A software vulnerability led to the SolarWinds supply chain attack in which Russian attackers compromised about 100 private corporations and nine federal agencies’ networks. And according to SolarWinds CEO Sudhakar Ramakrishna, software is also part of the solution to prevent a future breach of this magnitude.

But this will require an industry-wide mindset change, Ramakrishna added during a panel discussion on Thursday. “For instance, it’s well understood that software has bugs — that’s OK. But it’s well accepted that software has bugs. It’s well accepted that software can have security challenges. And I think that goes back to a mindset issue, from education all the way to how you build the software itself. We don’t talk about software needing to have quality, but yet we talk about software having to have security.”

SolarWinds CEO Plans Secure Software by Design

This plays into a new, companywide initiative that Ramakrishna calls “secure by design,” and it involves building security into the software itself. “You’ve got to do it at the design phase, and as a mindset and an education, not as an after-the-fact,” he said. “We should not be using patchwork tools to test security or build security after the fact.”

Ramakrishna spoke on a panel hosted by Neil Daswani and Moudy Elbayadi, authors of the newly released book, “Big Breaches: Cybersecurity Lessons for Everyone.” The book discusses some of the worst breaches to date, like the Capital One and Equifax breaches. “As we were writing the book, one of the largest espionage attacks in history had yet to be uncovered,” Daswani said. He co-directs Stanford Online’s Advanced Cybersecurity Certificate Program and is a former CISO for Symantec CBU and LifeLock.

Of course, Daswani means the SolarWinds attack, which researchers discovered in December, and the book released in its wake. “Such an attack could have targeted any one of hundreds of software companies that have widely deployed solutions as a part of our software supply chain used by the government and private sector. I would not be surprised if similar attacks could be and are happening against other companies besides SolarWinds.”

And, in fact, another major attack on Microsoft Exchange email systems happened shortly after, and some security researchers say its damage could be even worse than SolarWinds.

Microsoft Hack Keeps Netflix Head of Security Up at Night

Jimmy Sanders, head of security at Netflix and who also sits on the ISSA International Board of Directors, said the Microsoft Exchange hack keeps him awake at night.

“The attackers had the ability for months to read emails of transactions that you have within your company without you even knowing about it,” Sanders said, speaking on the panel. “And so now they are able to do research on, and specifically target CEOs and other high-level executives to do accurate spear phishing that would mimic the way that you would talk regularly as your company. If the attackers are smart about it, they would do something similar to what we saw with SolarWinds where they would ping servers, low and slow.”

Antivirus scanners and domain blacklisting services wouldn’t detect this type of stealth attack, he explained. “You go to VirusTotal, you do a check on it, and it shows up good because it has’t been reported yet,” Sanders said. “Those are the things that keep me up.”

This is why it’s vital to do true defense in depth security, which enacts a series of security controls that are layered throughout the network to protect systems and data, Sanders added. “We make it such that attackers don’t need to be right one time, they need to be right multiple times.”

SolarWinds CEO Narrows Attackers’ Entry Point

As SolarWinds continues its internal investigation, it has narrowed down the attackers’ initial entry point from 16 possibilities down to three, Ramakrishna said. Those three “painfully become routine at this point in terms of the initial entry,” he added. “We are investigating a very targeted spear phishing attack. Two is a vulnerability at that point in time in one of the third-party software that we have, which went unpatched and that might have exposed an entry point into our systems. And the third one is a credential compromise of a few specific users.”

While conducting researching for the book, Daswani said he and Elbayadi came up with both managerial and technical root causes of breaches. “The three managerial root causes of breach are: one, failure to prioritize. Two, failure to invest in. And three, failure to successfully execute on security initiatives,” he said. “On the technical side, there’s six root causes of breach from the 1000s of breaches that we analyzed.” These include: phishing, malware, software vulnerabilities, third-party compromise and abuse, unencrypted data, and inadvertent employee mistakes.

Ramakrishna said SolarWinds is addressing both the managerial and technical aspects to ensure a similar supply-chain attack doesn’t happen again. “One of the first things I did was establish a cybersecurity committee of the board, which includes myself and two CIOs who are sitting board members,” he said.

Autonomous CISO, Smarter Software Design

Additionally, Ramakrishna authorized SolarWinds’ CISO to stop any software release due to security concerns. “The tools, techniques, processes that my CISO uses to attack my own products, nobody knows in the company outside of myself,” he said. “So we are creating an independent organization to reach that level capability, comfort, and seat at the table with regards to our CISO.”

And as attackers become more sophisticated in their methods, so too must software developers in their build processes, Ramakrishna said. “We have to become smarter about how we design and build software as well.”

As part of this, SolarWinds is experimenting with multiple software build pipelines. “We are running parallel build systems through parallel build chains,” he explained. “So the idea is that we want to establish software integrity to two or three different pipelines to avoid that same type of supply chain attacks that we have experienced and variations of those attacks.”

Ramakrishna said he discussed this software development approach with the U.S. Cybersecurity and Infrastructure Security Agency and the Cyberspace Solarium Commission, and plans to publish research papers after it finishes these trials. “I’d like to experiment on this and really see if we’re adding value,” he said. “Ultimately, we are all here to add value to our customers, but do so in a secure fashion.”