Businesses are more willing to shoulder some of their contractors’ security costs to strengthen their own cyber resilience amid a surge of supply‑chain attacks, according to new research from Kaspersky.
Polling more than 1,700 C-suite leaders from enterprise firms around the world, Kaspersky’s Supply Chain Reaction study found that 25% of organisations have already begun sharing security costs, while 69% are actively considering investments.
That willingness to share the security burden comes after almost a third of firms (31%) reported a supply‑chain cyber-attack in the past year, with attacks exploiting trusted relationships hitting 25% of companies, making them the fifth most common threat.
While supply‑chain attacks have always been a concern, the problem has been amplified by the rapid expansion of contractor ecosystems. Kaspersky found that companies now manage more than sixty hardware and software suppliers on average, rising to 100 among larger firms.
Meanwhile, businesses reported an average of seventy‑two external contractors and third parties hold privileged access to their systems, rocketing to more than 130 for high enterprise.
The study found that companies’ readiness to invest in the security of their contractors is especially high in India (83%), Indonesia (80%), Russia (80%) and Brazil (76%), countries which Kaspersky said were notable for their higher than average number of contractors with access to the internal systems.
Despite 85% of execs admitting their organisation needs to upgrade protection against supply chain risks, the study shows an alarming level of overconfidence. Kaspersky found that more than a fifth of organisations (21%) that insist they face little or no supply‑chain risk are unable to estimate the number of software and hardware suppliers they use, creating significant blind spots within their attack surface.
Even among more aware businesses, the study found a patchwork of protections, dominated by basics like two-factor authentication, still only employed by 38% of firms, and adding contractors to IT security systems (33%).
Added to that, regular checks of contractors’ cybersecurity are practised by only about one-third of businesses (35%), with just 28% evaluating them before onboarding with even the most basic criteria such as reviews of their incident response plans (58%) cybersecurity policies (53%), or compliance certification (51%), though notably Kaspersky found no standard methodology for due diligence.
To mitigate rising supply chain risks, Kaspersky recommended that all firms begin a rigorous and evidence-based evaluation of their providers, applying structured evaluation frameworks to assess vendors’ security practices.
Recommended reading
- Report: Supply Chain Attacks a ‘Daily Reality’ As Vendor Security Lags
- Supply Chain Security Risks “Unmanageable”, Cyber Leaders Say
- What Key Cyber Risks Are Supply Chains Facing?
“Today, businesses realise that security cannot end at the borders of their own organisation, it must extend across the entire ecosystem,” said Sergey Soldatov, head of security operations at Kaspersky.
“By sharing resources and expertise, larger companies can close this gap, strengthening weak points throughout the entire dependency chain — and become a key driver of global cyber resilience.”





