The threat landscape surrounding software supply chains has never been more dangerous. Third-party identity breaches have doubled over the past year, fueled by supply chain compromises and weak security practices at service providers — and the fallout extends far beyond the organizations directly hit. As Damon Fleury, Chief Product Officer at SpyCloud, explains, every breach carries a “blast radius” that ripples outward to partners, vendors, and clients, leaving entire business ecosystems vulnerable to follow-on attacks. For security teams already stretched thin, understanding that extended risk has become just as critical as protecting their own perimeter.
In this exclusive VMblog Q&A, Fleury breaks down why traditional third-party risk management tools are falling dangerously short — and what organizations in both the public and private sectors need to do right now. With identity now widely recognized as the new security perimeter, SpyCloud is making the case that static scoring and periodic scans are no longer enough. Fleury walks us through the company’s new Supply Chain Threat Protection solution, which taps into billions of recaptured breach, malware, and phished data assets sourced directly from the criminal underground — delivering actionable intelligence to security teams, often within minutes of an active attack.
++
VMblog: Your team at SpyCloud recently reported that third-party identity breaches have doubled over the past year, driven largely by software supply chain compromises and weak security practices at service providers. Where are the companies and organizations affected by these breaches encountering the most security lapses?
Damon Fleury: So, of course, the companies that have experienced the breaches are the ones that see the most direct impact, whether it’s a ransomware attack or attempted IP theft, but that has a ripple effect out to all the companies that they’re connected to or have some form of partnership with. In the case they’ve lost control of their network, or they’ve lost control of key resources, there can be an impact on anyone that they’re doing business with.
Any time that there’s a breach, there’s the initial impact on that affected company, but then there’s what we call the blast radius. The blast radius describes the other systems or companies that are impacted, both within that company, but also within their community of partners, clients, and vendors. That extended community needs to be ready for the reality that the breached company has experienced. Every company that is a part of that extended community will need to take their own actions, in order to protect themselves from a follow-on breach or another type of security event.
VMblog: Why is it becoming increasingly urgent for public and private-sector organizations to know when vendors’ employees have been compromised, when authentication data is circulating on the dark web, and which partners pose the greatest downstream risk?
Fleury: It’s well known within security that the identity has become the new perimeter and is the most common attack vector that’s being used by criminals to gain access to companies. In order to understand the full scope of identity risks facing your team, you need to understand the identity risks of every organization you do business with. Understanding the active identity threats facing your partners, whether they stem malware infections, phish attacks, or third-party breaches, is critical to protecting your own organization.
VMblog: With these challenges in mind, what are the shortcomings that traditional security tools have when identifying and dealing with supply chain compromises?
Fleury: The majority of available tools today that are managing and monitoring third-party risk are dealing with exposures and vulnerabilities that exist for those organizations. What they don’t have is the ability to monitor active threats, and they specifically don’t have the ability to monitor the active threats that are targeting their identities. What you need is not just the ability to see these active threats, but also to be able to understand how those could impact that vendor, and then how that could similarly impact your organization.
VMblog: SpyCloud recently launched a supply chain solution to combat rising third-party identity threats. Can you tell us how it works, and how it is able to address these software supply chain compromises and weak security practices at service providers?
Fleury: The SpyCloud Supply Chain Threat Protection product is focused on analyzing the data that we recapture from the criminal underground. This product is based upon the world’s largest collection of identity data that’s taken directly from the dark web, which criminals have collected through attacks on third parties, third-party breaches, malware attacks, combolists, or phish attacks. In this solution, we take that data along with identity analytics to give our customers a sense of the total number of exposed accounts, type and severity of the identity attacks for which data is actively available on the darknet that could easily be used, and or is being used against your vendors.
Our solution provides an advanced layer of defense that expands identity threat protection across the extended workforce, including organizations’ entire vendor ecosystems. Unlike traditional third-party risk management platforms that rely on external surface indicators and static scoring, SpyCloud Supply Chain Threat Protection offers timely insights into identity threats derived from billions of recaptured breach, malware, phished, and combolists data assets, empowering organizations to act on credible threats rather than just observing and accepting the risk.
VMblog: In addition to the gaps we see for business with rising third-party identity thefts, at many government agencies and critical infrastructure operators, supply chain threats present national security risks that demand heightened vigilance. What are the steps that organizations should be taking to address this urgent risk right now?
Fleury: For government agencies and critical infrastructure operators, supply chain threats present national security risks that require heightened vigilance. Public sector organizations managing sensitive data and critical services increasingly rely on contractors and technology vendors whose compromised credentials could provide adversaries with entry points into classified systems or essential infrastructure.
For those organizations, it’s just so important for them to understand it’s not just the vulnerabilities that their vendors and operators are facing, but the active attacks that are going on against those specific organizations. This is really taking your ability to understand the risks against your supply chain and making it dynamic, allowing you to go past static analysis and understand the dynamic threats that are in the environment today, tomorrow, as you go forward in the future. That is so critical when you’re looking at critical infrastructure. It’s not okay just to have a periodic scan, a periodic update. We need to know what the ongoing attacks are, and we need to make sure that our vendors are ready, and even if they aren’t, that we are ready.
