You’ve secured your computers.

Your employees use multi-factor authentication.

Your email is protected.

Your devices are monitored.

Your staff receive cybersecurity training.

Everything looks good.

Then an email arrives from a company you’ve worked with for years.

You recognise the sender. The email address is correct. It refers to something that seems perfectly plausible. There’s a link for you to follow.

So you click it.

The problem isn’t necessarily that your business has been compromised.

The business you trust may have been.

We naturally trust people we already know

Most employees have become wary of obvious phishing emails.

A message from a stranger telling you that you’ve unexpectedly won £2 million is unlikely to fool many people.

But what about an email from your accountant?

Your solicitor?

A regular supplier?

A customer you’ve dealt with for ten years?

That’s very different.

When we recognise somebody, many of our normal warning signals disappear.

We already trust the sender. We expect them to contact us. We may regularly exchange documents and links with them.

And that’s exactly what can make a compromised supplier account so useful to an attacker.

A real example

We’ve seen this happen.

An organisation that one of our clients legitimately dealt with suffered an email account compromise.

The attackers gained access to a genuine mailbox. They then used that genuine account to send phishing messages to the organisation’s contacts.

Think about why that’s so effective.

The message wasn’t arriving from:

totally-legitimate-accountant-9837@gmail.com

It was coming from an email account belonging to a real organisation the recipient knew.

That gives the attacker something incredibly valuable.

Trust.

One of those malicious messages was sent to a business protected by Bitwise-IT.

The link attempted to take the recipient through a phishing process designed to compromise their Microsoft identity.

The security controls protecting the client detected the threat and prevented what could otherwise have become another compromised account.

That raises an interesting question:

What would have happened if that protection hadn’t been there?

Your suppliers are part of your attack surface

Businesses often think about cybersecurity as a boundary.

Everything inside the company needs protecting from everything outside.

The reality is more complicated.

Modern organisations are connected to dozens, sometimes hundreds, of other businesses.

Consider how many external organisations your employees interact with:

  • accountants;
  • solicitors;
  • payroll providers;
  • banks;
  • customers;
  • suppliers;
  • contractors;
  • software companies;
  • recruitment agencies;
  • insurers;
  • logistics providers;
  • marketing agencies;
  • IT providers.

Your employees receive emails, documents, invoices and links from them every day.

You can’t control the cybersecurity of every organisation you work with.

But their security can still affect you.

Global network representing connected suppliers and business partners

The more trusted the sender, the more convincing the attack

This creates an uncomfortable paradox.

Employees are frequently told:

“Don’t click links in suspicious emails.”

That’s good advice.

But what makes an email suspicious?

Poor spelling? An unknown sender? A strange domain? An unexpected message?

Now imagine an attacker is using a real mailbox belonging to one of your suppliers.

The email address is genuine. The email signature may be genuine. Previous conversations may even be available to the attacker.

They may know the names of people involved. They may understand the relationship between the two companies.

Suddenly the usual clues become much less obvious.

The attacker doesn’t have to convince your employee that they’re a trusted supplier.

They actually control the trusted supplier’s account.

Imagine they can read the conversation first

Sending phishing emails isn’t the only potential danger.

A compromised mailbox can provide an attacker with information.

Imagine they discover a conversation between your Finance Director and a supplier.

They can see:

A £40,000 invoice is due next Friday.

They know who normally sends it. They know who normally approves it. They know what the project is called. They know the language the people involved use.

Now imagine an email arrives saying:

“We’ve recently changed our banking arrangements. Please use the attached details for Friday’s payment.”

Would that immediately look suspicious?

Perhaps. Perhaps not.

But it is considerably more convincing than a random email from a stranger.

This is one of the reasons Business Email Compromise can be so dangerous.

The technology is only part of the attack.

The real target is often the business process.

Sometimes the attacker doesn’t need to hack you at all

This is an important point.

Suppose an attacker wants your company to transfer money to them.

One option is to attack your systems directly.

But if one of your suppliers has weaker security, compromising them may provide an easier route.

The attacker can then use the existing business relationship against you.

From your perspective:

Your Microsoft 365 account wasn’t compromised.

Your computers weren’t infected.

Your firewall wasn’t breached.

Your passwords weren’t stolen.

And yet your business could still lose money.

That’s why cybersecurity has to extend beyond the question:

“Are our systems secure?”

It also needs to ask:

“How do we safely interact with everybody else’s?”

Technology should distrust even trusted email

This is where layered security becomes important.

Email security systems shouldn’t automatically assume that a message is safe simply because the sender is familiar.

Depending upon the protection in place, security technology can examine things such as:

  • links contained in messages;
  • attachments;
  • impersonation attempts;
  • suspicious destinations;
  • malicious websites;
  • unusual sender behaviour;
  • authentication of the sending domain;
  • known threats.

Identity protection can add another layer.

If an employee does interact with something malicious and somebody subsequently attempts to use their identity in an unusual way, further controls and monitoring may provide another opportunity to detect the attack.

The objective is not to depend upon one perfect security system.

It’s to create multiple opportunities to stop the attack.

