In this increasingly interconnected world, the threat of cyberattacks looms large, capable of disrupting critical infrastructure and paralyzing operations. A company’s own security measures, no matter how robust, are only as strong as the weakest link in its supply chain. This is a critical consideration for any organization, as even the most sophisticated in-house defenses can be rendered ineffective if a third-party vendor is compromised.

Large companies, in particular, often rely heavily on a vast ecosystem of third-party service providers for everything from cloud hosting to payment processing and customer support. Each of these relationships introduces potential vulnerabilities that must be meticulously managed. The recent cyber incident involving Collins Aerospace, which made check-in services at Brussels Airport unavailable, serves as a stark reminder of how an attack on a single third-party provider can cascade and paralyze a customer organization’s critical functions.
A Glimpse into Supply Chain Vulnerabilities
While details of the cyber incident are limited, it’s understood that the disruption stemmed from an attack on Collins Aerospace, a global supplier of avionics and air traffic management systems. The attack, reportedly a ransomware incident, did not compromise Brussels Airport’s own systems. Instead, it impacted a crucial third-party provider whose services were essential for passenger check-in.
This type of supply chain attack is becoming increasingly common. Attackers target a less secure link in the operational chain to gain access or disrupt services for a vastly broader network. Particularly in the case of ransomware, a service provider with global customers is an alluring target, as they may be more likely to pay a hefty ransom. For Brussels Airport, however, this meant flight delays and operational challenges, demonstrating how deeply intertwined modern systems are and how a vulnerability in one part of the chain can have cascading effects. The incident underscored the critical importance of robust cybersecurity not just within an organization, but throughout its entire supply chain.
Ransomware: The Digital Extortionists
Imagine opening a seemingly innocuous email or clicking a suspicious link. Unbeknownst to you, this action can download malicious software onto your computer or network. This software typically exploits a known but unpatched vulnerability in the software or operating system on your computer, which is often the initial entry point. Once inside, the ransomware begins its destructive work:

Encryption
The ransomware quickly encrypts your files. This includes entire databases and applications. The encryption is theoretically reversible. However, you need the correct decryption key.

The Ransom note
After encryption, a ransom note appears on your screen. It demands payment in exchange for a decryption key.
The Impact of a Successful Ransomware Attack
Beyond the immediate costs, organizations face a significant ethical and strategic dilemma: whether to pay the ransom or attempt to restore systems from backups. Paying the ransom might seem like the quickest solution, but it risks not receiving a decryption key, validates the criminals’ illicit activities, and could make the organization a target for future attacks. Conversely, relying solely on restoration can be a lengthy and complex process, potentially extending downtime and increasing operational losses. Furthermore, if the victim cannot guarantee the malware has been fully removed from the network, the attacker can repeatedly encrypt restored backups. The true cost of a ransomware attack extends far beyond the ransom itself, encompassing:

Operational downtime
As seen with Brussels Airport, critical services can grind to a halt, leading to significant financial losses and disruption.

Data loss
If backups are also compromised or non-existent, valuable data can be permanently lost.

Reputational damage
Customers and stakeholders lose trust in an organization that fails to protect their data or provide reliable services.

Legal and regulatory penalties
In some industries and regions, data breaches can lead to significant fines. However, this cyber incident may be considered a force majeure under European law, which would likely exempt the airline from paying financial compensation.
Defenses Against Ransomware
The good news is that businesses are not powerless against these threats. A robust business continuity plan, heavily focused on cybersecurity, can significantly mitigate the risk and impact of a cyberattack. Here are three key best practices:
1
Business continuity plan
The unavailability of a critical piece of software in a supply chain is a perfect example of why business continuity plans are essential for modern enterprises. Such a plan should describe an organization’s actions and procedures in case of emergencies. Brussels Airport’s response wasn’t a singular plan but a combination of workarounds. The airport leveraged online check-in and self-service bag drop kiosks, which remained operational, and deployed a mix of manual processes using pen and paper, laptops, and iPads. The success of these workarounds allowed them to keep the majority of flights operating after the incident.
2
Implement a comprehensive backup
Backups are the most straightforward countermeasure against ransomware attacks. When attackers have encrypted your files, you remove the malware and restore a recent backup as quickly as possible. As a backup strategy, implement the 3-2-1 Rule, which means keeping at least three copies of your data, storing them on two different types of media, and keeping one copy offsite or in the cloud. Do not just set and forget your backup and recovery procedures; regularly test them to ensure they work when you need them most. Crucially, include offline or immutable backups that ransomware cannot reach and encrypt, as this is your ultimate safety net. Additionally, segment your network to prevent ransomware from spreading easily across your entire infrastructure, thereby protecting critical systems and backups.
3
Identity management
Ransomware rarely brute-forces its way into a network, but simply walks in through a compromised user account. This is where a robust Identity and Access Management (IAM) strategy becomes a critical defense. At its core, IAM operates on the principle of least privilege, ensuring every user and device has access only to the bare minimum resources required for their role. If a cybercriminal compromises one employee’s account, this principle severely limits their lateral movement. Instead of gaining access to the entire network, the attacker is confined to a small, controlled area, unable to access the critical servers and data repositories needed to deploy the ransomware network-wide. By tightly controlling who can access what, IAM effectively shrinks the potential attack surface, turning a would-be catastrophic breach into a contained and manageable security incident.
How Devoteam can help
At Devoteam, we help businesses build strong cybersecurity defences. From creating business continuity plans to setting up smart identity management, we’re here to guide you. We help you protect your business, and your entire supply chain, from attacks. Learn more here on how we can help you with your cybersecurity.
The Brussels Airport cyber attack, stemming from a third-party vendor compromise, highlights the critical need for robust cybersecurity, not only internally, but across the entire supply chain

Kasper Verhulst
Devoteam Cyber Security Consultant