Intel Execs Discuss the Future of Supply Chain Security
In the digital age, supply chain security has taken on a new meaning. It’s no longer just about protecting and ensuring a ready supply of critical goods, but ensuring those goods are secure from cyberthreats long after they reach the customer, Jackie Sturm, VP and GM of global supply chain operations at Intel, said during the Supply Chain Security Summit.
In the digital age, supply chain security has taken on a new meaning. It’s no longer just about protecting and ensuring a ready supply of critical goods, but ensuring those goods are secure from cyberthreats long after they reach the customer, Jackie Sturm, VP and GM of global supply chain operations at Intel, said during the Supply Chain Security Summit.
“If I think back 25 years ago, one of the biggest concerns for Intel was physical security. Microprocessors are small; they’re easily stored and transported; they were expensive; and they were a high, high-value target,” Sturm said. “As a company we had to figure out how we can protect our shipments because they were being hijacked on the road by bandits.”
While the physical supply chain remains critical, Sturm said, the threat has shifted to the digital domain over the last five years. “We’re seeing new threats emerging daily around cybersecurity. Bad actors are clearly increasing in their sophistication, and they’re also targeting larger institutions and looking for portals to access,” she said.
Instead of stealing physical chips off a truck, intellectual property is being targeted at points of digital exchange. This has lit a fire under many suppliers to ensure that the complex systems required to run critical infrastructure are protected from compromised hardware, according to Sturm.
Whether the chips have been intercepted in transit and swapped out with counterfeit parts, as was the problem 25 years ago, or compromised through a hardware or software exploit, there still exists a very real threat to the broader market, which relies on the technology to support its supply chains.
It doesn’t stop with the CPU either, according to Tom Garrison, VP and GM of client security strategy and initiatives at Intel. Supply chain security requires considerations about the platform as a whole, he said.
“We’ve heard about cases where devices were substituted out, whether they be for counterfeit reasons which introduce quality risks and security risks, or for just blatant security attacks,” he said.
Intel’s responsibility doesn’t stop once the hardware reaches the customer, Garrison said. “That device needs to be continually updated to make sure that it’s protected against the latest, greatest attacks.”
While that update mechanism is nothing new for Intel — the company has released numerous firmware patches for vulnerabilities over the years — Garrison said “it isn’t necessarily in practice by customers.”
Intel invests heavily in identifying, reporting, and mitigating vulnerabilities across its portfolio, but none of that work does customers much good if they’re not applying the appropriate patches.
“We spend a lot of time and energy making sure that the humans sitting at these devices are real. We do multi-factor authentication, we do biometrics, those kinds of things to make sure the person really is who they say they are. What we need to do is realize that’s only half the equation,” Garrison said.
The other half requires Intel to ensure that the device is safe, it hasn’t been compromised, and it’s up to date.
The roundtable came amid a pair of supply chain security revelations: the ongoing semiconductor shortage and associated national security concerns, and the SolarWinds hack, the implications of which are still coming to light months after its initial disclosure.
Sturm expects the next decade will be significantly riskier when it comes to supply chain security, and outlined three key areas of focus for the industry as a whole: prevention, detection, and response.
“We can protect ourselves against the known vulnerabilities using firewalls or existing security standards as they evolve,” she said. “But bad actors are constantly working to outsmart those systems, so rapid detection is the next layer of defense.”
To that end, security researchers earlier this month disclosed a novel side-channel attack affecting Intel chips based on the Ice Lake and Coffee Lake architectures.
When vulnerabilities are discovered, it’s critical for companies to respond quickly to mitigate them before they can negatively impact or infiltrate systems, Sturm said.
“You certainly can’t prepare, protect yourself from everything, but you can be prepared to respond, and smart supply chains are already doing that today,” she said. “We’re shifting our focus to encompass more around cyber and learn what’s happening in the marketplace.”
Finally, Sturm also called for a greater degree of collaboration across supply chains. “We know from the challenges that we’ve observed in 2020 that there’s a great level of interdependence and reliance on our collective set of supply chains around the world,” she said.