Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Supply Chain Cybersecurity topic

No spam. Unsubscribe anytime.

Experts: practical, low‑cost SCRM steps can help small businesses reduce cyber risk

Panel on small and medium business supply‑chain cybersecurity · June 3, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A panel of FCC officials, industry representatives and small‑ISP technologists told an audience that small and medium businesses should adopt simple baseline controls, vet suppliers with standardized templates and secure CEO buy‑in to make supply‑chain cybersecurity stick.

A public panel of telecom and cybersecurity experts on March 6 urged small and medium‑sized businesses to focus on practical, affordable steps to manage supply‑chain cybersecurity risks.

Jeff Goldthorpe, associate bureau chief and chief data officer at the Federal Communications Commission, opened the session by saying “risk is not stationary” and described how risk moves through a tiered communications supply chain, often landing on smaller tier‑2 and tier‑3 providers that lack the staff and budget to absorb it. Goldthorpe framed the discussion around how SMBs can reduce that externalized risk.

"I honestly don't see a lot of unique characteristics in the needs of SMBs versus large enterprises," said Mike Regan of the Telecommunications Industry Association, arguing that threat exposure often depends on attractiveness to attackers but that SMBs differ in their ability to pay for protections. Regan recommended setting higher expectations with suppliers and considering total cost of ownership rather than always buying the cheapest option.

Ola Sage, founder and CEO of CyberRx, recommended a three‑part approach she summarized as prioritize, prepare and perform: identify critical suppliers and systems, adopt a written supply‑chain risk management plan and follow through with operational steps and testing. Sage said the working group she helps lead produced an operational template with three use cases that her company used to vet managed‑service providers.

From a field perspective, Jerry Horton, technology and cybersecurity director for a small rural telecommunications company that also runs an MSP, emphasized that many SMBs have limited staff and leverage with vendors. Horton recommended starting with foundational controls—multifactor authentication, identity management and basic data protections—and using checklists to show business value to owners and boards.

Panelists pointed to publicly available resources: CISA (the Cybersecurity and Infrastructure Security Agency) checklists and guidance, the NIST Cybersecurity Framework version 2 with supply‑chain coverage, MITRE's System of Trust work and OWASP vulnerability intelligence as practical starting points. Horton specifically recommended CISA’s cross‑sector guidance as an easy, board‑accessible checklist for foundational cyber hygiene.

The panel also urged rethinking product lifecycles and vendor processes so fixes and vulnerability mitigations are pushed to customers promptly rather than deferred to distant releases. Regan said tools such as static and dynamic analysis and proactive monitoring are becoming requisites for vendors that supply products into critical applications.

During Q&A, panelists described real incidents that drove change. Horton recounted a DNS denial‑of‑service attack that occurred three days in a row and a separate case where a former employee with retained credentials caused damage—examples he said prompted concrete operational reforms.

The panel closed with a reminder that advancing supply‑chain risk management for SMBs will require executive champions, incentives such as tax credits or accounting treatments that shift cybersecurity from ‘‘below the line’’ expense to cost‑of‑revenue, and simple, actionable templates that companies can actually implement.