Malicious code can devastate your business – here’s how to make sure that doesn’t happen
Asian companies have a cybersecurity problem.
With digitalization well underway for the region, cybersecurity – or rather, the lack of it – has become a critical issue for enterprises. According to a report by Barracuda, 79% of respondents in Asia suffered at least one security breach as a direct result of a vulnerability in an application in the past 12 months.
One of the most notable challenges is securing an organization’s software supply chain, with 46% of respondents in Asia reporting that it’s their biggest concern when it comes to keeping their applications secure. A further 98% of them said that they needed to make at least some improvements to their organization’s defense against software supply chain attacks.
“We’re seeing high-profile attacks almost on a daily basis. This stuff is real and we need to talk about it as an industry,” said Lawrence Crowther, head of solutions engineering at cybersecurity platform Snyk.
A changing developer landscape
Software supply chains have become more difficult to secure because of how developers’ work has evolved.
“Life was pretty easy before this. If you’re a software developer, you’d write your code and probably put it on some sort of build server. IT operations would take that code and deploy it to the infrastructure,” Crowther explained. “But you did it within this perimeter, in a very controlled environment without too many external influences.”

Lawrence Crowther, head of solutions engineering at Snyk / Photo credit: Snyk
Today, many developers work outside this perimeter thanks in part to a massive ecosystem of tooling, open-source libraries, and third-party services for building applications. According to a report by silicon design firm Snyopsys, 97% of the 2,400 codebases it examined contained open-source code. Further, it found that 78% of the code in those codebases was open source.
While this has given developers more versatility, it’s also brought about additional risks due to the relatively unsecured nature of external environments as compared to an internal application development process.
Last year, a critical security flaw was discovered within the popular open-source software Log4j that put millions of applications at risk. Left unchecked, it would have allowed hackers to remotely take over computers running the faulty code.
To make matters worse, in nearly 70% of applications that included the software, the actual Log4j code wasn’t used as a primary tool to build applications – rather, it was used as part of other software procured by developers. This means that some developers might not have even been aware that they were including Log4j code in their systems and exposing themselves to the security flaw.
“It’s a complex web of components that make up the products that you deliver to customers,” Crowther added. “With some of the third-party sources, you may understand and accept the risks [involved], but other ones are more anonymous and opaque.”
Attacks of all shapes and sizes
According to Crowther, software supply chain attacks can happen through several different vectors.
One method is known as dependency confusion. This attack was discovered by a researcher and white-hat hacker called Alex Birsan, who found that the software installation scripts used by developers could be misdirected if the public version of a code library had the same name as the private internal version used by a company.
Through this, developers could be tricked into downloading the wrong open-source packages that contain malicious code, which would introduce an exploit into their internal systems. According to Birsan, this method was so effective that it allowed him to compromise the systems of tech giants such as Apple and Microsoft.
Another notable area that developers need to look out for is typosquatting, in which attackers intentionally upload many different permutations of the name of a code library. This method banks on the hope that developers misspell the name of the code library they’re searching for and inadvertently download the wrong package that uses the attackers’ code instead.
Should developers fall prey to these tactics, it could pose a threat not only to business operations but also to the company’s end customers as well.
Such was the case with the attack on software testing platform Codecov last year, which led to thousands of its customers compromising their own systems when they used the US-based firm’s solution.
“The end game is not to attack those specific companies or vendors directly, but to attack their customers’ customers in a cascading attack,” Crowther noted.
Company-wide changes
To improve security in these areas, Crowther advised companies to implement cultural changes when procuring software for new applications. One way would be to get the firm’s security teams to be more involved in the development process for these projects.
“In an agile software project, things can change direction quickly, with features getting dropped or added that may impact security,” he said. Having a security team as part of the extended development team throughout the whole process – instead of just at checkpoints or at the end of the project – is how he believes it should be done.
Additionally, automated tools are crucial in helping both developers and security teams implement a more secure software pipeline as they can help detect issues more efficiently.
Such was the case with Bank Jago, a digital bank, and DKatalis, a tech solutions firm, which found that the lack of such tools was making security a chore.
“We lost people on the developer and security side because our quality assurance tools were not automated, and that was a big pain point for us,” said Stephen Singam, group chief information security officer of Bank Jago and DKatalis.
To solve this, the group began using Snyk’s security solutions to help protect its software supply chain. These solutions issued weekly reports on security flaws as well as the necessary steps to remediate them.
According to Singam, the companies’ developers have since given feedback that the move has helped them enjoy their work more, with the firms also being able to better trust its developers. Because the process has become more automated, it’s now less prone to human errors present in attacks such as typosquatting.
Owning the security of the software supply chain
In the coming years, Crowther believes that software developers will move toward owning more of the infrastructure they create, which means that security will also become part of their responsibilities.
As such, companies should invest in tools that do the heavy lifting for developers to make the shift easier for them.
“If developers have to process a huge unprioritized list of vulnerabilities and security concerns, they’re never going to do it,” he said.
With both company-wide cultural changes and automated tools, developers will seamlessly be able to own and improve the security of their software supply chains, putting a stop to potential threats.
Snyk provides developer-first tooling and security intelligence solutions to help businesses develop fast and stay secure.
Try out a free trial of its solutions on its website.
This content was produced by Tech in Asia Studios, which connects brands with Asia’s tech community. Learn more about partnering with Tech in Asia Studios.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.
Recommended reads
Indonesian AI startup goes global
Forrest Li on scaling Sea, building smarter bots, and founder grit
An AI assistant that joins sales calls and scores team skills
SGX’s CEO says it doesn’t need a unicorn to win
SMEs want AI too, but not the kind Big Tech is selling
Oatside’s alt-milk rise hits a profitable gear
Alibaba’s financial health in 12 charts
Asia’s telcos bundle AI into mobile plans. Will it pay off?
M-Daq chases bigger clients as revenue falls, losses grow
VC tracker: Accel raises US$3.5b, including US$550m for India
Editing by Nathaniel Fetalvero and Lorenzo Kyle Subido
(And yes, we’re serious about ethics and transparency. More information here.)




