Site navigation

70% of Firms Are Ready to Foot the Bill for Contractor’s Security

Staff Writer

,

supply chain security
Companies are pivoting toward the idea of shared cyber‑resilience as supply‑chain threats become a top risk.

Businesses are more willing to shoulder some of their contractors’ security costs to strengthen their own cyber resilience amid a surge of supply‑chain attacks, according to new research from Kaspersky.

Polling more than 1,700 C-suite leaders from enterprise firms around the world, Kaspersky’s Supply Chain Reaction study found that 25% of organisations have already begun sharing security costs, while 69% are actively considering investments.

That willingness to share the security burden comes after almost a third of firms (31%) reported a supply‑chain cyber-attack in the past year, with attacks exploiting trusted relationships hitting 25% of companies, making them the fifth most common threat.

While supply‑chain attacks have always been a concern, the problem has been amplified by the rapid expansion of contractor ecosystems. Kaspersky found that companies now manage more than sixty hardware and software suppliers on average, rising to 100 among larger firms.

Meanwhile, businesses reported an average of seventy‑two external contractors and third parties hold privileged access to their systems, rocketing to more than 130 for high enterprise.

The study found that companies’ readiness to invest in the security of their contractors is especially high in India (83%), Indonesia (80%), Russia (80%) and Brazil (76%), countries which Kaspersky said were notable for their higher than average number of contractors with access to the internal systems.

Despite 85% of execs admitting their organisation needs to upgrade protection against supply chain risks, the study shows an alarming level of overconfidence. Kaspersky found that more than a fifth of organisations (21%) that insist they face little or no supply‑chain risk are unable to estimate the number of software and hardware suppliers they use, creating significant blind spots within their attack surface. 

Even among more aware businesses, the study found a patchwork of protections, dominated by basics like two-factor authentication, still only employed by 38% of firms, and adding contractors to IT security systems (33%).

Added to that, regular checks of contractors’ cybersecurity are practised by only about one-third of businesses (35%), with just 28% evaluating them before onboarding with even the most basic criteria such as reviews of their incident response plans (58%) cybersecurity policies (53%), or compliance certification (51%), though notably Kaspersky found no standard methodology for due diligence.

To mitigate rising supply chain risks, Kaspersky recommended that all firms begin a rigorous and evidence-based evaluation of their providers, applying structured evaluation frameworks to assess vendors’ security practices.


Recommended reading


For software products and cloud services, the report recommended collecting data on vulnerabilities and penetration tests, and even conducting dynamic application security testing, before entering a deal, with contracts written to include specific security requirements, such as regular audits or incident notification protocols.

“Today, businesses realise that security cannot end at the borders of their own organisation, it must extend across the entire ecosystem,” said Sergey Soldatov, head of security operations at Kaspersky.

“By sharing resources and expertise, larger companies can close this gap, strengthening weak points throughout the entire dependency chain — and become a key driver of global cyber resilience.”

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data