Site navigation

Report: Supply Chain Attacks a ‘Daily Reality’ As Vendor Security Lags

Tom Quinn

,

supply chain cybersecurity
Supply chain cyber-attacks are exposing firms’ outdated defences and immature response, with a new report from SecurityScorecard urging a shift from passive risk checks to active threat response.

 

The surge in high-profile cyber-attacks shows threat actors are zeroing in on weak links, with supply chains and third-party access becoming a prime target, but new research shows many firms are being lulled into a false sense of security, relying on outdated strategies and immature defences.

SecurityScorecard’s 2025 Supply Chain Cybersecurity Trends Survey found that more than 70% of organisations reported at least one material third-party cyber incident in the past year, with 5% suffering ten or more incidents.

With so many businesses falling victim, many are looking more closely at external risk sources, reflected in the 88% of cybersecurity leaders who said they are now more concerned about supply chain cyber risks.

The report, based on insights from nearly 550 CISOs and cyber professionals, found that despite these worries, fewer than 50% of organisations monitor cybersecurity across even half of their supply chains.

Added to that, the majority (79%) admit that less than half of their nth-party supply chain is covered by cybersecurity programs, while only 26% of organisations incorporate incident response into the supply chain cybersecurity programmes they do have.    

Meanwhile, nearly 40% of firms cite data overload and an inability to prioritise threats as their biggest supply chain security challenge, and when breaches occur, third-party risk management teams are often guilty of shifting the burden to already overloaded Security Operations Centre staff. 

According to SecurityScorecard, these problems are being compounded by the fact that a small number of third-party providers now support much of the world’s tech infrastructure, creating what the firm calls ‘an extreme concentration of risk’. 

When one of these providers is compromised, the ripple effect can disrupt potentially thousands of organisations at once. 

SecurityScorecard said that attackers have grown to understand this leverage, making the supply chain an increasingly attractive entry point as each vendor relationship expands their attack surface.

To meet the challenge, the report recommends that security teams should take a more active approach, including integrating threat intelligence programmes across vendor ecosystems, creating supply chain incident response workflows, and implementing security tiering for vendors.


Recommended reading


“Supply chain cyber-attacks are no longer isolated incidents; they’re a daily reality,” said Ryan Sherstobitoff, field chief threat intelligence officer at SecurityScorecard.

“Yet breaches persist because third-party risk management remains largely passive, focused on assessments and compliance checklists rather than action. 

“What’s needed is a shift to active defence: supply chain incident response capabilities that close the gap between third-party risk teams and security operations centres, turning continuous monitoring and threat intelligence into real-time action.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data