clic para entrar
← back to blog
Software

SolarWinds: the supply chain hack

SolarWinds: the supply chain hack

In December 2020 one of the most talked-about attacks of the past decade came to light: the SolarWinds case. The attackers didn’t force their way into thousands of organizations one by one. They did something quieter and more serious: they compromised a legitimate, widely used software tool and inserted malicious code into an update that the companies themselves downloaded and installed in good faith. The threat didn’t knock on the door; it arrived inside a product everyone trusted.

That’s the lesson that outlives the incident. For a Mexican small business, the technical detail matters less than the underlying idea: every software provider you use is also part of your risk surface. The billing system, the site plugin, the app that syncs your sales, the extension someone on the team installed “just to try it.” They all expand what can go wrong. The good news is that you don’t need a corporate budget to protect yourself; you need order, judgment, and decisions with reliable information.

Your software provider is also your risk

When you contract or install a tool, you don’t just acquire a function. You inherit the security practices of whoever built it, their update pace, and their way of handling the data you entrust to them. If that link fails, your operation is affected even if you did everything right on your side.

This doesn’t mean distrusting everything or slowing your operation. It means choosing with your eyes open and knowing exactly what you have installed and why. Most small businesses don’t have that inventory at hand, and that’s where the problem starts: you can’t protect what you don’t even know you’re using.

Diagram of a software supply chain with one compromised link
A single compromised provider can propagate risk to the entire chain that trusts it.

What a small business without a cybersecurity team can do

You don’t need an entire department to greatly reduce your exposure. The key is simple, sustained habits:

  • Make an inventory of your software. Note which tools, plugins, and services you use, what they’re for, and who’s responsible for each. What’s not on the list can’t be looked after.
  • Less is more. Retire what you no longer use. Every abandoned application is a door that stays open with no one watching it.
  • Limit access. Give each person and each system only the permissions they truly need. That way, if something is compromised, the damage stays contained.
  • Update with judgment, not on blind autopilot. Updates are good, but it’s worth knowing where they come from and keeping backups before applying them.
  • Have backups you can restore. A backup is only useful if you’ve tested it. Keep copies outside the main system and verify that they work.

Security isn’t buying one more tool; it’s knowing what you use, why you use it, and what you’d do if it failed.

Custom software: control over what runs in your business

One of the advantages of working with custom software is visibility. When a solution is built with your operation in mind, you know what components make it up, what data it handles, and how it updates. It’s not a black box with dozens of dependencies no one reviewed.

That doesn’t eliminate risk—no system does—but it does give you something valuable: control. You can decide what gets installed, keep a clear record, and respond quickly if a problem appears. And something we always take care of at Normandia: when modernizing or replacing a tool, you keep your data, processes, and history. Your business’s continuity shouldn’t depend on a single provider over which you have no say.

How to protect your software chain

Don’t try to solve it all in a week. Start with what you can actually cover and measure:

  • Make the list. Spend an afternoon inventorying your software and access. That alone will already put you ahead of most.
  • Clean up the obvious. Retire old accounts, users who are no longer around, and tools no one uses.
  • Secure your backups. Confirm they exist, that they’re outside the main system, and that you know how to restore them.
  • Review your key providers. Ask how they handle security and updates for what they sell you. Their answers tell you a lot.
  • Prioritize the critical. Focus first on the systems that, if they failed, would halt your operation.

The SolarWinds case reminded us that trust in software is necessary, but it’s worth it being informed trust. With order, judgment, and the right decisions, a small business can protect itself without slowing its growth. If you want to review your operation and figure out where to reinforce it, at Normandia Web we can support you with solutions built to your measure.

Ready to put it to work in your company?

Tell us what’s costing you time, money or control. We’ll help you figure out where to start.

Start your consultation →