CIO Brief: Supply-Chain Risk After SolarWinds — What Boards Now Ask
Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.
The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller set of targets, they then moved into Microsoft 365 email. Boards now routinely ask: could a trusted supplier compromise us?
What boards ask after SolarWinds
- Which software suppliers have deep access to our network?
- Could we detect an attacker who arrived through a trusted update?
- How dependent are we on on-premises systems that could be used to reach our cloud?
- Do we know which apps and accounts can read our executives' email?
The business impact
- Undetectable entry through trusted software.
- Long dwell time — attackers were inside some networks for months.
- Costly response across IT, legal and communications.
What good looks like
- An inventory of software with privileged access (monitoring, management, security, backup tools).
- Least-privilege configuration and network restrictions for those tools.
- Monitoring of administrative and cloud application activity, not just endpoints.
- Reduced dependence on on-premises identity servers that can forge cloud sign-ins.
- Vendor security requirements for critical software suppliers.
The decision
Ask for a list of your ten most privileged software products and the access each has. Then ask what would happen if one were compromised. The answers shape a supply-chain risk program better than any questionnaire.
- SolarWinds and Golden SAML (Dec 2020): The Supply-Chain Attack That Reached the Cloud Incident Teardowns
- How to Move From AD FS to Cloud Authentication and Retire Token-Signing Risk How-To & Hardening
- Detecting Golden SAML: Entra Sign-In Logs and Sentinel KQL Detection & Response