Levi Strauss & Co. (LS&Co.) was the recent target of a cybersecurity incident.
On Aug. 7, LS&Co. reported a cybersecurity breach with the U.S. Securities and Exchange Commission after an unauthorized third party gained access to company files through social engineering techniques that enabled unauthorized access to three employees’ company-issued computers. The company said it believes corporate information was “accessed and exfiltrated” because of the incident.
More from WWD
Following the detection, LS&Co. said it initiated response protocols, implemented containment measures and launched an investigation, which remains ongoing. The company has also engaged the services of third-party cybersecurity experts.
While LS&Co. said it does not believe the incident will have any material impact on its operations, the breach highlights a wider issue of the hidden vulnerabilities brands face across a complex business ecosystem. And Levi’s is not alone. Adidas, The North Face, Nike, Victoria’s Secret, Gucci, Balenciaga and other major brands have also faced cybersecurity incidents in recent years.
With networks spanning numerous suppliers, manufacturers, logistics providers and other partners across multiple tiers and geographies, Joe Schloesser, senior vice president at ISN, a contractor and supplier information management firm, said brands need a clearer picture of who they’re doing business with and where potential risks may exist.
“Bad actors are increasingly exploiting trusted relationships to gain access to organizations, whether through employees, contractors, suppliers or other third parties,” he said. “Companies need strong processes for verifying who is requesting access and why, particularly when that access extends outside their own organization. In practice, that verification [must] extend to contractors and suppliers, where most immature programs stop.”
Training helps, but he said social engineering is designed to exploit human behavior, even among trained and careful employees. Schloesser explained how brands must use “organizational guardrails” like verification protocols, least-privilege access and monitoring so that one person’s mistake can’t cascade into full system compromise. He added that this third-party risk management approach is where ISN sees the widest maturity gap between brands and their contractors or suppliers.
“This is especially true in extended supply chains, where a brand may have no direct relationship or insight into the security culture of a supplier’s employees,” he said.
Schloesser emphasized how a cyberattack on a smaller supplier, mill or technology provider could become a backdoor into a much larger brand.
“What we see and hear is that smaller contractors and suppliers can be attractive targets for bad actors seeking to exploit their trusted relationships with larger organizations. They may have fewer cybersecurity resources while still having meaningful access to systems, data or operations,” he said. “A company’s cybersecurity is ultimately influenced by the organizations it is connected to. Strengthening those relationships requires collaboration between hiring organizations and their contractors and suppliers.”
ISN provides solutions to mitigate vulnerabilities. Through ISNetworld, ISN collects and reviews health, safety, quality, insurance, training, cybersecurity, and sustainability information. The platform evaluates contractors and suppliers based on regulatory, industry and client criteria. Brands use ISN’s Transparency-One for supply chain transparency and traceability, mapping their supply chain to the site and material level. Schloesser said protections are built into the design of these platforms. “Suppliers and contractors maintain their own information and control which customers see it, data is collected once and verified instead of re-administered to every customer,” he said.
Efforts to increase transparency and report supply chain data add another layer of complexity. However, Schloesser said transparency itself isn’t the vulnerability. Rather, the risk is usually in how the information travels, for instance by email, spreadsheets or one-off questionnaires. Exchanging that same information through a controlled platform reduces exposure rather than adding to it, he said.
“Companies are exchanging more information across their supply chains, and that is progress. Not knowing who is in your supply chain is the larger risk. Understanding who has access to sensitive information, systems or critical operations helps organizations identify where their greatest third-party risks may exist and focus their efforts accordingly,” he said.
A trusted third party can reduce exposure rather than add to it. “When supplier information is collected once, verified, and shared on a need-to-know basis, brands gain visibility and suppliers answer fewer duplicate requests. The companies that hire them obtain a clear picture of the risk,” Schloesser said.
Schloesser urges brands to make cybersecurity a part of the broader conversation around supply chain risk, adding it is “a shared responsibility across the supply chain.”
“Greater transparency is an advantage, not a liability. The companies with the clearest view of their supply chain are the ones that are best positioned to find and close their cybersecurity gaps,” he said.
Best of WWD