A new global survey from ISC2 has revealed deepening concern across the cybersecurity community about the state of supply chain risk, with 70% of respondents reporting that their organisations are “very or extremely” concerned about cybersecurity vulnerabilities within their third-party ecosystems.
The findings, which come from a new ISC2 survey based on responses from 1,062 cybersecurity professionals across organisations of all sizes and sectors, reflect a shared industry reality: a persistent lack of visibility and control over supply chain security.
ISC2 highlights that organisations have been contending with “powerful” disruptions since 2020, including pandemic-driven breakdowns and major digital incidents such as the SolarWinds attack. Supply chain resilience has since become central to mature risk-management strategies.
Concern was highest among the largest organisations (more than 5,000 employees), where 82% reported being very or extremely concerned, compared with 57% in small and medium-sized firms (fewer than 500 employees). Industries facing the greatest pressure include financial services (82%), military and military contractors (81%) and healthcare (67%).
Rising incidents and uneven impact
Experiencing a supply chain incident is far from rare, unfortunately.
According to the survey, 28% of organisations have faced a cybersecurity incident originating from a third-party vendor or supplier within the past two years, rising to 34% among enterprise respondents. Financial services organisations reported the highest impact levels at 37%, compared to 20% in IT services.
ISC2 notes that direct impact is not universal: 47% of participants said their own organisations were not directly affected when a supplier experienced a cybersecurity incident. However, the survey draws attention to the broader systemic risks posed when supplier ecosystems suffer disruption.
Lack of visibility remains the biggest challenge
When asked about the most significant barriers to securing supply chains, respondents repeatedly cited limited visibility, transparency and control over suppliers. Many reported struggling to understand the security posture of their third-party vendors – and often the vendors’ own suppliers – creating blind spots across complex, interconnected digital ecosystems.
Common concerns included “poor or unknown vendor cybersecurity practices” and the need to “trust vendors without the ability to verify their claims.” Comments such as “we have to trust them,” “trust but can’t verify,” and “blind trust” reflect how opaque supplier practices continue to heighten risk.
Nearly two-thirds of respondents identified data breaches as the most disruptive supply chain threat (64%). Malware or ransomware followed at 52%, with software vulnerabilities ranking third at 51%. Other concerns included unauthorised access through third-party credentials (37%), lack of visibility into supplier cybersecurity practices (35%) and insider threats originating from vendors (29%).
How organisations are responding
The survey found that 70% of organisations conduct third-party risk assessments on a regular schedule, often at contract renewal or annually. Nearly half (49%) carry out assessments during initial onboarding, while 26% reassess following an incident and 25% rely on monitoring alerts.
Organisations evaluate supplier cybersecurity practices at varying intervals: 45% conduct annual assessments, 17% quarterly, 12% monthly and 10% semi-annually. Notably, 9% only conduct assessments during onboarding, which ISC2 warns may create a “false sense of security” during multi-year vendor relationships.
Many organisations are increasingly requiring suppliers to provide validation of their security controls. According to respondents, the most common requirements include compliance with standards such as ISO 27001, NIST or SOC 2 (77%), followed by audits or assessments (71%), multi-factor authentication and secure access protocols (62%), and incident response and breach notification procedures (61%). Only 5% of organisations said they do not require any controls.
Mixed maturity in ongoing risk management
Supply chain risk management remains uneven. Just over half of respondents (54%) said their organisation has a dedicated risk-management programme. This rises significantly to 70% among enterprises. However, 20% rely primarily on contracts and SLAs, 16% handle risks on a case-by-case basis and 10% do not have a formal approach at all — with 2% reporting no plans to create one.
Recommended reading
- 87% of Firms Hit By AI Cyber-attacks
- Cybersecurity in 2024 | The High Cost of Innovation
- AI in Cybersecurity | Navigating the Promises and Risks
Among organisations that provide software, digital services or connected managed services to others, 83% say they have formal incident response policies with communication plans and timelines. Only 6% reported they “definitely” do not have such policies, while 11% were unsure.
Where details were provided, respondents said their policies align with standards and regulations including ISO/IEC 27001 and 27035, GDPR, NIST guidance, DORA, NIS2, HIPAA, SOC 2, PCI-DSS, FedRAMP, DFARS 7012, ASD Essential Eight and the UK NCSC.
ISC2 say that better visibility is essential for managing third-party security risk, especially as AI tools begin to compound supply chain threats. They advises cybersecurity practitioners to focus on thorough risk assessments, critical-infrastructure risk management, Zero Trust architectures, contract reviews and professional development through certifications such as ISC2’s CGRC.





