Supply chain cyber-risks are becoming more problematic to manage, according to new research from BlueVoyant, the cyber-defence company.
The firm’s latest report, The State of Supply Chain Defence Annual Global Insights, found that 95% of UK organisations have experienced cybersecurity incidents in their supply chain in the last year, with over half (59%) reporting between 2 to 5 breach incidents.
Of the 2,100 C-suite leaders questioned for the survey, 66% said that third-party cybersecurity risk management is either not a priority, or somewhat of a priority, a decrease from 68% last year.
Despite falling in priority, a majority (92%) of respondents said that their budgets for third-party cyber-risk management actually increased this year.
The study also revealed that UK supply chain monitoring and visibility is decreasing, with 34% of businesses saying they monitor third-party supplier risk monthly or more frequently, a drop from 46% in 2023.
The lack of regular monitoring is having a big impact, with more than a third (34%) of firms saying they have no way of knowing when a cyber incident occurs.
Over half of all firms (57%) said that the main reason for this lack of visibility was that they don’t assess all vendors, primarily due to a lack of expertise, technology, and resources.
As well as falling supply chain visibility, the top challenges for firms this year were understanding how to penalise third party vendors and suppliers when they don’t respond or remediate issues, followed by issues around meeting regulatory requirements and ensuring third-party cybersecurity compliance.
The problem might only continue to get worse, too, with UK respondents being less likely to use solutions that provide autonomous visibility into the cyber-risks of their supply chain ecosystem, with only 11% saying they do this, compared to 15% globally.
However, UK businesses are more proactive in briefing senior management on third-party cyber-risks, with 8% doing so weekly, compared to 5% globally, and 15% monthly, compared to 13% globally.
Recommended reading
- Cybersecurity Workforce Growth Stalls, Skills Gap Widens
- Hiring Practices to Close the 4 Million Worker Gap in Cybersecurity
- ISC2 Study Exposes Gender Disparities in Cybersecurity Workforce
“UK businesses continue to struggle with the pressing challenge of mitigating supply chain and third-party cyber risks,” said Robert Hannigan, BlueVoyant head of international business for Europe and Middle East, and former director of GCHQ.
“The importance of managing risk across the supply chain cannot be understated. Not just from a brand and security perspective, but also with growing EU regulations such as NIS2 and DORA which call for better risk management, particularly across the supply chain, this is a strategic imperative.”





