On Thursday 3 September, IT distributor Dustin reported a serious security incident. The company took part of its systems offline as a precaution; according to its own announcement, the webshop and customer portals will not be back until 23 September. Nothing has yet been disclosed about the nature of the attack or whether customer data was taken. For an organisation with roughly two thousand employees and 1.8 billion euros in revenue, that is a notably long silence — and it is exactly that silence which makes this story relevant to anyone who buys from IT suppliers.
What is known so far
Dustin describes the event as a serious incident and has filed a report with the police. Beyond that it is holding its cards close: which systems were affected, how the attackers got in, and what data may have been accessed have all gone unmentioned. That is not unusual while a forensic investigation is running, but it does leave customers in the dark. The announcement that portals will stay down for weeks says enough about the scale of the recovery. Further background is available at Security.NL.
Why this is your problem too
Most organisations think of cyber risk as something that happens inside their own network. But a supplier that processes your orders knows your contacts, your billing addresses, your order history and sometimes the serial numbers of your equipment. If that party goes down, you lose two things at once: the operational route to order hardware, and the certainty that your data sits only with them.
There is a second, subtler risk. An incident at a well-known supplier is almost always followed by a wave of phishing that uses the incident itself as the pretext. Messages about "an outstanding order that needs reconfirming" or "changed bank details due to the outage" land with precisely the people who know something is genuinely going on. That makes such a message far more believable than the average fake email.
Four questions worth asking now
- Which suppliers process our data? Not only the IT parties, but also payroll, time registration and any webshop integration.
- What does the contract say about notification? Under the GDPR you remain accountable as the client; a processing agreement should specify a notification deadline.
- Do we have an alternative? If the ordering route is down for weeks, what happens when a laptop dies or a switch fails?
- Does everyone know payment details never change by email? Put it in writing that changes are verified by phone, on a number you look up yourself.
From scattered answers to one list
In practice these questions do get answered individually, but they rarely sit in one place. A simple list of suppliers, noting which data each one processes, who the contact is and what notification period was agreed, takes an afternoon to build and saves days during an incident. That same overview is also what regulators — and, for organisations in scope, the Dutch implementation of NIS2 — expect you to have. Research among Dutch IT professionals published this week showed that more than half of organisations had an incident in the past two years traceable to outdated software, as reported by Dutch IT Channel. Supply chain risk is the logical next layer on top of that.
We keep track of which suppliers and systems are in scope for our customers, and raise the alarm when something happens anywhere in that chain. If you would like to know how your own supplier overview holds up, book a conversation with an engineer — an hour is usually enough to see where the gaps are.
Read also
Critical vulnerability in Adobe Acrobat
Ready to run worry-free?
Book a no-obligation introduction. We map your IT and security and show where the difference lies.
Book a call →
