Security issues – leaks, breaches, hacks – involving third-party vendors continue to terrorise enterprises, research from cybersecurity firm Resilience shows.
The firm found that nearly half (47%) of organisations suffered an disruptive outage over the last year from a breach related to a vendor.
While most (85%) firms claim they are familiar with their third-party vendors, not enough (35%) are confident in their reliance on these external forms, creating a major fault in their overall cybersecurity posture.
This is even more apparent for smaller companies: nearly half (43%) of businesses with annual turnovers over £750m view their vendors precautions and security measures to be sufficient, compared to just a quarter (24%) of firms with an annual turnover of £250m and under.
Despite more confidence in their vendors, larger organisations appeared to show a more consistent level of concern over vendor outages, at 44% compared to the average of 40% across all businesses.
Mid-sized, growing companies seem to be at the greatest risk, according to the report, as more cyber-criminals opt for ‘big-game hunting’ of affluent but potentially under-resourced firms.
Much larger firms – those with a yearly turnover over £1bn – were largely untouched by vendor struggles.
Recommended reading
- ‘Big Game’ Ransomware Tactics Drives Spike in Attacks
- Comment | The Growing Threat of Third-Party Cyber Risks
- UK Proposes Ban on Public Sector Ransomware Payments
- Ransomware Payouts Plummet by £350M in 2024
Vendor and Supply Chain Security
According to CheckPoint’s 2025 report, supply chain attacks surged in 2024, with a year-on-year increase in weekly cyber-attack of 179%.
“Cyber risk has become an undeniable reality for businesses of all sizes, yet our findings highlight a concerning gap in understanding and preparedness, particularly in how leaders assess and manage these risks as financial risks,” Resilience CEO Vishaal Hariprasad said.





