The most unsettling class of modern attack doesn’t sneak past your defences — it arrives through the front door wearing a trusted badge. In a software supply-chain attack, criminals compromise a product or update channel you already rely on, and every customer who installs the update installs the intrusion. SolarWinds (2020) put the technique on front pages; the MOVEit file-transfer exploitation (2023) showed a single supplier flaw rippling into thousands of organisations; and a steady stream of poisoned open-source packages keeps the theme current.
Why attackers love the supply chain
- Leverage: one compromise, thousands of victims — the economics beat attacking targets one by one.
- Trust inheritance: updates from a known vendor bypass the suspicion (and often the controls) applied to strangers.
- Visibility gap: few businesses can list every third-party component inside the software they run.
The SMB version of the problem
You likely run dozens of third-party tools — accounting, remote access, website plugins, browser extensions. An SMB can’t audit vendors’ codebases, and shouldn’t try. What it can do is manage blast radius: know what you run, restrict what each tool can touch, and watch behaviour so a trusted program acting strangely gets caught anyway.
Practical defences
- Inventory: a simple list of the software and plugins you depend on — you can’t defend the unknown.
- Least privilege for tools, not just people: does that plugin really need admin?
- Keep patching — supply-chain risk is not an argument against updates; unpatched known flaws remain the bigger danger.
- Behavioural EDR: the defence that doesn’t care whether malicious code arrived via a stranger or a trusted update.
- Prefer vendors who publish security practices and disclose incidents quickly — how a supplier handles a flaw tells you everything.
You outsource software, but you can’t outsource accountability for what it can reach. Blast-radius thinking is the honest response to a risk you can’t fully see.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check