Secure business email protected by layered cybersecurity controls

Your employees are another layer

Technology isn’t infallible.

Employees therefore need to know that a message can be dangerous even when it comes from somebody they trust.

This doesn’t mean treating every supplier email like a criminal investigation.

It means recognising when a request deserves additional verification.

Particularly:

  • Changes to bank details.
  • Unusual payment requests.
  • Urgent requests involving money.
  • Unexpected login links.
  • Requests for passwords or authentication codes.
  • Unexpected document-sharing invitations.

If a supplier suddenly emails new bank details for a significant payment, verifying that change through a previously known telephone number is a small inconvenience compared with attempting to recover a large fraudulent payment.

And don’t verify the request by replying to the potentially compromised email account.

You may simply be asking the attacker whether their own fraudulent request is genuine.

Business processes can be security controls

Not every cybersecurity control involves software.

Imagine your company introduces a simple rule:

Any change to supplier bank details must be independently verified using existing contact information before payment.

That’s a cybersecurity control.

Or:

Payments over a certain value require approval from two people.

Another cybersecurity control.

Or:

Employees must report unexpected Microsoft 365 login requests to IT rather than trying repeatedly.

Another one.

Good cybersecurity combines:

People.

Processes.

Technology.

Leaving any one of those out creates unnecessary risk.

What about companies that have access to your systems?

Some suppliers present a greater risk than others.

Your stationery supplier probably doesn’t have administrative access to your Microsoft 365 environment.

Your IT provider might.

A software supplier might have access to business data.

A payroll provider may hold employee information.

An accountant may hold financial information.

A contractor might have remote access to systems.

The more access an organisation has, the more important its security becomes to you.

That doesn’t mean interrogating every supplier with a 200-question cybersecurity questionnaire.

It means applying sensible scrutiny according to risk.

Ask:

  • What information do they hold?
  • What systems can they access?
  • What would happen to us if they were compromised?
  • What would happen if their service became unavailable?
  • How would we revoke their access if necessary?

Those are business-risk questions.

Don’t forget old suppliers

Third-party access can accumulate over time.

A consultant needed access for a six-month project.

A software company installed an application three years ago.

An old IT provider had administrator accounts.

A marketing tool was connected to Microsoft 365 for a campaign nobody remembers.

The project finishes. The relationship ends.

But does the access disappear?

Not necessarily.

That’s why periodic reviews of accounts, applications, administrative privileges and external access are valuable.

You should know who currently has access to your business systems.

And why.

Ask your IT provider about supplier risk

You don’t need to become a supply-chain cybersecurity specialist.

But there are some useful questions you can ask your IT provider.

  1. What happens if one of our trusted suppliers sends us a malicious email?
    Does your protection examine the content, or is the sender simply trusted?
  2. What protection do we have against malicious links and attachments?
  3. If an employee enters their Microsoft 365 credentials into a phishing website, what happens next?
  4. Which external organisations or applications currently have access to our systems?
  5. Do we periodically review third-party access and remove anything no longer required?
  6. What business processes should we use to verify sensitive requests such as changes to supplier payment details?

The answers don’t need to be technically complicated.

They need to be reassuring.

Your cybersecurity is only part of the picture

There’s a tendency to think that once you’ve secured your own organisation, the job is complete.

Unfortunately, businesses don’t operate in isolation.

We exchange information with customers. We receive invoices from suppliers. We share documents with accountants. We communicate with solicitors. We connect software platforms together. We give trusted organisations access to information and systems.

All of those relationships create enormous business value.

They also create dependencies.

The answer isn’t to stop trusting your suppliers.

It’s to recognise that trust shouldn’t mean removing every security check.

What would happen if your most trusted supplier was compromised tomorrow?

Think of the five organisations your company trusts most.

Perhaps your accountant is one. Your solicitor. Your largest supplier. Your IT provider. A major customer.

Now imagine an attacker gains control of an employee’s email account at one of them tomorrow morning.

Would your cybersecurity still protect you?

Would your employees recognise an unusual request?

Would your payment procedures stop a fraudulent bank-detail change?

Would malicious links be detected?

Would suspicious identity activity be monitored?

That’s a much more useful question than simply asking:

“Do we have antivirus?”

Protect your business, even when somebody else’s security fails

Bitwise-IT provides managed IT and cybersecurity services to businesses across Essex and beyond.

Our approach to cybersecurity is based around layers of protection because no single technology, employee or supplier can ever be assumed to be perfect.

The objective is to make it difficult for one mistake, whether it happens inside your business or somewhere else, to become a serious incident.

If you’re responsible for IT within your organisation and would like to understand how well your current protection handles threats arriving through trusted suppliers, we’re happy to have a conversation.

Because your cybersecurity shouldn’t stop working simply because an email comes from somebody you trust.

Talk to Bitwise-IT

By Tim Downs

Tim has more than 25 years of experience in business technology and leads Bitwise-IT's managed IT and cybersecurity services for businesses across Essex. He writes practical guidance to help business owners and managers understand technology, reduce cyber risk and make better IT decisions.

RETURN TO BLOG