Across
- 2. Evaluation process for vendor cybersecurity controls before onboarding
- 3. Ongoing adherence to security standards and regulations
- 6. Type of attack often associated with data theft and extortion
- 7. What organizations lack regarding their vendors' security practices
- 9. Criminal demand made after stealing sensitive data
- 12. Ability to withstand and recover from supply chain vulnerabilities
- 13. Potential danger from attackers targeting the supply chain
- 15. Software Bill of Materials; transparency document for software components
- 17. Entertainment company affected by the 2024 Snowflake breach
- 19. Cloud platform targeted in a major 2024 data breach affecting 165+ organizations
- 20. Elevated access often required by vendors for system maintenance
Down
- 1. Third party relied upon by vendors, creating multi-layered supply chains
- 4. Continuous evaluation of vendor security posture
- 5. Stolen usernames and passwords used by attackers to access systems
- 8. Third-party worker whose compromise enabled access to customer data
- 10. Unauthorized access to sensitive data, as occurred in the 2024 incident
- 11. Federal agency providing cybersecurity framework standards for supply chain security
- 14. Complex network of vendors and their sub-vendors
- 16. Third-party provider whose compromise can lead to supply chain attacks
- 18. Multi-factor authentication; security control that could have prevented the 2024 breach
