According to new analysis, 97% of the UK’s largest companies had a breach in their third-party ecosystem in the last year. This is compared to 98% in France, 95% in Italy, and 94% in Germany.
These statistics come from SecurityScorecard’s newly-published The United Kingdom Top 100 Companies: Cybersecurity Threat Report, which reportedly pulled from the world’s largest proprietary risk and threat intelligence dataset.
The new research also found that 97% of UK FTSE 100 companies had a breach in their fourth-party ecosystem as well. This is compared to 100% of French companies, 97% of Italian companies, and 95% of German companies,
Amid companies increasing the cyber protection of their “front doors” through measures such as firewalls, stronger passwords, and multi-factor identification, adversaries are increasingly incentivised to target smaller supply chain vendors to bypass these efforts.
SecurityScorecard found that, overall, the UK has the strongest average cybersecurity rating compared to its neighbours. The data showed that just 24% of UK companies had a security rating of “C” or below compared to their French, Italian, and German counterparts, with 40%, 41%, and 34% having a C or below respectively.
Despite this higher average cybersecurity rating, 12% of UK firms had experienced a direct breach in the last year, it was discovered. This is compared to 8% of German companies, 7% of French companies, and 3% of Italian companies.
Recommended reading
- What Cybersecurity Trends are Emerging in 2024?
- 90% of Cyber Threats Rely on Social Engineering
- NHS Dumfries and Galloway Stolen Data Published on Dark Web
Commenting on the results, Will Gray, director of Northern Europe for SecurityScorecard, said: “Third-party risk management is a key component of any robust cybersecurity program, and the companies represented in this report would benefit by making it a priority.
“The sectors and organisations in the UK (and in Europe as a whole) need to do more now if they are going to be ready for the implementation of DORA [Digital Operational Resilience Act] by January 2025, as well as the NIS2 directive.
“The rise of data breaches across Europe demonstrates that UK companies still need to make third-party risk management (TPRM) an integral component of not only their security program but of their vendor selection process as well.”





