Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Supply-Chain Risk After SolarWinds — What Boards Now Ask

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.

The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller set of targets, they then moved into Microsoft 365 email. Boards now routinely ask: could a trusted supplier compromise us?

What boards ask after SolarWinds

  • Which software suppliers have deep access to our network?
  • Could we detect an attacker who arrived through a trusted update?
  • How dependent are we on on-premises systems that could be used to reach our cloud?
  • Do we know which apps and accounts can read our executives' email?

The business impact

  • Undetectable entry through trusted software.
  • Long dwell time — attackers were inside some networks for months.
  • Costly response across IT, legal and communications.

What good looks like

  • An inventory of software with privileged access (monitoring, management, security, backup tools).
  • Least-privilege configuration and network restrictions for those tools.
  • Monitoring of administrative and cloud application activity, not just endpoints.
  • Reduced dependence on on-premises identity servers that can forge cloud sign-ins.
  • Vendor security requirements for critical software suppliers.

The decision

Ask for a list of your ten most privileged software products and the access each has. Then ask what would happen if one were compromised. The answers shape a supply-chain risk program better than any questionnaire.

solarwinds hack impactSolarWinds / Golden SAML2020

More on this story