [third party risk](https://blog.nisos.com/blog/tag/third-party-risk), [supply chain](https://blog.nisos.com/blog/tag/supply-chain)

Any business operating on the internet with internet accessible services provides an opening for anyone else on the internet - good, bad, or indifferent - to interrogate those services and see what’s running. 

Bad actors and security companies are always actively conducting reconnaissance to find vulnerabilities but often lack  additional context. This [additional context](https://blog.nisos.com/white-papers/transitioning_cti_to_actionable_ti) is what should give a security team the advantage over bad actors running scrapers or scanners on the internet looking to take advantage of those vulnerabilities. 

Medium sized businesses should expect their larger customers and clients to contact them about potential vulnerabilities.  Generally the requests fall into three categories, according to AlixPartners’ Bill Varhol.

- A news-worthy vulnerability that brings data at risk such as Heartbleed or Shellshock. Larger organizations are going to want to know what exactly is vulnerable and when is it going to be fixed.
- Vendor onboarding diligence usually through questionnaires or security companies. These will often involve smaller scale vulnerabilities such as missing spf records or weak cryptography. However they can also include un-reviewed and automated findings with higher rates of false positives such as email addresses found on websites
- Potential typo-squatting domains that a medium-sized business should be aware of
- Outdated browser versions
- Web-application vulnerabilities such as cookies without http-only flags
- A suspicious email seemingly originating from a domain owned by the medium sized business.

 

Listen to Bill’s guidance for how medium sized businesses should prepare to address security issues like these with customers and clients:

 

---

---

---

- Solutions 
    - [Human Risk](https://nisos.com/solutions/human-risk/)
    - [Cybersecurity](https://nisos.com/solutions/cybersecurity/)
    - [Trust and Safety / Platform](https://nisos.com/solutions/trust-safety/)
    - [Corporate / Physical Security](https://nisos.com/solutions/corporate-security/)

- [Human Risk](https://nisos.com/services/human-risk/) 
    - [Employment Shield](https://nisos.com/services/employment-shield/)
    - [Executive Shield](https://nisos.com/services/executive-shield/)
    - [Third-Party Intelligence Solutions](https://nisos.com/services/third-party-intelligence-solutions/)
    - [Insider Threat Intelligence Solutions](https://nisos.com/services/insider-threat-intelligence-solutions/)
- [Risk Assessments](https://www.nisos.com/services/risk-assessments/) 
    - [Threat Landscape Assessment](https://nisos.com/services/threat-landscape-assessment/)
- [Threat Monitoring](https://www.nisos.com/services/threat-monitoring/) 
    - [OSINT Monitoring & Analysis](https://www.nisos.com/services/osint-monitoring-and-analysis/)
    - [Executive Shield](https://www.nisos.com/services/executive-shield/)
- [Investigations](https://www.nisos.com/services/investigations/) 
    - [Adversary Insights® Investigation](https://www.nisos.com/services/adversary-insights/)
    - [Event-Driven Intel Investigation](https://www.nisos.com/services/event-driven-investigation/)

- Why Nisos 
    - [About Us](https://nisos.com/company/about-us/)
    - [Client Success](https://nisos.com/company/client-success/)
    - [Our Approach](https://nisos.com/company/our-approach/)
    - [The Dogpile](https://www.nisos.com/the-dogpile/)
    - [Team Pandion™](https://www.nisos.com/company/team-pandion/)
    - [Careers](https://www.nisos.com/company/about-the-company/careers/)

- Resources 
    - [Blog](https://www.nisos.com/nisos-blog/)
    - [Resource Library](https://nisos.com/resources/library/)
    - [Podcast](https://www.nisos.com/podcasts/)
    - [News](https://www.nisos.com/news/)
    - [Events](https://nisos.com/events/)
    - [Law Firms](https://nisos.com/law-firms/)
    - [Federal](https://nisos.com/federal/)
    - [Media Inquiries](https://nisos.com/company/about-us/media-support/)

**Contact**  
[info@nisos.com](mailto:info@nisos.com)  
tel: [703-382-8400](tel:7033828400)  
2101 Wilson Blvd. Suite 304  
Arlington, VA 22201

<https://twitter.com/nisos>

<https://www.linkedin.com/company/nisos/>

<https://www.facebook.com/nisos.managed.intelligence/>

<https://www.instagram.com/nisos.managed.intelligence/>

![Nisos](https://blog.nisos.com/hs-fs/hubfs/Nisos_July2023/images/NISOS_logo_high_res_vert_white@2x.png?width=320&name=NISOS_logo_high_res_vert_white@2x.png "Nisos")

[Terms and Conditions](https://www.nisos.com/terms-conditions/) [Cookie Policy](https://www.nisos.com/cookie-policy/) [Privacy Policy](https://www.nisos.com/privacy-policy/)

©2025 Nisos All Rights Reserved

![](https://px.ads.linkedin.com/collect/?pid=1593266&fmt=gif)