VMblog: Circling back to SpyCloud, your solution(s) delivers signals by transforming raw underground data into clear, prioritized actions that security teams use to protect their organization. Can you give an example of this underground data that you’re working with, and how you are using it to assist customers?
Fleury: One example of high-fidelity identity data is successfully phished data, which is collected from working directly with criminals and understanding how they are deploying phish attacks to make victims of the vast majority certainly of the English-speaking population. And when you fall prey to a phish, you give up information, like your credentials, that gets transmitted through the darknet.
At SpyCloud, we gather that type of information along with recaptured breach, infostealer and combolist data and we add it immediately to our growing data lake and respond to the reality that an individual has been phished. It could be within minutes of the actual attack having taken place. We can then provide that information directly to the affected: to a company that employs that person, for which they may have given up their credentials. We can also alert their vendors and let them know that a significant individual within a company has fallen prey to a phish.
This is about understanding that new threat – that threat that the company is facing right now – and that there may be a next attack, because something as critical as an important VIP’s credentials has been stolen. And so, we need to be ready in case that vendor is not able to respond effectively, so that we won’t see the next attack on our business.
VMblog: SpyCloud isn’t alone in monitoring dark web threats and supply chain risks. How does your approach differ from other vendors in this space, and what gives SpyCloud a competitive advantage in accessing and analyzing this underground data?
Fleury: There are many other vendors that approach similar problems, and if you look at the supply chain vendors themselves, they do monitor some information coming from the dark web. Those vendors are typically monitoring static information that’s been available for quite a while on the darknet, and that information is not organized in such a way that it can easily be connected to identity threats. That data is typically stale isn’t specifically being gathered from the active malware and phish attacks that are ongoing within the darknet.
SpyCloud’s Supply Chain Threat Protection addresses the critical gap in enterprise security, which is the inability to maintain real-time awareness of identity exposures affecting third-party partners and vendors. Our solution enables organizations and agencies to continuously monitor thousands of suppliers, with each company’s threats enumerated in detail, and also represented in an at-a-glance Identity Threat Index. The index is a comprehensive and continuously updated analysis that quantifies vendor security posture through the lens of identity exposure, from both active and historical phishing, breach, and malware sources, and surfaces which partners pose the most significant risk based on verified dark web intelligence.
Furthermore, our enhanced vendor management and communications facilitate sharing of actionable evidence and detailed executive-level reports directly with vendors to collaboratively improve security posture, transforming vendor relationships from adversarial scoring to collaborative protection. Our integrated response functionality in the SpyCloud console gives teams access to identity threat protection beyond the traditional employee perimeter with this extension to suppliers, allowing analysts to respond to workforce identity threats within a single tool.
This is a unique capability that SpyCloud has, and it’s a unique mechanism in which we can deliver that data within minutes, often, of a malware or phish attack, to those who are monitoring those organizations. In doing this, we are able to focus on the dynamic, active threats that are occurring, that are focused specifically on the identities within those organizations, and that’s something that no other supply chain product offers.
And similarly, if you look at darknet products, often known as threat intelligence products, they sometimes have a supply chain component. Those tools do not focus on the most prevalent identity attacks and they do not offer the same level of constant monitoring and the ability to respond to those threats and feed them directly into your SOC.
VMblog: Organizations are already stretched thin with security tools and budgets. What should companies expect in terms of implementation complexity, learning curve, and time-to-value when deploying your supply chain solution? How quickly can they expect to see actionable results?
Fleury: Most of our customers see actionable results in the proof of concept. As they are first looking at the product or in a demo, they immediately see things that can be responded to, and that can help to protect their business. That value continues to be provided throughout the initial deployment. Deployment itself is a very simple process. As a SaaS product, SpyCloud follows the same types of methodologies as the wide variety of SecOps tools that are out there today. It can easily be deployed and immediately added into their arsenal of tools, and it’s pretty straightforward to deploy and to take advantage of right away.
##
About Damon Fleury
Damon Fleury is SpyCloud’s Chief Product Officer and has held product and technology leadership positions for a variety of companies in the networking and security sectors over the last 25+ years. His specialty has been joining companies early in their development to help build and release initial products and then optimizing strategies to enable their success in the marketplace.
Damon has led teams at TippingPoint (Trend Micro), Mirage Networks (Trustwave), Exodus Intelligence, NSS Labs, and CacheIQ (NetApp), and held leadership positions in Engineering, Product Management, and Market Strategy to develop and launch innovative and disruptive products.
Prior to joining SpyCloud as the VP of Strategy in early 2022, Damon served as the Chief Technical Officer and VP of Cybersecurity Services at Texas-based MSSP CyberDefenses. In this role, Damon supported the growth of the commercial and SLED services business, including the creation of and go-to-market efforts for SOC, Security Engineering, Cyber Intelligence, CISO Advisory, and Incident Response services.
As Chief Product Officer of SpyCloud, Damon is responsible for the product roadmap and strategic innovation initiatives that have driven SpyCloud to become the leader in Cybercrime Analytics – helping enterprises combat cyber threats including ATO, ransomware, and online fraud.






