Cybersecurity leaders warn third-party providers becoming critical infrastructure risks | UAE News Today

0

Experts warned that organisations relying on third-party providers to run critical services are creating new cybersecurity and resilience risks. Photo: KT file

 

The concept of critical infrastructure has changed a lot as businesses transition from using their own internal systems to relying on cloud services and other infrastructure from outside providers.


Cybersecurity leaders emphasized that this shift has introduced new risks related to cybersecurity and system resilience that organizations can no longer ignore. During a panel discussion at the third edition of Future Sec, hosted by Khaleej Times, experts discussed how this evolution has impacted the definition of critical infrastructure.

Dee Deu, Group Director of Information Security at Chalhoub Group, explained that ten or twenty years ago, critical infrastructure was something that organizations owned and managed in-house, with their own IT teams.

Today, however, the landscape has changed. "We now have infrastructure as a service," Deu said. "We look at the cloud and how we've moved to cloud-based solutions in certain situations."

Many organizations today use a combination of on-premise infrastructure they own and cloud or other services from external providers, which creates a greater dependence on outside vendors.

"If you look at the recent AWS incident and the number of organizations affected, the concept of critical infrastructure has to be viewed through that lens," Deu added. "It's no longer about what we own but what services are essential for our operations."

The panel also addressed the issue of third- and fourth-party risks.

As organizations grow more dependent on external providers, it becomes harder to fully understand the scope of their technology environment. Patrick Pitchappa, CISO of Equiti Group, pointed out that many organizations aren't managing these dependencies well. "I don’t think any organization has it right," he said, highlighting the long-standing issue of shadow IT and the growing challenge of shadow AI.

Pitchappa used the Cloudflare outage and the subsequent AWS incident as examples of how being overly reliant on a single external provider can have widespread effects.

"You build large infrastructures, but then there's this one third-party that you're so reliant on," he explained. "There are a lot of third- and fourth-party dependencies. That's where I think we start. We miscalculate."



Tags

Post a Comment

0Comments
Post a Comment (0)